Subprocessors

Version 1.0 · Effective August 30, 2026

This page lists the third parties that process Eden One data. It forms part of the Privacy Policy and may be supplied as it stands for a vendor review, an insurance questionnaire or a broker's compliance check.

1. Infrastructure

ProviderFunctionData processedLocation
SupabaseDatabase, authentication, document storageAccount data and all customer data, including uploaded documentsCentral EU — Frankfurt, Germany (eu-central-1)
VercelApplication hosting and deliveryRequest data in transit; no data at restGlobal edge network

2. Communication

ProviderFunctionData processedLocation
Resend, delivering via Amazon SESTransactional email only: account invitations, password resets, and invoices sent by customers to their brokersRecipient name and email address, message contents, attached invoice PDFsUnited States / European Union
TelegramSupport conversations, where a customer chooses that channelMessage contents supplied by the customerPer Telegram's own terms

We do not use a marketing email platform. No mailing list is created on signup.

3. Payments

3.1 Subscriptions are processed by a third-party payment provider acting as merchant of record. That provider is the seller of record for the transaction and is responsible for invoicing and for collecting and remitting sales tax and VAT.

3.2 The provider receives billing data directly: name, billing address and payment card details. We do not receive or store payment card details.

3.3 The provider receives no customer data. No loads, drivers, documents or invoices are transmitted to it.

3.4 (Provider to be named here once the merchant account is live.)

4. Not used

4.1 No advertising networks.

4.2 No cross-site or third-party analytics.

4.3 No data brokers or list vendors.

4.4 No machine learning training on customer data, by us or by any provider listed above.

5. International transfers

5.1 Where a provider processes personal data outside the European Economic Area, that transfer relies on the mechanisms available under the GDPR, including standard contractual clauses entered into by the relevant provider.

6. Changes

6.1 This page is updated when the list changes and the version and date at the top are revised.

6.2 Account owners are notified before a provider that will process customer data is added.

6.3 Earlier versions are retained in our public repository.

7. Requests

7.1 Requests for a signed data processing addendum, or for a specific security or vendor questionnaire to be completed, may be sent to hello@edenone.app.