Sub-processors
Current as of 19 September 2026 · Node Logic, trading as AuditSchedule
These are the third-party providers that process customer data on our behalf. This page is the same list that appears in section 4 of our Privacy Policy, published separately so you can check it, cite it, or watch it without reading the whole policy.
Current list
| Provider | Purpose | Location | Safeguard |
|---|---|---|---|
| Supabase | Database, authentication, and file/session infrastructure | EU (Frankfurt) | EU hosting and data processing terms |
| Vercel | Application hosting and content delivery; processes request metadata and handles workspace data transiently in memory while serving a request | Global edge network; US-based provider | Standard Contractual Clauses and Vercel data processing terms |
| Cloudflare | Off-platform backup storage: a nightly compressed copy of workspace data held in an R2 bucket, so that a copy survives the loss of our primary platform | EU jurisdiction | Bucket created under the EU jurisdiction and Cloudflare data processing terms |
| Stripe | Checkout, payment processing, invoicing, tax and subscription records | US / global | Standard Contractual Clauses and Stripe data processing terms |
| Resend | Transactional email, password/reset emails, import-error reports, and marketing email delivery | US | Standard Contractual Clauses and data processing terms |
| Optional Google OAuth sign-in | US / global | Standard Contractual Clauses and Google data processing terms | |
| Upstash | Rate limiting for signup, password reset, and other security-sensitive endpoints where configured | Cloud region configured by Node Logic | Data processing terms and applicable transfer safeguards |
| Anthropic | Powers the in-app AI help assistant; receives only the message you type plus our product manual, never workspace data | US | Standard Contractual Clauses and Anthropic commercial/data processing terms; API data is not used for model training |
| Sentry | Error and exception monitoring; stack traces may incidentally contain identifiers such as a user or workspace ID | US | Standard Contractual Clauses and Sentry data processing terms |
| jsDelivr | Delivery of public Bootstrap and icon assets used by the application interface | Global CDN | Public asset delivery; no workspace content is sent intentionally |
Where personal data is transferred outside the European Economic Area, we rely on Standard Contractual Clauses adopted by the European Commission under Art. 46(2)(c) GDPR, supplemented by provider security commitments where required. The database and every record entered into a workspace are held in the EU.
How changes are notified
Section 6.6 of our Terms commits us to giving reasonable notice before a material change to this list takes effect. You then have 14 days to object on reasonable data-protection grounds. If we cannot resolve the objection, either of us may terminate the affected subscription and we refund the unused portion.
In practice that means three things happen together: the change is added to the history below, the Privacy Policy's effective date moves, and we email the full administrators of every active workspace. If you would rather a specific person at your organisation received that email, tell us at support@auditschedule.com.
Change history
| Date | Change |
|---|---|
| 19 September 2026 | Added Cloudflare (off-platform backup storage), Vercel (application hosting) and Sentry (error monitoring). Cloudflare was engaged on 18 September 2026 when off-platform backups began; Vercel and Sentry had been in use since launch and were missing from this list rather than newly added. |
| 2 July 2026 | First published list: Supabase, Stripe, Resend, Google, Upstash, Anthropic and jsDelivr. |
Questions? support@auditschedule.com · Privacy Policy · Terms of Service