Legal

Sub-processors

Last updated: 8 June 2026

Every vendor with access to Tradeflo customer data is listed below. We update this page within 30 days of any addition. Each vendor has its own Data Processing Agreement with us, listed by link below — they're each independently bound by GDPR. We never sell data to any of them, and they never sell data downstream.

VendorWhat they doDataRegionDPA
VercelWebsite + API hosting, edge functionsVisitor IPs (transit only), HTTP request logs (30-day rotation)US-headquartered, EU edge (Frankfurt)View →
SupabasePostgres database, authentication, file storage, edge functionsClient account data, lead records, audit submissions, audit resultsEU — FrankfurtView →
PostHogSite analytics, session replays (only after cookie consent)Pseudonymised visitor events, page views, click paths. No PII.EU-hostedView →
StripePayment processing, subscription billing, KYC for paid clientsCardholder data (held by Stripe, not us), billing email, billing addressIreland (Stripe Payments Europe Ltd, Dublin)View →
ResendTransactional email delivery (audit confirmations, lead alerts)Recipient email, message contentUS-headquartered, EU/US sending infrastructureView →
TwilioSMS + WhatsApp message delivery on behalf of clientsRecipient phone number, message contentTwilio Ireland Ltd (Dublin)View →
Anthropic (Claude API)AI analysis for the free-audit scan and the AI Automation SuiteBusiness name, website URL, public-website scrape results. No customer PII beyond what is needed for the scan.US-headquartered, EU API endpoint availableView →
BrowserlessHeadless browser rendering for audit PDF generationPublic web pages being audited (no personal data unless user submits a PII-laden URL)EU/US infrastructureView →
UpstashRedis for API rate limiting (per-IP + per-domain caps)Hashed IP addresses, request counters. 24-hour rolling window.EU region (Frankfurt) for Tradeflo workloadsView →
Loops / ConvertKitNurture email sequences — only for people who explicitly opt inEmail, name, marketing engagement eventsUSView →

Changes to this list

Active clients are notified by email when we add a new sub-processor. You have a right to object — see the Data Processing Addendum for the formal mechanism. Site visitors who haven't signed up don't need to be notified — refer to this page any time.