Last reviewed: 2026-08-31
Service: Netanza / Media Forge
This register identifies third-party providers currently used, or intended to be used, in operating Media Forge. It distinguishes runtime/customer-data processing from development tooling so the list does not overstate where Customer Content flows.
Purpose: Production compute, Cloud Run API, Cloud Batch workers, Cloud Storage, Firestore, logging/monitoring, IAM/secret infrastructure
Data categories: Customer Content during requested processing; derived outputs; job metadata; tenant/usage/security records
Customer Content expected? Yes, transiently as required to provide processing
Current boundary: Primary production cloud; current PROD region us-central1; platform-managed derived outputs have verified 30-day lifecycle
Purpose: Payment, billing, invoices, provider-side commercial events/reconciliation
Data categories: Business/account billing identifiers, invoice/payment/usage references
Customer Content expected? No media payload intended
Current boundary: Commercial provider projection; local immutable usage authority remains Media Forge-owned
Purpose: Source control, CI/CD, Actions, protected environment configuration
Data categories: Source code, build/test metadata, deployment identity metadata, protected operational configuration
Customer Content expected? No
Boundary: Customer media must not be committed, attached to issues, or placed in ordinary CI artifacts
A new provider that will receive Customer Content, customer personal data, billing/account information, or security-sensitive operational data must be classified before activation. Record:
provider/legal name;
service/purpose;
data categories;
whether Customer Content flows to it;
processing region/location where relevant;
contractual/data-protection mechanism where required;
security review reference; and
effective date.
Provider experimentation in DEV does not automatically make a provider a production subprocessor.
This page is the current Media Forge subprocessor register. Netanza is finalizing the notice mechanism for material subprocessor changes together with its customer-contact setup, and the applicable order form or Data Processing Addendum will state the notice mechanism that applies to a Customer.