← AuditSchedule

Sub-processors

Current as of 19 September 2026  ·  Node Logic, trading as AuditSchedule


These are the third-party providers that process customer data on our behalf. This page is the same list that appears in section 4 of our Privacy Policy, published separately so you can check it, cite it, or watch it without reading the whole policy.

Current list

ProviderPurposeLocationSafeguard
SupabaseDatabase, authentication, and file/session infrastructureEU (Frankfurt)EU hosting and data processing terms
VercelApplication hosting and content delivery; processes request metadata and handles workspace data transiently in memory while serving a requestGlobal edge network; US-based providerStandard Contractual Clauses and Vercel data processing terms
CloudflareOff-platform backup storage: a nightly compressed copy of workspace data held in an R2 bucket, so that a copy survives the loss of our primary platformEU jurisdictionBucket created under the EU jurisdiction and Cloudflare data processing terms
StripeCheckout, payment processing, invoicing, tax and subscription recordsUS / globalStandard Contractual Clauses and Stripe data processing terms
ResendTransactional email, password/reset emails, import-error reports, and marketing email deliveryUSStandard Contractual Clauses and data processing terms
GoogleOptional Google OAuth sign-inUS / globalStandard Contractual Clauses and Google data processing terms
UpstashRate limiting for signup, password reset, and other security-sensitive endpoints where configuredCloud region configured by Node LogicData processing terms and applicable transfer safeguards
AnthropicPowers the in-app AI help assistant; receives only the message you type plus our product manual, never workspace dataUSStandard Contractual Clauses and Anthropic commercial/data processing terms; API data is not used for model training
SentryError and exception monitoring; stack traces may incidentally contain identifiers such as a user or workspace IDUSStandard Contractual Clauses and Sentry data processing terms
jsDelivrDelivery of public Bootstrap and icon assets used by the application interfaceGlobal CDNPublic asset delivery; no workspace content is sent intentionally

Where personal data is transferred outside the European Economic Area, we rely on Standard Contractual Clauses adopted by the European Commission under Art. 46(2)(c) GDPR, supplemented by provider security commitments where required. The database and every record entered into a workspace are held in the EU.

How changes are notified

Section 6.6 of our Terms commits us to giving reasonable notice before a material change to this list takes effect. You then have 14 days to object on reasonable data-protection grounds. If we cannot resolve the objection, either of us may terminate the affected subscription and we refund the unused portion.

In practice that means three things happen together: the change is added to the history below, the Privacy Policy's effective date moves, and we email the full administrators of every active workspace. If you would rather a specific person at your organisation received that email, tell us at support@auditschedule.com.

Change history

DateChange
19 September 2026Added Cloudflare (off-platform backup storage), Vercel (application hosting) and Sentry (error monitoring). Cloudflare was engaged on 18 September 2026 when off-platform backups began; Vercel and Sentry had been in use since launch and were missing from this list rather than newly added.
2 July 2026First published list: Supabase, Stripe, Resend, Google, Upstash, Anthropic and jsDelivr.

Questions? support@auditschedule.com · Privacy Policy · Terms of Service