Legal · Subprocessors
Blossom Subprocessors
Version 0.1 — Last updated July 22, 2026
This page identifies third parties Polymath HQ, Inc. d/b/a Blossom engages to process Customer Personal Data when providing the Services. Capitalized terms have the meanings in the Data Processing Addendum.
1. How to read this list
In short: These are vendors Blossom hires. A service you independently connect under your own agreement is not added merely because Blossom accesses it for you.
The tables list Blossom’s active subprocessors by function. The source inventory did not establish contracted processing locations, so the location column is expressly marked for verification before publication. Customer’s deployment, configuration, and selected AI model determine which subprocessors receive Customer Personal Data.
Customer-Connected Services—such as Customer’s own Gmail or Google Workspace, Microsoft 365, Slack, Zoom, phone systems, notetakers, and other services in the connector directory—are selected and contracted for by Customer. They are not Blossom subprocessors merely because Customer directs Blossom to access them. Blossom’s own vendors that host, route, automate, or operate those connections are listed below.
2. Infrastructure, identity, communications, and payments
In short: These vendors provide Blossom’s core hosting, authentication, email, and billing infrastructure.
| Subprocessor | Purpose | Primary expected location |
|---|---|---|
| Convex | Backend database, application functions, and file storage | To be verified before publication |
| Vercel, including Vercel Queue and Vercel Sandbox | Web hosting, job queues, and sandboxed agent execution | To be verified before publication |
| WorkOS | Authentication, identity, sessions, organization membership, and credential-vault services | To be verified before publication |
| Resend | Transactional and authentication email delivery | To be verified before publication |
| Stripe, including Stripe Connect | Subscription billing, payments, transaction state, and marketplace payouts | To be verified before publication |
3. AI and model providers
In short: Depending on the selected workflow or model, Customer Data may be routed to these AI providers under contractual training and retention restrictions.
| Subprocessor | Purpose | Primary expected location |
|---|---|---|
| OpenRouter | AI-model routing and inference | To be verified before publication |
| Vercel AI Gateway | AI-model routing, observability, and inference transport | To be verified before publication |
| Google Gemini | AI analysis and inference, including supported audio analysis | To be verified before publication |
| BaseTen | Hosted model inference and synthesis | To be verified before publication |
| Groq | Speech-to-text transcription and model inference | To be verified before publication |
Blossom contractually restricts these AI-model providers from using Customer Data to train, develop, or improve their models. A high-risk or new AI model that cannot meet those restrictions may be enabled for a Customer account only with prior, affirmative, account-specific, revocable consent as described in the DPA.
4. Agent execution and automation
In short: These vendors help agents browse, run isolated code, convert files, and carry out workflows.
| Subprocessor | Purpose | Primary expected location |
|---|---|---|
| Kernel | Hosted browser sessions, connector authorization, session persistence, and browser-based extraction | To be verified before publication |
| Browser Use | Browser automation | To be verified before publication |
| E2B | Sandboxed code execution | To be verified before publication |
| ConvertAPI | File conversion | To be verified before publication |
5. Token-holding integration providers
In short: These vendors may hold OAuth tokens and broker access to Customer-Connected Services at Customer’s direction.
| Subprocessor | Purpose | Primary expected location |
|---|---|---|
| Composio | Managed OAuth, token storage, and integration execution | To be verified before publication |
| Pipedream | Managed OAuth, token storage, and fallback integration execution | To be verified before publication |
6. Enrichment and support
In short: These vendors support company lookup and customer support interactions.
| Subprocessor | Purpose | Primary expected location |
|---|---|---|
| Clearbit | Company autocomplete and enrichment for company information entered during the Audit | To be verified before publication |
| Birdie | Customer support widget and user-submitted support screen recordings | To be verified before publication |
7. Planned additions not yet active
In short: Sendblue and Apify are not active subprocessors today. They will move into the tables only after notice and activation.
The following vendors are staged but are not currently authorized to process Customer Personal Data as active subprocessors:
| Proposed subprocessor | Proposed purpose | Status |
|---|---|---|
| Sendblue | iMessage/SMS channel operations | Staged; not active |
| Apify | Web data collection and automation | Staged; not active |
Blossom will give the notice described below before either vendor begins processing Customer Personal Data.
8. Changes, notice, and objections
In short: Blossom gives 30 days’ notice before a new subprocessor starts; customers have 15 days to object on data-protection grounds.
Blossom will provide at least 30 days’ notice before authorizing a new subprocessor to process Customer Personal Data. A Customer may object by emailing legal@blossom.fm within 15 days after notice and explaining its reasonable, documented data-protection grounds. The parties will try in good faith to resolve the concern. If no commercially reasonable solution is available, Customer may terminate the affected Service before the new subprocessor begins processing and receive a pro rata refund of prepaid fees for the unused portion of that Service. Termination of the affected Service is Customer’s sole remedy for an unresolved objection.
An urgent replacement needed to protect security or service continuity may occur on shorter notice. Blossom will give notice as soon as reasonably practicable and preserve the objection process where feasible.
9. Subscribe to updates
In short: Email us to receive future subprocessor-change notices.
To subscribe, email legal@blossom.fm with the subject “Subprocessor Updates” and identify the Customer account and notice email. Customers are responsible for keeping that address current. Blossom may also provide notice to account administrators or through the Services.
10. Contact
In short: Questions and objections go to legal@blossom.fm.
Polymath HQ, Inc. d/b/a Blossom
New York, United States
Attention: Noah Lenz
legal@blossom.fm
Changelog
In short: This log records the initial list and every later addition, removal, or material purpose change.
| Date | Effective date | Version | Change |
|---|---|---|---|
| July 22, 2026 | To be set at publication | 0.1 | Initial working-draft list. Sendblue and Apify identified as staged but inactive. |