1. What This List Is
This is the canonical list of the sub-processors we engage to process personal data on behalf of our customers. It exists as one document, with one version, because the Data Processing Addendum turns it into a commitment: under a general written authorisation we must notify customers before a new sub-processor begins processing, and allow them to object. A commitment whose subject can change without anything noticing is a commitment nobody can keep.
Changing this list requires moving its version, and the version is what the notification fires on. Both are enforced in CI rather than remembered.
2. Notice and Objection
We notify the owner of each workspace whose organisation has accepted the Data Processing Addendum, by email, at least 30 days before a new sub-processor begins processing personal data, and we update this list at the same time.
The obligation follows the contract: it is owed to customers who have accepted the Addendum. Where none has, there is nobody entitled to notice and the period has nothing to run against — which is a consequence of the commitment, not an exception to it.
A customer may object on reasonable data protection grounds by replying to that notice or writing to support@eptk.cloud within the notice period. If the objection cannot be resolved, either party may terminate the affected part of the Service.
3. Sub-processors
- Google Ireland Limited / Google Cloud — hosting, database, file storage, authentication, AI processing, and analytics warehousing. Authentication data is processed in the United States; see section 5.
- Stripe, Inc. — payment processing
- Twilio SendGrid — transactional email delivery
- PostHog Inc. — product analytics, EU Cloud (Frankfurt)
- Linear Orbit, Inc. — support and feedback requests raised from within the Service or through the public feedback form
- Slack Technologies (Salesforce, Inc.) — support handling
- Vaisala Xweather — weather data for a location
- AirLabs — flight status for a flight number
4. Engaged Only at the Customer's Own Choice
These are engaged only where a customer connects its own account with the provider. The content stored there is held under the customer's own agreement with that provider rather than under our Addendum, and its location follows that arrangement.
- Microsoft Ireland Operations Limited — customer-connected SharePoint or OneDrive storage
- Dropbox International Unlimited Company — customer-connected Dropbox storage
5. Processing Outside the European Union
Personal data is stored and processed within the European Union, with one exception:
- Authentication data — email address, password hash and sign-in identifiers — is processed in the United States, because the authentication service we use offers no European location. The transfer is made under the European Commission's adequacy decision for the EU–US Data Privacy Framework and under Standard Contractual Clauses, as set out in the provider's data processing terms.
Other sub-processors may process data outside the European Union under equivalent safeguards.
6. Contact
Questions about this list, and objections under section 2, go to support@eptk.cloud.