In accordance with data protection regulations, including the GDPR, we maintain a list of all sub-processors that we engage to process personal data on our behalf. Below is our current list of sub-processors that have access to customer data.
Our Sub-processors
Supabase
Location: Account configuration may use EU (Frankfurt, Germany); confirm the active region
Purpose: Database and authentication infrastructure
Data Processed: Customer data, user profiles, compliance documents
Transfer Mechanism: Confirm the applicable safeguard for this account and activity
Vercel
Location: United Kingdom (London); confirm other processing locations against the service configuration and agreement
Purpose: Hosting and deployment platform
Data Processed: Application data, user session information
Transfer Mechanism: Confirm the applicable safeguard for this account and activity
Anthropic
Location: United States-based provider; confirm processing locations for the account
Purpose: AI model processing for GDPR compliance analysis
Data Processed: Customer documents for compliance analysis
Transfer Mechanism: Confirm the applicable safeguard for this account and activity
Resend
Location: United States-based provider; confirm processing locations for the account
Purpose: Email delivery and notifications
Data Processed: Email addresses, notification content
Transfer Mechanism: Confirm the applicable safeguard for this account and activity
Stripe
Location: EU (Dublin, Ireland) / United States
Purpose: Payment processing and billing
Data Processed: Payment information, billing records
Transfer Mechanism: Confirm the applicable safeguard for this account and activity
Changes to Sub-processors
We regularly review our sub-processors and may add or remove sub-processors from time to time. If we add new sub-processors, we will update this list and notify our customers as required by applicable data protection laws. We are committed to maintaining transparency about how customer data is processed.
Data Processing Agreements
Our supplier records link to the applicable legal information and agreement where available. Confirm the executed agreement, account configuration, processing locations and transfer safeguard for each supplier before relying on this list for a particular workspace. A provider listing is not, by itself, proof that a GDPR-compliant arrangement is in place.
Contact Us
If you have any questions about our sub-processors or how your data is processed, please contact us at compliance@rowpa.app.