Veracly
Subprocessors

The companies we trust with customer data.

A complete, public list of every third-party service that processes personal data on Veracly's behalf, what they do, where they run, and the data they touch.

Last updated: 2026-08-21

Under GDPR Article 28, we are required to tell you, in advance, who we engage as a sub-processor and to give you a fair chance to object before a new one starts processing your data. The table below is the canonical list. We update it whenever we add, replace, or remove a vendor, and we email everyone subscribed to the change list at least 14 days before any new vendor goes live.

Clerk, Inc.
PurposeAuthentication, session management, MFA, and the user profile UI.
Data categoriesName, email, password hash, MFA factors, login IP, device fingerprint.
Infrastructure regionUnited States (multi-region) · EU residency on request
Transfer mechanismEU Standard Contractual Clauses (Module 2 / 3, 2021) plus the EU, US Data Privacy Framework where the vendor is self-certified. Supplementary measures: encryption in transit (TLS 1.3) and at rest (AES-256), access logging, and contractual data-residency commitments where offered.
Effective date2026-04-27
Hetzner Online GmbH
PurposeCloud infrastructure, application, API, background workers, PostgreSQL database, and S3-compatible object storage.
Data categoriesAll service data at rest and in transit (account data, scan findings, generated reports), hosted in the EU.
Infrastructure regionHelsinki, Finland (EU)
Transfer mechanismProcessing within the EEA, no cross-border transfer.
Effective date2026-07-18
Mistral AI SAS
PurposeAI text generation for plain-language finding explanations, summaries, remediation suggestions, and translations in scan reports.
Data categoriesTechnical violation data and a short HTML snippet of the flagged element only, no account, contact, or billing data.
Infrastructure regionFrance (EU)
Transfer mechanismProcessing within the EEA, no cross-border transfer.
Effective date2026-07-18
Resend, Inc.
PurposeTransactional email delivery, verification emails, scan-complete notifications, billing alerts, and privacy responses.
Data categoriesRecipient name, email, the message body and headers, delivery telemetry (bounces, opens).
Infrastructure regionUnited States · Frankfurt edge processing
Transfer mechanismEU Standard Contractual Clauses (Module 2 / 3, 2021) plus the EU, US Data Privacy Framework where the vendor is self-certified. Supplementary measures: encryption in transit (TLS 1.3) and at rest (AES-256), access logging, and contractual data-residency commitments where offered.
Effective date2026-04-27
Stripe Payments Europe, Ltd.
PurposePayment processing, subscription billing, invoicing, and tax-document generation.
Data categoriesBilling address, name, email, VAT/ABN, card last-4, payment method tokens, transaction history.
Infrastructure regionIreland (EU) · United States (cross-border for fraud detection)
Transfer mechanismEU Standard Contractual Clauses (Module 2 / 3, 2021) plus the EU, US Data Privacy Framework where the vendor is self-certified. Supplementary measures: encryption in transit (TLS 1.3) and at rest (AES-256), access logging, and contractual data-residency commitments where offered.
Effective date2026-04-27
Prighter EU Rep GmbH · Prighter Ltd
PurposeArticle 27 GDPR and UK GDPR representative. Receives data-subject requests and correspondence from supervisory authorities on our behalf, and hosts the certificate-of-representation badge shown on our legal pages.
Data categoriesIdentity and contact details you provide in a data-subject request, and the content of that request. Because the representation badge is loaded from their domain, your IP address and browser metadata are also disclosed to them when you view one of our legal pages.
Infrastructure regionVienna, Austria (EU) · London, United Kingdom
Transfer mechanismEEA (no transfer) · UK — adequacy
Effective date2026-04-30
On request

Effective date is the date the vendor began processing personal data on our behalf. For vendors already engaged when Veracly was first built, we show 27 April 2026, the date of the earliest record in our source history. Prighter EU Rep GmbH and Prighter Ltd were added to this list on 21 August 2026; they have acted as our Article 27 representatives since 30 April 2026 and were omitted from earlier versions of this page in error.

Former subprocessors

Vendors we have stopped using. We keep this record rather than deleting the row, because a controller needs to establish when a vendor stopped processing their data and when that vendor's stored copy was destroyed. A decommissioned service that still holds a database is still a subprocessor, so the deletion date is the one that matters.

VendorRoleTraffic ceasedCopy deleted
Amazon Web Services, Inc.United StatesObject storage (report PDFs, evidence)2026-07-18Deletion in progress
Anthropic, PBCUnited StatesAI inference (report wording)2026-07-18Deletion in progress
Railway Corp.United StatesAPI and worker hosting2026-07-182026-07-19
Supabase, Inc.United StatesManaged PostgreSQL (application database)2026-07-182026-07-19
Upstash, Inc.United StatesManaged Redis (job queue)2026-07-18Deletion in progress
Vercel Inc.United StatesWeb hosting and edge network2026-07-182026-07-19

How we notify you about changes

When we plan to add a new sub-processor we will: (1) update this page, (2) email everyone on the subprocessor-changes mailing list, and (3) wait at least 14 calendar days before the new vendor begins processing your data, so customers have a meaningful window to object. If you object, we will work with you in good faith to find an alternative; if no alternative is feasible, you may terminate the affected service with a pro-rata refund of prepaid fees, as set out in the Data Processing Addendum.

Stay informed

Get notified when this list changes.

Email privacy@veracly.app and ask to be added to the subprocessor-changes list. We will email you at least 14 days before any new vendor begins processing your data.

The companies we trust with customer data, Veracly