Our subprocessors.
Every provider that processes personal data on our behalf to run stomwerk.com and the platform apps - what each one does, where it processes data, and the transfer mechanism that covers it. Changes land here first, dated.
How changes are notified.
Customers with a Stomwerk DPA receive at least 30 days' notice before a subprocessor is added or replaced: we email the owner accounts of every affected workspace, and we record the change as a dated entry in the change log on this page. Objections on reasonable data protection grounds go to [email protected] within the notice period.
The list.
Customer data is stored in the EU - Postgres in Frankfurt for records and attachments, and an EU-jurisdiction Cloudflare R2 bucket for stomwerk content media. The table records where each vendor processes data and the transfer mechanism where processing touches the US.
| Vendor | Role | Location of processing | Transfer mechanism |
|---|---|---|---|
| Supabase | Primary database hosting (Postgres, including file attachments stored in-database) | EU - Frankfurt (eu-central-1); US corporate entity | SCCs (EU-resident infrastructure; not DPF-certified) + Transfer Impact Assessment |
| Cloudflare R2 | Object storage for stomwerk content customer assets: uploaded logos, brand imagery, guideline PDFs and generated media | EU - bucket created in the R2 EU jurisdiction, stored and processed in EU data centres (EU endpoint only); US corporate entity | EU-US Data Privacy Framework (participant 5666) + SCCs fallback |
| Supabase Storage | Fallback object store for stomwerk content assets, used only when R2 is not configured | EU - Frankfurt (same Supabase project as the database) | SCCs + Transfer Impact Assessment (as Supabase) |
| Vercel | Application hosting and compute for the platform and satellite apps | EU - Frankfurt (fra1 function region); routing middleware and CDN cache are global; US corporate entity | EU-US Data Privacy Framework (participant 6847) + SCCs fallback |
| Cloudflare | Marketing-site hosting (Pages) and form relay (Pages Functions) | Global edge network; US corporate entity | EU-US Data Privacy Framework (participant 5666) + SCCs fallback; EU Cloud Code of Conduct |
| Anthropic | AI inference for AI-assisted features (Claude API) | United States | SCCs (incorporated in Commercial Terms; not DPF). API data not used for training; retained max 30 days |
| Amazon Web Services (Bedrock) | AI inference for stomwerk content: text generation (Amazon Nova models) and, where enabled, image generation (Stability models) | Text: EU - Stockholm (eu-north-1). Images: United States (us-west-2) - Bedrock offers no EU image model | EU-US Data Privacy Framework + SCCs (AWS GDPR DPA, auto-incorporated in the AWS Service Terms). Prompts and outputs are not stored by Bedrock, not used for training and not shared with the model providers; generated images are stored back in the EU |
| Stripe | Payment processing and subscription billing | United States (EU-regulated Irish payment entities) | EU-US Data Privacy Framework (participant 6436) + SCCs. Independent controller for its own fraud/AML processing |
| Resend | Transactional email (password resets, invitations, verification) | United States (storage; EU sending region routes dispatch only) | SCCs (not DPF-certified) |
| HubSpot | CRM, contact-form storage and newsletter delivery | EU - EU1 (Frankfurt) | Hosted in the EU; EU-US Data Privacy Framework + SCCs at entity level |
| GitHub | Source-code hosting (no customer personal data in the repository) | United States | EU-US Data Privacy Framework (participant 6174) |
| Plausible Analytics | Marketing-site analytics, cookie-free and collecting no personal data | European Union | EU-hosted - no third-country transfer |
Third-party content providers - not subprocessors.
Map views in the apps fetch tiles directly from the visitor's browser, which exposes the visitor's IP address and requested map coordinates to the provider. These providers act as independent parties, not on Stomwerk's instructions over customer data:
| Provider | Content | Notes |
|---|---|---|
| Esri (ArcGIS) | Satellite and map imagery | Client-side tile fetches |
| MapTiler | Map tiles (optional) | Client-side tile fetches |
| OpenStreetMap (incl. Nominatim) | Map data and geocoding | Client-side fetches |
Change log.
| Date | Change |
|---|---|
| 13 July 2026 | Added Amazon Web Services (Bedrock): stomwerk content text generation on Amazon Nova in Stockholm (EU-resident), and AI image generation on Stability models in a US region (no EU image model exists on Bedrock). Prompts are processed transiently - not stored, not used for training; generated images are stored in the EU. |
| 6 July 2026 | Added Cloudflare R2 (object storage for stomwerk content customer assets, EU jurisdiction bucket) and Supabase Storage (EU fallback object store). Defined the change-notification mechanism: 30 days' email notice to workspace owners plus this dated change log. |
| 2 July 2026 | Replaced GA4 with Plausible Analytics (EU-hosted, cookie-free). |
| 1 July 2026 | Initial published list: Supabase, Vercel, Cloudflare, Anthropic, Stripe, Resend, HubSpot, GitHub. |