legal · sub-processors · art. 28 gdpr
Sub-processors
last updated · 2026-09-23
These are the service providers we use to run eventflow and that may process personal data. For Customer Data they act as our sub-processors under the Data Processing Agreement; this list is its Annex 3. Stripe also acts as an independent controller for payment processing. The privacy policy explains the processing in context.
current sub-processors
- Supabase, Inc. (Supabase)
Purpose: Database, user authentication, file storage (for example uploaded invoices, logos and fonts) and daily database backups.
Data: All Customer Data stored in a workspace, account data and login metadata.
Location: EU, Frankfurt (Germany).
Transfer safeguard: Data is hosted in the EU. For any access from outside the EU: EU Standard Contractual Clauses. - Vercel Inc. (Vercel)
Purpose: Hosting of the eventflow application and this website. Application server functions run in the Frankfurt region; this website uses Vercel Web Analytics only with consent.
Data: Request data (IP address, user agent, URL, time) and any Customer Data processed while serving a request.
Location: Server functions in Frankfurt (Germany); content delivery through Vercel's global edge network.
Transfer safeguard: EU-U.S. Data Privacy Framework (the provider is certified under it). - Cloudflare, Inc. (Cloudflare)
Purpose: Edge service at worker.event-flow.ai that dispatches email and routes AI requests; Workers AI inference; AI Gateway, through which we reach OpenAI and some Anthropic models under Cloudflare's billing; Browser Rendering, which turns timetables into PDF files and designs into images; Turnstile bot protection on public forms; DNS.
Data: Request data, email content and recipients handed to the email provider, AI prompts and outputs (including invoice documents), timetable and design content sent for rendering, anti-abuse signals.
Location: Cloudflare's global network; processing location varies by request.
Transfer safeguard: Listed in the EU-U.S. Data Privacy Framework; we also rely on EU Standard Contractual Clauses. - Twilio Inc. (Twilio SendGrid)
Purpose: Sending transactional email and the messages a Customer sends from eventflow (for example artist briefings), and reporting delivery and open events.
Data: Recipient names and email addresses, message content, delivery and open events.
Location: USA.
Transfer safeguard: EU-U.S. Data Privacy Framework (the provider is certified under it). - Stripe Payments Europe, Ltd. (Stripe)
Purpose: Checkout, subscription billing, invoices, tax calculation and the billing portal.
Data: Billing contact, billing address, VAT ID, payment method and transaction data.
Location: Ireland, with processing in the USA.
Transfer safeguard: EU-U.S. Data Privacy Framework (the provider is certified under it). - OpenAI (OpenAI models, reached through Cloudflare AI Gateway)
Purpose: The invoice check (reading an uploaded invoice and comparing it with the agreed booking), turning a workspace's written invoice instructions into the list of requirements the check applies, reading invoices an operator uploads to prefill them, and the assistant that helps write communication templates. Requests run with payload logging switched off at the gateway and with a zero data retention request.
Data: Invoice documents, including payee names, addresses, tax numbers and bank details; extracted invoice data; event and booking facts needed for the check; a workspace's written invoice instructions; template drafts; instructions and outputs.
Location: USA.
How engaged: Through Cloudflare, Inc.: requests are billed and routed by Cloudflare under Cloudflare's contract with the provider; we hold no direct contract or API key with OpenAI.
Transfer safeguard: EU Standard Contractual Clauses. - Anthropic Ireland, Limited (Claude models)
Purpose: Fallback for the invoice check when the primary check fails; a scheduled second check of stored invoice checks, whose results we as the operator review to improve our prompts; translation of communication templates, briefing page headlines, invoice instructions and invoice check results; parsing of imported lineups; and turning corrections into short guidance (section 3 of the Data Processing Agreement). Separately, Anthropic writes the first automatic reply in our support chat; for that we are the controller and Anthropic is our processor, not a sub-processor of Customer Data.
Data: Invoice documents, including payee names, addresses, tax numbers and bank details; event and booking facts; support chat messages; template, headline and message text; lineup text a Customer imports; corrections to AI output; instructions and outputs.
Location: USA.
How engaged: Through our own API contract with Anthropic (direct API calls) and, for the scheduled invoice verification and template translation, through Cloudflare AI Gateway.
Transfer safeguard: EU Standard Contractual Clauses. - PostHog, Inc. (PostHog (EU Cloud, eu.i.posthog.com))
Purpose: Counting page views in aggregate, in the signed-in application and on the public pages /sign-in, /sign-up, /forgot-password, /intake/<workspace>, /submit and /help. It is cookieless: nothing is stored on the device, and each page load gets a fresh anonymous identifier held only in memory. No automatic click capture, no session recording, no person profiles. Not loaded on personal link pages such as guest lists, briefings, invoices, the door or outreach pages.
Data: The anonymous per-page-load identifier, the page path with identifiers removed, and the time. The IP address of the request reaches PostHog as part of the connection.
Location: EU, Frankfurt (Germany).
Transfer safeguard: Data is hosted in the EU. For any access from outside the EU: EU-U.S. Data Privacy Framework (the provider is certified under it). - Functional Software, Inc. (Sentry)
Purpose: Error and performance monitoring for the application. Default personal data collection is switched off and events are sanitised before sending.
Data: Error reports, sanitised URLs, technical request and device metadata.
Location: EU data region (Germany).
Transfer safeguard: Data is hosted in the EU. For any access from outside the EU: EU-U.S. Data Privacy Framework (the provider is certified under it). - Backblaze, Inc. (Backblaze B2)
Purpose: Periodic off-site copy of the database backup, kept in a private bucket.
Data: A copy of the database, which contains Customer Data.
Location: EU.
Transfer safeguard: Data is hosted in the EU. For any access from outside the EU: EU-U.S. Data Privacy Framework (the provider is certified under it).
other recipients
Google Ireland Limited (Google Fonts). The design studio and the HTML emails eventflow sends load font files from Google Fonts. When they load, the browser or email client of the viewer transmits its IP address to Google.
changes to this list
We inform Customers by email at least 30 days before we add or replace a sub-processor, and update this page. A Customer may object within that period as described in section 6 of the Data Processing Agreement. Questions: hello@event-flow.ai.