Cindera · Sub-processors
Sub-processors
Last updated · 2026-06-03
Section 01
About this list
Under Article 28 of the GDPR, a sub-processor is a third party engaged by Cindera (the processor) to process personal data on behalf of our customers (the controllers). Each sub-processor is bound by a written contract that imposes data-protection obligations no less protective than those Cindera owes the customer under the Data Processing Agreement.
Cindera deliberately keeps this list small. We use a limited set of carefully chosen vendors that provide a clear technical purpose, maintain independently audited security programmes, and operate in regions compatible with the customer's data-residency expectations. Existing customers are notified by email at least 30 days before we add or replace a sub-processor that processes personal data, giving them an opportunity to object on reasonable grounds.
Section 02
Current sub-processors
Supabase
Managed PostgreSQL database hosting
- Location
- EU (Frankfurt, eu-central-1)
- Compliance
- SOC 2 Type II, HIPAA, GDPR compliant
- Data processed
- Application data, tenant records, scan results, audit logs.
Vercel
Application hosting and edge runtime
- Location
- EU regions (Frankfurt fra1 primary)
- Compliance
- SOC 2 Type II, ISO 27001, GDPR compliant
- Data processed
- Application code execution. No persistent data storage.
Upstash
Redis for rate limiting
- Location
- EU (Frankfurt)
- Compliance
- SOC 2 Type II, GDPR compliant
- Data processed
- Ephemeral rate-limit counters. No personal data persisted.
Inngest
Background job orchestration
- Location
- US-hosted. Standard Contractual Clauses in place for personal-data transfer.
- Compliance
- SOC 2 Type II
- Data processed
- Job metadata only (tenant IDs, scan IDs). No Microsoft Graph data passes through Inngest payloads.
Resend
Transactional email delivery
- Location
- US-hosted. Standard Contractual Clauses in place for personal-data transfer.
- Compliance
- SOC 2 Type II, GDPR compliant
- Data processed
- Email addresses and report content for assessment results and recurring reports.
| Provider | Purpose | Location | Compliance | Data processed |
|---|---|---|---|---|
| Supabase | Managed PostgreSQL database hosting | EU (Frankfurt, eu-central-1) | SOC 2 Type II, HIPAA, GDPR compliant | Application data, tenant records, scan results, audit logs. |
| Vercel | Application hosting and edge runtime | EU regions (Frankfurt fra1 primary) | SOC 2 Type II, ISO 27001, GDPR compliant | Application code execution. No persistent data storage. |
| Upstash | Redis for rate limiting | EU (Frankfurt) | SOC 2 Type II, GDPR compliant | Ephemeral rate-limit counters. No personal data persisted. |
| Inngest | Background job orchestration | US-hosted. Standard Contractual Clauses in place for personal-data transfer. | SOC 2 Type II | Job metadata only (tenant IDs, scan IDs). No Microsoft Graph data passes through Inngest payloads. |
| Resend | Transactional email delivery | US-hosted. Standard Contractual Clauses in place for personal-data transfer. | SOC 2 Type II, GDPR compliant | Email addresses and report content for assessment results and recurring reports. |
Section 03
Changes to this list
We will provide notice via email to existing Customers at least 30 days before adding or replacing a sub-processor that processes personal data on behalf of the Customer. The notice will describe the new sub-processor, the service it provides, its hosting region, and the categories of personal data involved.
Customers may object to the change on reasonable data-protection grounds by emailing support@cindera.eu within the notice period. If objections cannot be resolved between the parties, the Customer may terminate the affected service in accordance with the Terms of Service.