Subprocessors
Last updated: 1 October 2026
These providers help us run Tandly Cloud and may process Customer personal data on our behalf, under the Data Processing Addendum. We announce changes here at least 30 days before they take effect. To get updates by e-mail, write to [email protected].
We are moving production from netcup to Google Cloud, with files on Cloudflare R2. During the move both are in use. All Customer Data is stored in the EU.
| Subprocessor | Purpose | Data | Location | Transfer safeguard |
|---|---|---|---|---|
| netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany | Our current production servers: application, database, file storage and backups. Being replaced by Google Cloud; we will remove it here once the migration is complete and its data has been deleted | All Customer Data | Germany (EU) | Within the EU/EEA |
| Google Cloud EMEA Limited, Velasco, Clanwilliam Place, Dublin 2, Ireland (Google Cloud; part of the Google group, whose parent is Google LLC, USA) | Application servers (Cloud Run), database (Cloud SQL), cache (Memorystore), secrets (Secret Manager), logs and monitoring (Cloud Logging and Monitoring), load balancer and firewall (Cloud Armor), database backups | All Customer Data | europe-west4 (Netherlands) and europe-west1 (Belgium); database backups in Google's EU multi-region | Stored in the EU/EEA. EU–US Data Privacy Framework and Standard Contractual Clauses for any access from outside the EU, such as by Google's support |
| Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA | (1) File storage (R2) for all uploaded files and images. (2) The network in front of the app and API: DNS, TLS termination, protection against attacks. (3) Hosting our status page (Workers) | (1) All uploaded files. (2) All traffic in transit, including IP addresses and the content of requests. (3) Visitors' IP addresses; no Customer Data | (1) EU: the bucket is restricted to R2's EU jurisdiction. (2) Cloudflare's global network, usually the data centre nearest the user. (3) Global | EU–US Data Privacy Framework, Standard Contractual Clauses |
| Twilio Inc. (SendGrid), 101 Spear Street, San Francisco, CA 94105, USA | Sends our e-mail: address confirmation, password resets, security alerts, billing and administrator notices | Recipient's e-mail address and name, and the content of the e-mail (a new sign-in alert names the device and IP address) | USA | EU–US Data Privacy Framework, Standard Contractual Clauses |
| 650 Industries, Inc. (Expo), Palo Alto, USA — once the mobile apps are published | Relays push notifications to the Tandly mobile apps | Push token, notification title and preview, identifiers and links to open in the app | USA | Standard Contractual Clauses |
| Google LLC (Firebase Cloud Messaging) | Delivers push notifications to Android devices | Push token, notification title and preview, identifiers and links to open in the app | USA / global | EU–US Data Privacy Framework, Standard Contractual Clauses |
| Apple Inc. (Apple Push Notification service) | Delivers push notifications to iOS devices | Push token, notification title and preview, identifiers and links to open in the app | USA / global | EU–US Data Privacy Framework, Standard Contractual Clauses |
Google Cloud also checks every minute, from locations in Europe, the Americas and Asia-Pacific, that the service answers. These checks only call a health endpoint and carry no personal data. Cloudflare keeps its own operational logs of the traffic it carries under its data processing terms; we have not switched on any export of those logs to us.
Not subprocessors, but good to know
- Your browser's push service (for example Google for Chrome, Mozilla for Firefox, Apple for Safari, or Microsoft for Edge) delivers web notifications. Your browser chooses the service. The notification is encrypted end to end to your browser, so the push service cannot read it. You can turn web notifications off in the app or in your browser.
- Google and Apple sign-in, and single sign-on through the Customer's own identity provider: when a User signs in this way, those providers act under their own terms or under the Customer's agreement with them.
- Google Workspace directory sync and SCIM provisioning run against the Customer's own Google Workspace or identity provider, under the Customer's agreement with them.
- Google Calendar and Google Drive: when a User connects them, we read them under that User's authorisation and Google's terms.
- Integrations that the Customer configures (webhooks, bots, slash commands) receive data because the Customer instructs us to send it there.
Planned
- Stripe Payments Europe, Ltd. (card payments and invoices on paid plans), Dublin, Ireland. It processes the billing contact's name, e-mail address and billing details, and the card itself never reaches us. Stripe acts for our billing relationship with the Customer, not on Customer Data. We will list it above at least 30 days before card payments are switched on for customers.