Last updated 2026-07-27

Sub-processor register

This page is the Register referenced by Annex III of the Data Processing Addendum and forms part of that Annex by reference. It lists every third party involved in running the ERPflow.ai Service, what it does, where it operates, which categories of personal data it touches, and the transfer basis relied on for any processing outside the EEA.

Sub-processors

Entities that process Customer Data on behalf of the Provider, mapped one-to-one to the Annex III categories.

Annex III category Sub-processor (legal entity, registered address) Processing / personal-data categories Hosting location Transfer basis
Cloud infrastructure Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany Hosting of the application API, the Postgres database, and the self-hosted authentication service (Ory Kratos). Processes all Customer Data — the Annex I categories: identification and contact data, professional data, transactional data, HR-adjacent data, and usage and audit data. Germany (EU) n/a — EU/EEA processing
Cloud infrastructure (edge) Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA DNS, CDN, WAF and bot protection (Turnstile), application SPA hosting (Pages), request routing (Workers), object storage (R2: organization logos, asset attachments). All Service traffic and uploaded files transit Cloudflare, so any category of personal data the Customer processes through the Service may appear in transit. Global edge network; US entity EU–US Data Privacy Framework; SCCs in Cloudflare's DPA
Managed database and backups Hetzner Online GmbH (database host) and Cloudflare, Inc. (R2 object storage for backups) Nightly logical database dumps covering all Customer Data, GPG-encrypted (AES-256) before upload, stored in a dedicated R2 bucket with isolated credentials Database: Germany (EU). Backups: Cloudflare R2 with EU jurisdiction — backup data resides in EU data centres DPF / SCCs (Cloudflare)
Email delivery Plus Five Five, Inc. (d/b/a Resend), 2261 Market St #5039, San Francisco, CA 94114, USA Transactional and notification email: invoice sends, booking confirmations and calendar invites, workspace notifications, contact-form forwards. Processes recipient names, email addresses, and message content. USA EU–US Data Privacy Framework; SCCs in Resend's DPA
Error monitoring and observability No sub-processor currently engaged No third-party observability backend is deployed
Payment processing No sub-processor — payment data is handled by Stripe as an independent controller under its own terms (see "Related third parties" below), consistent with Annex III
Customer support tooling No sub-processor currently engaged — support requests are handled over plain email by the Provider
E-invoicing / PEPPOL access point No sub-processor currently engaged — e-invoices (UBL BIS Billing 3.0 XML) are generated inside the Service and downloaded by the Customer; the Service does not transmit them over the PEPPOL network

Related third parties (not sub-processors)

Services that receive personal data in connection with erpflow.ai but act as independent controllers, or process only marketing-site visitor data outside the DPA's scope. Listed for transparency; itemized in the privacy policy.

Third party Role Purpose
Stripe Payments Europe, Ltd. (Ireland) / Stripe, Inc. Independent controller Subscription billing and payment collection; card data is held by Stripe, never by the Provider
Google Ireland Limited Independent controller "Sign in with Google" (OIDC); Google Analytics on the marketing website (consent-gated)
Vercel Inc. Marketing-site processor Hosting of the marketing website incl. Speed Insights performance telemetry (visitors, not Customer Data)
Meta Platforms Ireland Limited Independent controller (dormant) Legacy Facebook OIDC sign-in retained for v1 identities; removed from the UI, provider still configured

Changes to this register

The Data Processing Addendum (clause 7.2) commits to at least thirty (30) days' prior notice before a new or replacement sub-processor begins to process Customer Personal Data. Notice is given by email to the account email address and/or by in-product notification, and every change is recorded in the change log below. The Customer may object to a proposed sub-processor on reasonable data-protection grounds within the notice period (DPA clause 7.3).

Change log

  • 2026-07-27 — Register restructured to match DPA v1.0 (effective 21-07-2026): personal-data categories stated per entry, backup storage documented as Cloudflare R2 with EU jurisdiction, and this change-notification section added. No sub-processor was added, replaced, or removed.
  • 2026-07-22 — Initial public register.

ابدأ مجانًا. وتوسّع مع نموّ أعمالك.

أدِر أعمالك كلها من مكان واحد، وادفع ثمنها كمؤسِّس لا كشركة كبرى.

بلا بطاقة · بلا فترة تجريبية · تصدير كل بياناتك · إلغاء في أي وقت