Cindera · Sub-processors
Sub-processors
Last updated · 2026-08-22
Section 01
About this list
Under Article 28 of the GDPR, a sub-processor is a third party engaged by Cindera (the processor) to process personal data on behalf of our customers (the controllers). Each sub-processor is bound by a written contract that imposes data-protection obligations no less protective than those Cindera owes the customer under the Data Processing Agreement.
Cindera deliberately keeps this list small. We use a limited set of carefully chosen vendors that provide a clear technical purpose, maintain independently audited security programmes, and operate in regions compatible with the customer's data-residency expectations. Existing customers are notified by email at least 30 days before we add or replace a sub-processor that processes personal data, giving them an opportunity to object on reasonable grounds.
Section 02
Current sub-processors
Supabase
Managed PostgreSQL database hosting
- Location
- EU (Frankfurt, eu-central-1)
- Compliance
- SOC 2 Type II, HIPAA, GDPR compliant
- Data processed
- Application data, tenant records, scan results, audit logs, and the generated report PDFs in a private bucket.
Vercel
Application hosting and content delivery
- Location
- Application code runs in the EU (Frankfurt, fra1), pinned in our repository. The content delivery network in front of it is global: a request is accepted by whichever edge location is nearest and forwarded to Frankfurt, so connection metadata such as an IP address may be handled outside the EU. Covered by Standard Contractual Clauses.
- Compliance
- SOC 2 Type II, ISO 27001, GDPR compliant
- Data processed
- Application code execution in Frankfurt. No persistent data storage: nothing is written to disk by the platform. Edge nodes route requests and cache static assets; they do not run application logic or touch scan data.
Upstash
Redis for rate limiting
- Location
- EU (Frankfurt)
- Compliance
- SOC 2 Type II, GDPR compliant
- Data processed
- Ephemeral rate-limit counters. No personal data persisted.
Inngest
Background job queue (scans, reports, retention, monitoring)
- Location
- US-hosted. Standard Contractual Clauses in place for personal-data transfer.
- Compliance
- SOC 2 Type II
- Data processed
- Pseudonymous record references only: tenant, scan and finding identifiers. These are not re-identifiable without our database, which stays in Frankfurt. Names, titles, email addresses and domains are no longer sent; each job reads what it needs from the EU database when it runs.
Resend
Transactional email delivery (sign-in, alerts, report notices)
- Location
- US-hosted. Standard Contractual Clauses in place for personal-data transfer.
- Compliance
- SOC 2 Type II, GDPR compliant
- Data processed
- The recipient's email address and a generic subject line. Reports are not attached and emails name no accounts, tenants or findings: they link to the dashboard or to a time-limited download whose document stays in Frankfurt. A recipient address does identify the customer, which is inherent to sending email at all.
Sentry
Application error monitoring
- Location
- EU (Germany)
- Compliance
- SOC 2 Type II, ISO 27001, GDPR compliant
- Data processed
- Error reports: exception type, message and stack trace, plus the URL and browser of the affected session. Configured with user identifiers and request bodies switched off, so directory data and scan results are not sent.
Stripe
Subscription billing and payment processing
- Location
- US-hosted, with EU processing for European customers. Standard Contractual Clauses in place for personal-data transfer.
- Compliance
- SOC 2 Type II, ISO 27001, PCI DSS Level 1, GDPR compliant
- Data processed
- Billing contact details, company name, VAT number and payment-method data. Card details are captured by Stripe directly and never reach Cindera's systems.
