Sub-processor List

Last Updated: April 4, 2026 | Version 2.1

NIM Labs LLC | nim-labs.com | legal@coord.io

Overview

This page lists the third-party sub-processors that NIM Labs LLC ("NIM Labs"), a Delaware limited liability company, engages to process personal data in connection with the Coord platform (coord.io). This list is maintained in accordance with NIM Labs' obligations under the General Data Protection Regulation (GDPR) and our Data Processing Agreement (DPA).

NIM Labs enters into written data processing agreements with each sub-processor that impose data protection obligations no less protective than those in our DPA. NIM Labs remains liable to customers for each sub-processor's compliance with those obligations.

This list covers NIM Labs' own sub-processors — third parties that process personal data on NIM Labs' behalf. It does not include third-party AI agent providers (Anthropic, OpenAI, Google), LLM APIs accessed via customer-supplied credentials, or identity and integration providers (GitHub, Google) where customers authenticate with their own existing accounts. Those providers are engaged directly by customers and are independent data controllers or processors. Customers are responsible for reviewing those providers' data practices separately.

Change Notification

NIM Labs will provide at least 30 days' prior written notice of any addition or replacement of sub-processors to customers who have executed a Data Processing Agreement. Notice will be provided via email to the account contact and/or via the Coord platform. Enterprise customers who object to a new sub-processor may do so in writing within 14 days of notice as set out in the DPA.

Current Sub-processors

Infrastructure and Storage

Sub-processorPurposeLocationPrivacy
Amazon Web Services (AWS)Cloud infrastructure hosting, compute, relational database storage, and S3-compatible object storageUSALink
Vercel Inc.Frontend web application hosting and deliveryUSALink

Email Delivery

Sub-processorPurposeLocationPrivacy
Resend (Loops, Inc.)Transactional and notification email deliveryUSALink

Billing and Payments

Sub-processorPurposeLocationPrivacy
Polar.sh (Polar Software Inc.)Subscription management, billing, and payment processingUSALink

Website Analytics

Sub-processorPurposeLocationPrivacy
Vercel Inc. (Web Analytics + Speed Insights)Privacy-focused, cookie-free usage analytics and performance monitoring. No personal data processed.USALink

Not Sub-processors

The following are explicitly not NIM Labs sub-processors and are not covered by this list or the NIM Labs DPA. They fall into two categories: (a) AI agent providers engaged directly by customers via their own accounts, and (b) identity and integration providers where the customer authenticates with their own existing account.

AI Agent Providers

ProviderWhy not a sub-processor
Anthropic, PBC (Claude Code)Engaged directly by the customer via their own Anthropic account and credentials (API key, OAuth token, or subscription login). Anthropic processes data under its own terms and privacy policy. NIM Labs does not control or instruct Anthropic's data processing.
OpenAI, LLC (Codex)Same as above. Customer's own OpenAI account and credentials. Governed by OpenAI's terms and policies.
Google LLC (Gemini)Same as above. Customer's own Google AI account and credentials. Governed by Google's terms and policies.

Identity and Integration Providers

ProviderWhy not a sub-processor
GitHub, Inc. (OAuth + GitHub App)Customers authenticate to Coord via their own GitHub account (OAuth) and authorize the Coord GitHub App for their own GitHub organization. For OAuth sign-in, GitHub provides user identity data (name, email, avatar) to NIM Labs under the customer's existing GitHub account relationship. For the GitHub App integration, all repository operations (branch creation, pull requests) occur on GitHub's platform under the customer's own GitHub permissions — repository code does not transit Coord's servers. GitHub is engaged directly by the customer and processes data under GitHub's own terms of service and privacy statement.
Google LLC (OAuth sign-in)Customers may authenticate to Coord via their own Google account (OAuth). Google provides user identity data (name, email) to NIM Labs under the customer's existing Google account relationship. Google is engaged directly by the customer and processes data under Google's privacy policy. Note: Vercel Inc. (not Google LLC) provides analytics for the coord.io website via Vercel Web Analytics, which is cookie-free and does not collect personal data.

Contact

For questions about our sub-processors or to exercise rights under a Data Processing Agreement, contact privacy@coord.io.