Disciplines Products Pricing About Platform Start a conversation

Our subprocessors.

Every provider that processes personal data on our behalf to run stomwerk.com and the platform apps - what each one does, where it processes data, and the transfer mechanism that covers it. Changes land here first, dated.

OperatorStomwerk AB, Sweden
Change notice30 days, by email
Last updated13 July 2026

How changes are notified.

Customers with a Stomwerk DPA receive at least 30 days' notice before a subprocessor is added or replaced: we email the owner accounts of every affected workspace, and we record the change as a dated entry in the change log on this page. Objections on reasonable data protection grounds go to [email protected] within the notice period.

The list.

Customer data is stored in the EU - Postgres in Frankfurt for records and attachments, and an EU-jurisdiction Cloudflare R2 bucket for stomwerk content media. The table records where each vendor processes data and the transfer mechanism where processing touches the US.

VendorRoleLocation of processingTransfer mechanism
SupabasePrimary database hosting (Postgres, including file attachments stored in-database)EU - Frankfurt (eu-central-1); US corporate entitySCCs (EU-resident infrastructure; not DPF-certified) + Transfer Impact Assessment
Cloudflare R2Object storage for stomwerk content customer assets: uploaded logos, brand imagery, guideline PDFs and generated mediaEU - bucket created in the R2 EU jurisdiction, stored and processed in EU data centres (EU endpoint only); US corporate entityEU-US Data Privacy Framework (participant 5666) + SCCs fallback
Supabase StorageFallback object store for stomwerk content assets, used only when R2 is not configuredEU - Frankfurt (same Supabase project as the database)SCCs + Transfer Impact Assessment (as Supabase)
VercelApplication hosting and compute for the platform and satellite appsEU - Frankfurt (fra1 function region); routing middleware and CDN cache are global; US corporate entityEU-US Data Privacy Framework (participant 6847) + SCCs fallback
CloudflareMarketing-site hosting (Pages) and form relay (Pages Functions)Global edge network; US corporate entityEU-US Data Privacy Framework (participant 5666) + SCCs fallback; EU Cloud Code of Conduct
AnthropicAI inference for AI-assisted features (Claude API)United StatesSCCs (incorporated in Commercial Terms; not DPF). API data not used for training; retained max 30 days
Amazon Web Services (Bedrock)AI inference for stomwerk content: text generation (Amazon Nova models) and, where enabled, image generation (Stability models)Text: EU - Stockholm (eu-north-1). Images: United States (us-west-2) - Bedrock offers no EU image modelEU-US Data Privacy Framework + SCCs (AWS GDPR DPA, auto-incorporated in the AWS Service Terms). Prompts and outputs are not stored by Bedrock, not used for training and not shared with the model providers; generated images are stored back in the EU
StripePayment processing and subscription billingUnited States (EU-regulated Irish payment entities)EU-US Data Privacy Framework (participant 6436) + SCCs. Independent controller for its own fraud/AML processing
ResendTransactional email (password resets, invitations, verification)United States (storage; EU sending region routes dispatch only)SCCs (not DPF-certified)
HubSpotCRM, contact-form storage and newsletter deliveryEU - EU1 (Frankfurt)Hosted in the EU; EU-US Data Privacy Framework + SCCs at entity level
GitHubSource-code hosting (no customer personal data in the repository)United StatesEU-US Data Privacy Framework (participant 6174)
Plausible AnalyticsMarketing-site analytics, cookie-free and collecting no personal dataEuropean UnionEU-hosted - no third-country transfer

Third-party content providers - not subprocessors.

Map views in the apps fetch tiles directly from the visitor's browser, which exposes the visitor's IP address and requested map coordinates to the provider. These providers act as independent parties, not on Stomwerk's instructions over customer data:

ProviderContentNotes
Esri (ArcGIS)Satellite and map imageryClient-side tile fetches
MapTilerMap tiles (optional)Client-side tile fetches
OpenStreetMap (incl. Nominatim)Map data and geocodingClient-side fetches

Change log.

DateChange
13 July 2026Added Amazon Web Services (Bedrock): stomwerk content text generation on Amazon Nova in Stockholm (EU-resident), and AI image generation on Stability models in a US region (no EU image model exists on Bedrock). Prompts are processed transiently - not stored, not used for training; generated images are stored in the EU.
6 July 2026Added Cloudflare R2 (object storage for stomwerk content customer assets, EU jurisdiction bucket) and Supabase Storage (EU fallback object store). Defined the change-notification mechanism: 30 days' email notice to workspace owners plus this dated change log.
2 July 2026Replaced GA4 with Plausible Analytics (EU-hosted, cookie-free).
1 July 2026Initial published list: Supabase, Vercel, Cloudflare, Anthropic, Stripe, Resend, HubSpot, GitHub.