Who processes data for us
We use a small number of providers to run the service. This list is factual and reflects the deployment as it stands; we will update it before adding a new sub-processor.
| Sub-processor | Purpose | Data it handles | Location |
|---|---|---|---|
| Neon (database) | The application database | All register content, evidence metadata, users and the audit log | Data resides in the European Union (Frankfurt, Germany). Neon Inc. is incorporated in the United States, so support access is covered by standard contractual clauses |
| Vercel Inc. | Application hosting, content delivery and blob storage for uploaded evidence | Requests, uploaded evidence files, operational logs | Vercel Inc. is incorporated in the United States and transfers rely on standard contractual clauses. Application functions and evidence storage are pinned to the European Union (Frankfurt); the content delivery network operates globally and carries no register content |
| Sentry (Functional Software, Inc.) | Error and performance monitoring, so a failure is diagnosable | Error messages, stack traces and the route a failure happened on. Request bodies, cookies, authorisation headers and query strings are removed before sending, and record identifiers in the path are replaced, so no register content and no document reaches it | European Union (Sentry EU region). Enforced in code: if the configured endpoint is not in the EU region, monitoring is switched off rather than sent elsewhere |
| Resend | Transactional email (sign-in links, invitations, digests) | Recipient name and email address, message content | United States, under standard contractual clauses |
| Anthropic PBC, via Vercel AI Gateway | Treica Assist only, and only when the add-on is on the contract AND an owner has switched it on | Only the document or answers submitted for that specific action; never the register | United States, under standard contractual clauses; not used for model training |
What is not sub-processed
- There is no advertising provider, no analytics or tracking provider, and no cookie is set for either. Sentry is error and performance monitoring, not audience measurement: it is told that a route failed, never who was using it.
- AI providers receive nothing at all unless a workspace is entitled AND an owner has enabled AI - and then only that action's own input.
- No provider receives the register as a whole.
- Error monitoring receives no register content and no uploaded document. Request bodies, cookies, authorisation headers and query strings are removed before an event is sent, and record identifiers in the URL are replaced with a placeholder, so a report says which screen failed and not whose record it was.
Changes
We will publish any addition here before it takes effect, so a customer can object under their data processing agreement.