| Provider | Purpose | Location | Compliance | Data processed |
|---|---|---|---|---|
| Supabase | Managed PostgreSQL database hosting | EU (Frankfurt, eu-central-1) | SOC 2 Type II, HIPAA, GDPR compliant | Application data, tenant records, scan results, audit logs, and the generated report PDFs in a private bucket. |
| Vercel | Application hosting and content delivery | Application code runs in the EU (Frankfurt, fra1), pinned in our repository. The content delivery network in front of it is global: a request is accepted by whichever edge location is nearest and forwarded to Frankfurt, so connection metadata such as an IP address may be handled outside the EU. Covered by Standard Contractual Clauses. | SOC 2 Type II, ISO 27001, GDPR compliant | Application code execution in Frankfurt. No persistent data storage: nothing is written to disk by the platform. Edge nodes route requests and cache static assets; they do not run application logic or touch scan data. |
| Upstash | Redis for rate limiting | EU (Frankfurt) | SOC 2 Type II, GDPR compliant | Ephemeral rate-limit counters. No personal data persisted. |
| Inngest | Background job queue (scans, reports, retention, monitoring) | US-hosted. Standard Contractual Clauses in place for personal-data transfer. | SOC 2 Type II | Pseudonymous record references only: tenant, scan and finding identifiers. These are not re-identifiable without our database, which stays in Frankfurt. Names, titles, email addresses and domains are no longer sent; each job reads what it needs from the EU database when it runs. |
| Resend | Transactional email delivery (sign-in, alerts, report notices) | US-hosted. Standard Contractual Clauses in place for personal-data transfer. | SOC 2 Type II, GDPR compliant | The recipient's email address and a generic subject line. Reports are not attached and emails name no accounts, tenants or findings: they link to the dashboard or to a time-limited download whose document stays in Frankfurt. A recipient address does identify the customer, which is inherent to sending email at all. |
| Sentry | Application error monitoring | EU (Germany) | SOC 2 Type II, ISO 27001, GDPR compliant | Error reports: exception type, message and stack trace, plus the URL and browser of the affected session. Configured with user identifiers and request bodies switched off, so directory data and scan results are not sent. |
| Stripe | Subscription billing and payment processing | US-hosted, with EU processing for European customers. Standard Contractual Clauses in place for personal-data transfer. | SOC 2 Type II, ISO 27001, PCI DSS Level 1, GDPR compliant | Billing contact details, company name, VAT number and payment-method data. Card details are captured by Stripe directly and never reach Cindera's systems. |
Section 03
Transfers outside the EU, in detail
Three of the providers above operate from the United States. Saying "Standard Contractual Clauses apply" is true but not informative, so this sets out per provider what actually reaches them and what we do to keep that to a minimum.
- Inngest. Receives pseudonymous record identifiers: tenant, scan and finding ids. Those identifiers are still personal data under the GDPR, but they cannot be resolved to a person without our database, which is in Frankfurt. Names, finding titles, email addresses and domains are not transmitted; each job reads what it needs from the EU database at the moment it runs. Transfer mechanism: Standard Contractual Clauses.
- Resend.Receives the recipient's email address and a generic subject line that names no tenant, account or finding. Reports are never attached: a scheduled report links to a document that stays in Frankfurt. A recipient address does identify the customer, which is inherent to sending email at all rather than something we can design away. Transfer mechanism: Standard Contractual Clauses.
- Stripe. Receives billing contact details, company name, VAT number and payment method for paying customers. Unrelated to the Microsoft 365 directory: no scan data, no findings, no directory objects. Card details are captured by Stripe directly and never reach our systems. Transfer mechanism: Standard Contractual Clauses.
- Vercel. Application code runs in Frankfurt. The global delivery network in front of it means connection metadata, such as an IP address, may be handled by an edge location outside the EU before the request is forwarded. Edge nodes do not execute application logic and never see scan data. Transfer mechanism: Standard Contractual Clauses.
Supabase, Upstash and Sentry are configured to EU regions and are not the subject of a transfer.
Section 04
Changes to this list
We will provide notice via email to existing Customers at least 30 days before adding or replacing a sub-processor that processes personal data on behalf of the Customer. The notice will describe the new sub-processor, the service it provides, its hosting region, and the categories of personal data involved.
Customers may object to the change on reasonable data-protection grounds by emailing support@cindera.eu within the notice period. If objections cannot be resolved between the parties, the Customer may terminate the affected service in accordance with the Terms of Service.
