##The list
| Function | What it is used for | Data it can reach | Where |
|---|---|---|---|
| Cloud hosting provider | Application servers, database and backups | All workspace data | Workspace region only |
| Transactional email provider | Account mail, approval requests, breach and renewal notices, website form delivery | Name, email address, notification content | EU and India |
| Messaging provider | WhatsApp intake, where a workspace enables it | Sender number, message text, attachments | Provider network |
| Payment processor | Card payments, invoices and tax handling | Billing name, address, country, card token | Global, PCI DSS Level 1 |
| Error monitoring | Application exceptions and performance traces | Workspace identifier, request path, stack trace | EU |
| Object storage | Ticket attachments and generated report files | Attachments, exports, PDF reports | Workspace region only |
| External uptime monitoring | Measuring availability from outside our network | No customer data - public endpoints only | Three regions |
Named vendors, their contractual terms and their current certifications are provided on request through the contact page, under a mutual non-disclosure agreement where your procurement process requires one. Select Security or procurement review and the pack comes back without you having to chase it.
##What each one touches
Hosting and object storage are the only subprocessors with access to the full workspace, and they are region-locked to the region chosen when the workspace was created. Data does not move between regions, including for support.
Transactional email receives the content of what it sends: an approval request names the action and the device, a renewal notice names the product and the seat count. It receives no device inventory and no ticket history beyond what appears in a notification.
The messaging provider is only involved where a workspace turns on WhatsApp intake. Messages pass through its network before reaching us; this is inherent to the channel and is the reason it is optional.
The payment processor never receives workspace content. We never hold a full card number - only a token, the billing details and the last four digits.
Error monitoring receives exceptions with the workspace identifier and the request path. Ticket text, device inventory and licence keys are stripped before a trace leaves our systems.
Uptime monitoring touches no customer data at all. It requests public endpoints from outside our network, which is what makes the status page worth reading.
##Deliberately absent
What is not on this list says as much as what is, so here it is explicitly.
- No advertising or analytics platforms. This website carries no third-party analytics script and no advertising tracker.
- No session replay tooling. Nobody records what you do in the dashboard.
- No third-party AI provider receives workspace content. Classification and similar-ticket matching run inside our own infrastructure, within the boundary of the workspace that created the records. No ticket text is sent to an external model provider.
- No data brokers or enrichment services. We do not append anything to what you give us.
- No marketing automation platform. There is no sequence to be put into, which is why signing up produces exactly one email.
##Region and transfers
A workspace region is chosen at creation and fixed afterwards. Workspace content stays in that region. Where a subprocessor operates outside it - transactional email, the messaging provider, payments - the data it receives is limited to what is described above, and the transfer is covered by standard contractual clauses.
If your procurement rules require everything within a single jurisdiction, say so before you start. WhatsApp intake is the usual sticking point, and it can simply be left off.
##Changes to this list
Workspace admins are notified at least 30 days before a new subprocessor with access to workspace data starts handling it. If you object on reasonable grounds, tell us within that window: we will either work around it for your workspace or, where that is not possible, let you cancel with a pro rata refund of anything prepaid.
Removing a subprocessor, or replacing one with something we run ourselves, is not notified in advance. It appears in the changelog.
##How they are chosen
Four things, applied before anything is signed.
- Can we avoid it? The shortest list is the best list. Several functions here were third-party once and are not any more.
- What is the blast radius? A subprocessor that can reach the full workspace is held to a different standard than one that receives a stack trace.
- Does it support our region commitment? A vendor that cannot keep data in one region cannot hold workspace content, whatever else it offers.
- Can we leave? Exportable data and a realistic migration path, assessed at the point of choosing rather than at the point of needing it.
