Template document.This is a template document. Final legal review by a qualified data protection counsel is recommended before signing commercial agreements. Contact support@cindera.eu for the signed version.

Cindera · Sub-processors

Sub-processors

Last updated · 2026-06-03

Section 01

About this list

Under Article 28 of the GDPR, a sub-processor is a third party engaged by Cindera (the processor) to process personal data on behalf of our customers (the controllers). Each sub-processor is bound by a written contract that imposes data-protection obligations no less protective than those Cindera owes the customer under the Data Processing Agreement.

Cindera deliberately keeps this list small. We use a limited set of carefully chosen vendors that provide a clear technical purpose, maintain independently audited security programmes, and operate in regions compatible with the customer's data-residency expectations. Existing customers are notified by email at least 30 days before we add or replace a sub-processor that processes personal data, giving them an opportunity to object on reasonable grounds.

Section 02

Current sub-processors

Supabase

Managed PostgreSQL database hosting

Location
EU (Frankfurt, eu-central-1)
Compliance
SOC 2 Type II, HIPAA, GDPR compliant
Data processed
Application data, tenant records, scan results, audit logs.

Vercel

Application hosting and edge runtime

Location
EU regions (Frankfurt fra1 primary)
Compliance
SOC 2 Type II, ISO 27001, GDPR compliant
Data processed
Application code execution. No persistent data storage.

Upstash

Redis for rate limiting

Location
EU (Frankfurt)
Compliance
SOC 2 Type II, GDPR compliant
Data processed
Ephemeral rate-limit counters. No personal data persisted.

Inngest

Background job orchestration

Location
US-hosted. Standard Contractual Clauses in place for personal-data transfer.
Compliance
SOC 2 Type II
Data processed
Job metadata only (tenant IDs, scan IDs). No Microsoft Graph data passes through Inngest payloads.

Resend

Transactional email delivery

Location
US-hosted. Standard Contractual Clauses in place for personal-data transfer.
Compliance
SOC 2 Type II, GDPR compliant
Data processed
Email addresses and report content for assessment results and recurring reports.

Section 03

Changes to this list

We will provide notice via email to existing Customers at least 30 days before adding or replacing a sub-processor that processes personal data on behalf of the Customer. The notice will describe the new sub-processor, the service it provides, its hosting region, and the categories of personal data involved.

Customers may object to the change on reasonable data-protection grounds by emailing support@cindera.eu within the notice period. If objections cannot be resolved between the parties, the Customer may terminate the affected service in accordance with the Terms of Service.