Subprocessors
Effective from 2026-09-12
This page lists, separately, the providers that process personal data a customer enters into its workspace on the customer’s behalf — subprocessors under the Data Processing Agreement — and the providers we use for our own processing as controller. A provider appears here only if it actually receives personal data today — not because an integration or library exists for it.
1. Subprocessors under the DPA — Customer Personal Data
These providers process Customer Personal Data — data a customer enters into its workspace, such as employee records, requests and approvals — on the customer’s behalf. Article 28 GDPR and the notice and objection process in the Data Processing Agreement apply to them.
| Provider | Purpose | Customer Personal Data | Location |
|---|---|---|---|
| Microsoft Azure | Application hosting, database, object storage, logs, secrets | All data in the service | EU — Poland Central |
| Clerk, Inc. | Sign-in of the customer’s users, and delivery of workspace invitations | Name and email address of invited and signed-in users, user identifier, authentication metadata | USA — transfer under a Chapter V GDPR mechanism set out in the provider’s data processing agreement |
| Resend, Inc. | Delivery of service email, including request and approval notifications to the customer’s users | Recipient name and email address, message content | USA — transfer under a Chapter V GDPR mechanism set out in the provider’s data processing agreement |
2. Other processors and recipients — Tivero’s own processing as controller
These providers process personal data for purposes Tivero determines itself: running accounts and sign-in security, billing, usage analytics with consent, and our own correspondence. They are described in the Privacy Policy. They are not subprocessors under the Data Processing Agreement, and its notice and objection process does not apply to changes among them.
| Provider | Purpose | Personal data | Location | Role |
|---|---|---|---|---|
| Clerk, Inc. | Account sign-in, session security and abuse prevention | User identifier, email address, authentication and session metadata | USA — transfer under a Chapter V GDPR mechanism set out in the provider’s data processing agreement | Processor for Tivero |
| Resend, Inc. | Account, security and billing messages | Recipient email address and name, message content | USA — transfer under a Chapter V GDPR mechanism set out in the provider’s data processing agreement | Processor for Tivero |
| PostHog, Inc. | Usage analytics — only with consent | Pseudonymous identifier, usage events | EU cloud (eu.i.posthog.com) | Processor for Tivero |
| Microsoft 365 | Receiving correspondence sent to the contact address | Content of messages sent to us | According to the data location of Tivero’s Microsoft 365 tenant | Processor for Tivero |
| Stripe | Payments, invoices and tax calculation for paid subscriptions | Company billing details and the billing contact; no data about the customer’s employees | According to Stripe’s data processing terms | Processor for Tivero for billing; separate controller for its payment-services and fraud-prevention obligations |
3. Providers that receive no personal data
- Calendarific, the public-holiday data source, receives only a country code, a year and a day type.
- Google Tag Manager is loaded on tivero.app only after marketing consent, holds no tags, and receives no customer data.
4. Changes to this list
Section 1. Before a new or replacement subprocessor starts processing Customer Personal Data, we update this page and email the owner of each workspace at least 14 days in advance, except where an urgent change is needed for the security or continuity of the service. The customer may object on reasonable data-protection grounds, as set out in the Data Processing Agreement.
Section 2. Changes to the providers we use for our own processing are published on this page and in the Privacy Policy.
Questions: hello@tivero.app.