Subprocessors
The third-party providers that may process client personal data, and what each one is used for.
- Effective
- August 26, 2026
- Updated
- August 26, 2026
NextEra Group engages the third-party providers below to help deliver our services. Each is bound by a written agreement requiring appropriate security measures and restricting processing to our documented instructions. This page is referenced by our Data Processing Addendum.
Current subprocessors
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Vercel Inc. | Website and application hosting, edge delivery | Usage and request metadata, IP address | United States |
| Amazon Web Services, Inc. | Cloud infrastructure, storage, and compute | Client application data, backups | United States |
| Google LLC | Business email, document collaboration, analytics | Business contact details, correspondence | United States |
| Anthropic PBC | AI model inference for features that use large language models | Content submitted to AI features, as configured per engagement | United States |
| OpenAI, L.L.C. | AI model inference where an engagement specifies it | Content submitted to AI features, as configured per engagement | United States |
| Stripe, Inc. | Payment processing for invoicing and billing systems | Billing contact details, transaction metadata | United States |
Engagement-specific providers
Some engagements involve providers chosen by the client or specific to a deliverable — a payment gateway, CRM, or analytics platform already in use by the client. Those are identified in the applicable statement of work rather than listed here, because they vary by engagement.
Notice of changes
We give clients with an executed DPA at least 30 days’ advance notice before adding or replacing a subprocessor that processes their personal data. Clients may object on reasonable data protection grounds within that window, as described in Section 6 of the DPA.
To receive these notices, send the email address that should be notified to info@nexteragp.com.
International transfers
The providers above are located in the United States. Where personal data originates in the EEA, the UK, or Switzerland, transfers are made under the Standard Contractual Clauses together with supplementary measures, as described in our Privacy Policy.