Khoros Data Location and Subprocessor Guide

Last Update: 05/27/2019


Khoros processes and stores its U.S., Canadian, and Asia/pacific customers’ data primarily in the United States, and its European/ Middle Easter customers’ data primarily in the EU/ EEA, with some exceptions noted below.

Customer Region

Khoros Application

Primary Storage

Back Up Storage

US/ Canada/Asia/pacific

Khoros Community

US (Equinix in transition moving to AWS in 2018)

US (AWS)

US/ Canada/Asia/pacific

Khoros Social Media Management (Reach and Response/ LSW)

US (AWS)

US (AWS)

US/ Canada/Asia/pacific

Spredfast-legacy products

US (AWS)

US (AWS)

US

Khoros JX Community, formerly known as Jive-X

US (Jive)

US (Jive)

EU/ EEA/ Middle East

Khoros Community

The Netherlands (Equinix in transition moving to Ireland, AWS in 2018)

Ireland (AWS)

EU/ EEA/ Middle East

Khoros Social Media Management (Reach and Response/ LSW)

Ireland (AWS)

Ireland (AWS)

EU/ EEA/ Middle East

Spredfast-legacy products

US (AWS)

US (AWS)

EU

Khoros JX Community, formerly known as Jive-X

The Netherlands (Jive)

England (Jive)


Effective October 2, 2018, Khoros and Spredfast closed their merger transaction, and new listings related to Spredfast-legacy products have been added as appropriate.

Effective October 3, 2017, Khoros acquired the Jive-x external community platform from Jive Software, an Aurea company. As a result, Khoros entered into a transition services agreement with Jive that will allow Jive, functioning as a subprocessor, to continue to provide Jive-x services for 12 to 15 months.

Khoros provides customer support and conducts engineering work that might sometimes require limited access to our customers’ data from Khoros office locations in the U.S. and India.

In addition, Khoros engages subcontractors outside the EU/ EEA that process some limited EU customer data such as log files, and spam email filtering, or that provide technical support to our European customers.

Khoros requires that its subcontractors comply with security and data privacy standards at least as protective as those that Khoros commits to its customers, and this is reflected in our contracts with our subcontractors. In relation to EU data privacy regulatory compliance, Khoros complies with the requirements of the EC Standard Contractual Clauses, and requires that its subcontractors that have access to Khoros customers’ data similarly comply. Further, Khoros will enter into the EC Standard Contractual Clauses with any European customer upon request.


In addition to the above, Khoros also utilizes the following subprocessors to provide certain optional services (as indicated below) to those Khoros customers who elect to purchase those optional services:

Khoros also utilizes subcontractors that do not have any access to our customer’s data, and are therefore not listed in this Guide.

Subprocessor Detail Chart:

Vendor

Usage / Khoros Applications

Access Type

Transfer or Access

Security Audit
SSAE 16 SOC 2

Security Certification
ISO 27001

Controls

AWS

Cloud hosting for Khoros Community and SMM

Logical access to data is possible

No data is transferred (stays in region)

Yes

Yes

Data is encrypted. Only Khoros has keys.

Sumo Logic

Log collection and storage for Khoros Community and SMM

Log files only

Logs are transferred to servers in USA

Yes

Yes

Log data is encrypted. Sumo has keys.

Akismet

Spam detection for Khoros Community

No access to PII (only content)

Content is transferred to API end point in USA

No

No

Short-term access to content only.

Persistent

Outsourcing for Khoros Community and SMM

Development services

Access from India

No

Yes

Same as Khoros employees.

ETI Software Solutions (formerly Netmania)

Outsourcing for Khoros Community and SMM

Support, Migration, Upgrades

Access from Bulgaria, Italy, and UK

No

Yes

Same as Khoros employees.

Ooyala

Video playback and storage for Khoros Community

Access to uploaded videos is possible

Storage in the USA

Yes

No

Ooyala has access to videos.

