Template document.This is a template document. Final legal review by a qualified data protection counsel is recommended before signing commercial agreements. Contact support@cindera.eu for the signed version.

Cindera · Sub-processors

Sub-processors

Last updated · 2026-08-22

Section 01

About this list

Under Article 28 of the GDPR, a sub-processor is a third party engaged by Cindera (the processor) to process personal data on behalf of our customers (the controllers). Each sub-processor is bound by a written contract that imposes data-protection obligations no less protective than those Cindera owes the customer under the Data Processing Agreement.

Cindera deliberately keeps this list small. We use a limited set of carefully chosen vendors that provide a clear technical purpose, maintain independently audited security programmes, and operate in regions compatible with the customer's data-residency expectations. Existing customers are notified by email at least 30 days before we add or replace a sub-processor that processes personal data, giving them an opportunity to object on reasonable grounds.

Section 02

Current sub-processors

Supabase

Managed PostgreSQL database hosting

Location
EU (Frankfurt, eu-central-1)
Compliance
SOC 2 Type II, HIPAA, GDPR compliant
Data processed
Application data, tenant records, scan results, audit logs, and the generated report PDFs in a private bucket.

Vercel

Application hosting and content delivery

Location
Application code runs in the EU (Frankfurt, fra1), pinned in our repository. The content delivery network in front of it is global: a request is accepted by whichever edge location is nearest and forwarded to Frankfurt, so connection metadata such as an IP address may be handled outside the EU. Covered by Standard Contractual Clauses.
Compliance
SOC 2 Type II, ISO 27001, GDPR compliant
Data processed
Application code execution in Frankfurt. No persistent data storage: nothing is written to disk by the platform. Edge nodes route requests and cache static assets; they do not run application logic or touch scan data.

Upstash

Redis for rate limiting

Location
EU (Frankfurt)
Compliance
SOC 2 Type II, GDPR compliant
Data processed
Ephemeral rate-limit counters. No personal data persisted.

Inngest

Background job queue (scans, reports, retention, monitoring)

Location
US-hosted. Standard Contractual Clauses in place for personal-data transfer.
Compliance
SOC 2 Type II
Data processed
Pseudonymous record references only: tenant, scan and finding identifiers. These are not re-identifiable without our database, which stays in Frankfurt. Names, titles, email addresses and domains are no longer sent; each job reads what it needs from the EU database when it runs.

Resend

Transactional email delivery (sign-in, alerts, report notices)

Location
US-hosted. Standard Contractual Clauses in place for personal-data transfer.
Compliance
SOC 2 Type II, GDPR compliant
Data processed
The recipient's email address and a generic subject line. Reports are not attached and emails name no accounts, tenants or findings: they link to the dashboard or to a time-limited download whose document stays in Frankfurt. A recipient address does identify the customer, which is inherent to sending email at all.

Sentry

Application error monitoring

Location
EU (Germany)
Compliance
SOC 2 Type II, ISO 27001, GDPR compliant
Data processed
Error reports: exception type, message and stack trace, plus the URL and browser of the affected session. Configured with user identifiers and request bodies switched off, so directory data and scan results are not sent.

Stripe

Subscription billing and payment processing

Location
US-hosted, with EU processing for European customers. Standard Contractual Clauses in place for personal-data transfer.
Compliance
SOC 2 Type II, ISO 27001, PCI DSS Level 1, GDPR compliant
Data processed
Billing contact details, company name, VAT number and payment-method data. Card details are captured by Stripe directly and never reach Cindera's systems.

Section 03

Transfers outside the EU, in detail

Three of the providers above operate from the United States. Saying "Standard Contractual Clauses apply" is true but not informative, so this sets out per provider what actually reaches them and what we do to keep that to a minimum.

  • Inngest. Receives pseudonymous record identifiers: tenant, scan and finding ids. Those identifiers are still personal data under the GDPR, but they cannot be resolved to a person without our database, which is in Frankfurt. Names, finding titles, email addresses and domains are not transmitted; each job reads what it needs from the EU database at the moment it runs. Transfer mechanism: Standard Contractual Clauses.
  • Resend.Receives the recipient's email address and a generic subject line that names no tenant, account or finding. Reports are never attached: a scheduled report links to a document that stays in Frankfurt. A recipient address does identify the customer, which is inherent to sending email at all rather than something we can design away. Transfer mechanism: Standard Contractual Clauses.
  • Stripe. Receives billing contact details, company name, VAT number and payment method for paying customers. Unrelated to the Microsoft 365 directory: no scan data, no findings, no directory objects. Card details are captured by Stripe directly and never reach our systems. Transfer mechanism: Standard Contractual Clauses.
  • Vercel. Application code runs in Frankfurt. The global delivery network in front of it means connection metadata, such as an IP address, may be handled by an edge location outside the EU before the request is forwarded. Edge nodes do not execute application logic and never see scan data. Transfer mechanism: Standard Contractual Clauses.

Supabase, Upstash and Sentry are configured to EU regions and are not the subject of a transfer.

Section 04

Changes to this list

We will provide notice via email to existing Customers at least 30 days before adding or replacing a sub-processor that processes personal data on behalf of the Customer. The notice will describe the new sub-processor, the service it provides, its hosting region, and the categories of personal data involved.

Customers may object to the change on reasonable data-protection grounds by emailing support@cindera.eu within the notice period. If objections cannot be resolved between the parties, the Customer may terminate the affected service in accordance with the Terms of Service.