1. Scope of this register
This register applies only where Blame acts as processor or subprocessor for Customer Personal Data. Capitalised terms have the meanings in the Data Processing Addendum at https://blame.so/legal/dpa.
A provider is listed when Blame selects and contracts with it to process Customer Personal Data in support of the Services. A provider is not omitted merely because its infrastructure is operated by an affiliate or because it uses its own authorised subprocessors; relevant onward-processing terms remain governed by Blame's contract with the listed provider.
2. Current Subprocessors
3. Providers not acting as Customer Content Subprocessors
4. Change notification and objections
Blame will provide at least 30 days' advance notice before authorising a new material Subprocessor to process Customer Personal Data, normally by updating this register and sending notice through the Account or Customer contact email. A shorter period may apply where an urgent security, availability, legal, or supplier event makes advance notice impracticable; Blame will then give notice as soon as reasonably practicable.
Customer may object on reasonable, documented data-protection grounds by emailing legal@blame.so within 15 days after notice. The objection must identify the affected processing and explain the specific risk. Blame and Customer will work in good faith on a reasonable alternative. If no alternative is reasonably available, the termination right in Section 11 of the DPA applies.
A change to a listed provider's company name, address, affiliate structure, or description that does not materially change processing risk may be published without a new objection period. Blame will still maintain an accurate current entry.
5. Change history
- 18 July 2026 — Version 1.0: initial public register; OVH SAS added as Blame's hosting and infrastructure Subprocessor.