Box

File storage for customers using the File Preview feature of Khoros Community and/or SMM

Access to file attachments is possible

Storage in the USA

Yes

Yes

Files are stored encrypted. Box has access to keys.

Infogain Corporation

Outsourcing for Khoros Community and SMM

Support and troubleshoot

Access from USA and India

Yes

Yes

Same as Khoros employees.

Cloud Elements, Inc.

API integration platform (for CRM integration with Khoros SMM)

Logical access is possible

No data is transferred (stays in region)

No

No

EC Model Clauses and audit rights

Direct Defense, Inc.

Incident Response

Logical access to logfiles and other data is possible

Data is transferred to DirectDefense ShareFile servers in a SOC 2 certified SaaS environment.

Yes

No

Multi-Factor Authentication required for access. Data is encrypted in transit and at rest. Least privilege access control processes are in place.

Akamai Technologies, Inc.

Content Delivery Network for Khoros Community

Logical access to data is possible

Data is transferred to the nearest Akamai network POP within the geographical origin area of the end user request

Yes

ISO 27002

EC Model Clauses and annual review of SOC 2 audit report

Infoesearch

Content moderation services

Logical access to data is possible

No data is transferred (stays in region)

Yes

Yes

Data is encrypted. Only Khoros has keys.

ServiceRocket, Inc.

Cloud hosting for Khoros training and education materials for Khoros Community and SMM

Logical access to data is possible

Transfer to US hosting facilities

Yes

No

Data is encrypted. Only Khoros has keys.

Clarotest Consulting Lab S.R.L.

Development services and support for the Khoros JX Community

Some access to customer data as part of outage mitigation.

Access from Argentina

No

No.

ISO 9001 instead.

Comply with Khoros’s security requirements.

Smooch Technologies, Inc.

Hosted service that helps extend Khoros's conversational capabilities

Logical access to data is possible

Storage in USA

In progress

No

Data is encrypted.

Netbase Solutions, Inc.

Ingestion and analysis of customer’s Khoros Data

Logical access to data is possible

Storage in USA

Yes

No

EC Model Clauses and audit rights

iTalent Corporation

Outsourcing for Khoros Community and Khoros JX Community

Support and trouble-shoot, migration and upgrades, Some access to customer data

Access from USA , UK and India

Yes

Yes

EC Model Clauses and audit rights

Social Edge Consulting, LLC

Outsourcing for Khoros Community and Khoros JX Community

Support and trouble-shoot, migration and upgrades, Some access to customer data

Access from USA, Canada, UK, Portugal and Spain

Yes

Yes

EC Model Clauses and audit rights

Grazitti Interactive

Outsourcing for Khoros Community

Support and trouble-shoot, migration and upgrades, Some access to customer data

Access from India

No – SSAE 18 SOC 1 and SOC 2

Yes

EC Model Clauses and audit rights

Salesforce.com, Inc.

Hosted service that provides customer support ticketing for Khoros products

Logical access to data is possible

Data storage in USA.

Yes

Yes

EC Model Clauses; also see https://trust.salesforce.com/en/compliance/

Fastly

Content Delivery Network for Spredfast

Logical access to data is possible

Data is transferred to the nearest Fastly POP within the geographical origin area of the end user request

Yes

No

https://docs.fastly.com/guides/compliance/

VirtualMind

Outsourcing for Spredfast products

Development services

Access from Argentina

No

No

Same as Khoros Employees

SoftServe

Outsourcing for Spredfast products

Development services

Access from Ukraine

No

Yes

Same as Khoros Employees

GoodData

Hosted service that provides customer facing analytics for Spredfast products

Logical access to data is possible

Storage in USA

Yes

Yes

Data is encrypted

Zendesk

Hosted service that provides customer support ticketing for Spredfast products

Some access to customer data possible

Storage in USA

Yes

Yes

Data is encrypted

Pendo

Hosted service that provides in-product help, guidance and product announcements.

Some access to customer data possible

Storage in USA

Yes

No

Data is encrypted