Last updated 2026-07-27
Sub-processor register
This page is the Register referenced by Annex III of the Data Processing Addendum and forms part of that Annex by reference. It lists every third party involved in running the ERPflow.ai Service, what it does, where it operates, which categories of personal data it touches, and the transfer basis relied on for any processing outside the EEA.
Sub-processors
Entities that process Customer Data on behalf of the Provider, mapped one-to-one to the Annex III categories.
| Annex III category | Sub-processor (legal entity, registered address) | Processing / personal-data categories | Hosting location | Transfer basis |
|---|---|---|---|---|
| Cloud infrastructure | Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Hosting of the application API, the Postgres database, and the self-hosted authentication service (Ory Kratos). Processes all Customer Data — the Annex I categories: identification and contact data, professional data, transactional data, HR-adjacent data, and usage and audit data. | Germany (EU) | n/a — EU/EEA processing |
| Cloud infrastructure (edge) | Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA | DNS, CDN, WAF and bot protection (Turnstile), application SPA hosting (Pages), request routing (Workers), object storage (R2: organization logos, asset attachments). All Service traffic and uploaded files transit Cloudflare, so any category of personal data the Customer processes through the Service may appear in transit. | Global edge network; US entity | EU–US Data Privacy Framework; SCCs in Cloudflare's DPA |
| Managed database and backups | Hetzner Online GmbH (database host) and Cloudflare, Inc. (R2 object storage for backups) | Nightly logical database dumps covering all Customer Data, GPG-encrypted (AES-256) before upload, stored in a dedicated R2 bucket with isolated credentials | Database: Germany (EU). Backups: Cloudflare R2 with EU jurisdiction — backup data resides in EU data centres | DPF / SCCs (Cloudflare) |
| Email delivery | Plus Five Five, Inc. (d/b/a Resend), 2261 Market St #5039, San Francisco, CA 94114, USA | Transactional and notification email: invoice sends, booking confirmations and calendar invites, workspace notifications, contact-form forwards. Processes recipient names, email addresses, and message content. | USA | EU–US Data Privacy Framework; SCCs in Resend's DPA |
| Error monitoring and observability | No sub-processor currently engaged | No third-party observability backend is deployed | — | — |
| Payment processing | No sub-processor — payment data is handled by Stripe as an independent controller under its own terms (see "Related third parties" below), consistent with Annex III | — | — | — |
| Customer support tooling | No sub-processor currently engaged — support requests are handled over plain email by the Provider | — | — | — |
| E-invoicing / PEPPOL access point | No sub-processor currently engaged — e-invoices (UBL BIS Billing 3.0 XML) are generated inside the Service and downloaded by the Customer; the Service does not transmit them over the PEPPOL network | — | — | — |
Related third parties (not sub-processors)
Services that receive personal data in connection with erpflow.ai but act as independent controllers, or process only marketing-site visitor data outside the DPA's scope. Listed for transparency; itemized in the privacy policy.
| Third party | Role | Purpose |
|---|---|---|
| Stripe Payments Europe, Ltd. (Ireland) / Stripe, Inc. | Independent controller | Subscription billing and payment collection; card data is held by Stripe, never by the Provider |
| Google Ireland Limited | Independent controller | "Sign in with Google" (OIDC); Google Analytics on the marketing website (consent-gated) |
| Vercel Inc. | Marketing-site processor | Hosting of the marketing website incl. Speed Insights performance telemetry (visitors, not Customer Data) |
| Meta Platforms Ireland Limited | Independent controller (dormant) | Legacy Facebook OIDC sign-in retained for v1 identities; removed from the UI, provider still configured |
Changes to this register
The Data Processing Addendum (clause 7.2) commits to at least thirty (30) days' prior notice before a new or replacement sub-processor begins to process Customer Personal Data. Notice is given by email to the account email address and/or by in-product notification, and every change is recorded in the change log below. The Customer may object to a proposed sub-processor on reasonable data-protection grounds within the notice period (DPA clause 7.3).
Change log
- 2026-07-27 — Register restructured to match DPA v1.0 (effective 21-07-2026): personal-data categories stated per entry, backup storage documented as Cloudflare R2 with EU jurisdiction, and this change-notification section added. No sub-processor was added, replaced, or removed.
- 2026-07-22 — Initial public register.