Subprocessors

The companies we trust with customer data.

A complete, public list of every third-party service that processes personal data on Veracly's behalf, what they do, where they run, and the data they touch.

Last updated: 2026-04-29

Under GDPR Article 28, we are required to tell you, in advance, who we engage as a sub-processor and to give you a fair chance to object before a new one starts processing your data. The table below is the canonical list. We update it whenever we add, replace, or remove a vendor, and we email everyone subscribed to the change list at least 14 days before any new vendor goes live.

Clerk, Inc.
PurposeAuthentication, session management, MFA, and the user profile UI.
Data categoriesName, email, password hash, MFA factors, login IP, device fingerprint.
Infrastructure regionUnited States (multi-region) · EU residency on request
Transfer mechanismEU Standard Contractual Clauses (Module 2 / 3, 2021) plus the EU, US Data Privacy Framework where the vendor is self-certified. Supplementary measures: encryption in transit (TLS 1.3) and at rest (AES-256), access logging, and contractual data-residency commitments where offered.
Hetzner Online GmbH
PurposeCloud infrastructure, application, API, background workers, PostgreSQL database, and S3-compatible object storage.
Data categoriesAll service data at rest and in transit (account data, scan findings, generated reports), hosted in the EU.
Infrastructure regionHelsinki, Finland (EU)
Transfer mechanismProcessing within the EEA, no cross-border transfer.
Mistral AI SAS
PurposeAI text generation for plain-language finding explanations, summaries, remediation suggestions, and translations in scan reports.
Data categoriesTechnical violation data and a short HTML snippet of the flagged element only, no account, contact, or billing data.
Infrastructure regionFrance (EU)
Transfer mechanismProcessing within the EEA, no cross-border transfer.
Resend, Inc.
PurposeTransactional email delivery, verification emails, scan-complete notifications, billing alerts, and privacy responses.
Data categoriesRecipient name, email, the message body and headers, delivery telemetry (bounces, opens).
Infrastructure regionUnited States · Frankfurt edge processing
Transfer mechanismEU Standard Contractual Clauses (Module 2 / 3, 2021) plus the EU, US Data Privacy Framework where the vendor is self-certified. Supplementary measures: encryption in transit (TLS 1.3) and at rest (AES-256), access logging, and contractual data-residency commitments where offered.
Stripe Payments Europe, Ltd.
PurposePayment processing, subscription billing, invoicing, and tax-document generation.
Data categoriesBilling address, name, email, VAT/ABN, card last-4, payment method tokens, transaction history.
Infrastructure regionIreland (EU) · United States (cross-border for fraud detection)
Transfer mechanismEU Standard Contractual Clauses (Module 2 / 3, 2021) plus the EU, US Data Privacy Framework where the vendor is self-certified. Supplementary measures: encryption in transit (TLS 1.3) and at rest (AES-256), access logging, and contractual data-residency commitments where offered.

Former subprocessors

Vendors we have stopped using. We keep this record rather than deleting the row, because a controller needs to establish when a vendor stopped processing their data and when that vendor's stored copy was destroyed. A decommissioned service that still holds a database is still a subprocessor, so the deletion date is the one that matters.

VendorRoleTraffic ceasedCopy deleted
Amazon Web Services, Inc.United StatesObject storage (report PDFs, evidence)2026-07-18Deletion in progress
Anthropic, PBCUnited StatesAI inference (report wording)2026-07-18Deletion in progress
Railway Corp.United StatesAPI and worker hosting2026-07-182026-07-19
Supabase, Inc.United StatesManaged PostgreSQL (application database)2026-07-182026-07-19
Upstash, Inc.United StatesManaged Redis (job queue)2026-07-18Deletion in progress
Vercel Inc.United StatesWeb hosting and edge network2026-07-182026-07-19

How we notify you about changes

When we plan to add a new sub-processor we will: (1) update this page, (2) email everyone on the subprocessor-changes mailing list, and (3) wait at least 14 calendar days before the new vendor begins processing your data, so customers have a meaningful window to object. If you object, we will work with you in good faith to find an alternative; if no alternative is feasible, you may terminate the affected service for breach with a pro-rata refund.

Stay informed

Get notified when this list changes.

Email privacy@veracly.app and ask to be added to the subprocessor-changes list. We will email you at least 14 days before any new vendor begins processing your data.