Subprocessors

The trusted providers behind Scriboflow

A verified register of providers, their actual role, processed data, locations, and transfer safeguards. Not every provider is a customer-data subprocessor.

Subprocessor basics

What is a subprocessor?

Third-party support for Scriboflow
A subprocessor handles personal data on Scriboflow's instructions to provide the Service. Other providers may be independent controllers or handle only Scriboflow's own operational data.

Provider list

Provider register

The register shows legal provider name, classification, purpose, data categories, processing location, safeguards, source, and verification date.

Supabase, Inc.

Verified: 2026-08-21

Purpose
Managed database, authentication, realtime services, and object storage.
Data categories
Account, organisation, contact, contract, signing, audit, and uploaded-file data entered into the service.
Processing location
Primary production region: Frankfurt, Germany. Limited provider support and ancillary processing may occur from other locations under the provider terms.
Safeguards
EU/EEA regional hosting for the primary project; contractual transfer safeguards where required.
Source: Supabase regions

Google Cloud EMEA Limited and Google group processors

Verified: 2026-08-21

Purpose
Cloud object storage and supporting infrastructure for files and generated contract artefacts.
Data categories
Uploaded files, generated documents, contract identifiers, and related technical metadata.
Processing location
Location depends on the configured resource and provider operations. Google may process where it or its subprocessors maintain facilities, as described in its DPA.
Safeguards
Google Cloud data-processing terms, including applicable EU Standard Contractual Clauses for restricted transfers.
Source: Google Cloud Data Processing Addendum

Vercel Inc.

Verified: 2026-08-21

Purpose
Application hosting, content delivery, server-side request processing, deployment, and operational logs.
Data categories
Account and request identifiers, IP and device metadata, operational logs, and data transmitted through application requests.
Processing location
United States and other global locations used by Vercel and its subprocessors.
Safeguards
Vercel DPA, EU Standard Contractual Clauses, and the EU–US Data Privacy Framework where applicable.
Source: Vercel DPA

Resend, Inc.

Verified: 2026-08-21

Purpose
Transactional email delivery for invitations, contract events, security, and service communications.
Data categories
Recipient names and email addresses, organisation and contract identifiers, message content, and delivery metadata.
Processing location
United States and other locations used by Resend and its infrastructure subprocessors.
Safeguards
Resend DPA and transfer safeguards stated by the provider, including Standard Contractual Clauses where applicable.
Source: Resend DPA

Idura ApS

Verified: 2026-08-21

Purpose
MitID authentication and identity-assisted electronic signing when that signing method is selected.
Data categories
Signer identity, contact and authentication data, signing transaction identifiers, and evidence metadata.
Processing location
European Union under Idura's published privacy and data-protection terms.
Safeguards
Idura's published processor terms state that service personal data is not transferred outside EU territory and require equivalent safeguards from its processors.
Source: Idura privacy and data protection

Stripe Payments Europe, Limited and Stripe group entities

Verified: 2026-08-21

Purpose
Subscription billing, payment processing, invoicing, tax features, and fraud prevention.
Data categories
Billing contact, organisation, transaction, payment-method, tax, and fraud-prevention data.
Processing location
Global Stripe infrastructure, including the United States, under Stripe's services terms.
Safeguards
Stripe's privacy, data-transfer, and payment-services terms. Stripe determines purposes required for regulated payment services.
Source: Stripe Privacy Center

PostHog, Inc.

Verified: 2026-08-21

Purpose
Product analytics and error diagnostics for Scriboflow's service operations.
Data categories
Usage events, account identifiers, device and network metadata, and application error context.
Processing location
PostHog EU Cloud; limited provider operations may involve other locations under its terms.
Safeguards
EU Cloud configuration and PostHog contractual data-protection terms.
Source: PostHog Trust Center

Google LLC and relevant Google group entities

Verified: 2026-08-21

Purpose
Website analytics and, where enabled, Google sign-in and public map functionality.
Data categories
Website usage, device and network metadata, analytics identifiers, sign-in account attributes, and map requests, depending on the feature used.
Processing location
Google's global infrastructure, including the United States and other locations described in the applicable service terms.
Safeguards
Applicable Google service and data-processing terms, including transfer safeguards where required. These activities are not treated as customer contract-data subprocessors by default.
Source: Google Ads Data Processing Terms

Cloudflare, Inc.

Verified: 2026-08-21

Purpose
Turnstile bot and abuse protection for the public contact form when configured.
Data categories
Network, browser, device, challenge, and request-integrity signals associated with contact-form use.
Processing location
Cloudflare's global network and locations used by its subprocessors under the applicable terms.
Safeguards
Cloudflare Customer DPA and applicable transfer safeguards. This activity protects Scriboflow's public form and is not a customer contract-data subprocessor by default.
Source: Cloudflare Customer DPA

Provider selection

How we choose providers

Selection criteria
When selecting service providers, Scriboflow considers factors such as security practices, reliability, privacy commitments, and operational maturity. We aim to work with providers that help us deliver a secure and dependable experience for our customers.

Provider updates

Changes to this list

Updated as Scriboflow evolves
Scriboflow gives at least 30 calendar days' notice before a new customer-data subprocessor begins processing so customers can object on reasonable data-protection grounds.