Sub-processors

We use the companies below to run OneBooks. We give at least 30 days’ notice before we add or replace any of them, so you can object first. This page is generated from the register the product actually uses, so it cannot quietly fall behind.

Neon

Hosts the PostgreSQL database in which all customer records are stored.

Processes in
European Union (eu-central-1)
Used since
2025-01-01
Data they can reach
  • Every category of personal data in the service
  • Account details, accounting records, contacts, attachments metadata
Transfers outside the EEA
None required for the primary store — data stays in the EU. Neon is additionally certified under the EU–US Data Privacy Framework.

Cloudflare

Runs the application, the APIs and the public sites, and provides the network and DDoS protection in front of them.

Processes in
Global edge network; US-headquartered
Used since
2025-01-01
Data they can reach
  • Data in transit for every request
  • IP addresses and request metadata
  • Uploaded files held in object storage
Transfers outside the EEA
Standard Contractual Clauses, in Cloudflare’s customer Data Processing Addendum.

Stripe

Takes subscription payments and issues receipts.

Processes in
United States and Ireland
Used since
2025-01-01
Data they can reach
  • Billing name and email
  • Billing country and currency
  • Payment and subscription status
Transfers outside the EEA
Certified under the EU–US Data Privacy Framework, its UK extension and the Swiss–US DPF. Card details never reach our systems.

Resend

Delivers transactional email: verification, password resets, and the invoices and quotes a customer chooses to send.

Processes in
United States
Used since
2025-01-01
Data they can reach
  • Recipient email address
  • Message subject and body, including any attached document
Transfers outside the EEA
⟨TO BE COMPLETED BY THE CONTROLLER⟩ — confirm and file Resend’s DPA and transfer mechanism.

Google public website only

Measures aggregate usage of the public marketing website — and only if the visitor accepts analytics.

Processes in
United States
Used since
2025-01-01
Data they can reach
  • Pseudonymous analytics identifier
  • Pages viewed
  • Approximate location from IP
Transfers outside the EEA
EU–US Data Privacy Framework. IP anonymisation enabled; advertising signals permanently denied under Consent Mode v2.

⟨TO BE COMPLETED BY THE CONTROLLER⟩ — AI model provider

Answers questions the AI assistant is asked, using the accounting data retrieved to answer them.

Processes in
⟨TO BE COMPLETED BY THE CONTROLLER⟩
Used since
2026-09-01
Data they can reach
  • The question the user types
  • Accounting data retrieved to answer it
Transfers outside the EEA
⟨TO BE COMPLETED BY THE CONTROLLER⟩ — name the provider actually enabled in AI_PROVIDER_ORDER, confirm its transfer mechanism, and record the Art. 35 DPIA. The assistant is available on every tier, including Free, so this is not an edge case.

Who is not on this list

Customers ask about these, so here is the reasoning rather than silence.

  • Shopify, Square, Clover, Lightspeed, Loyverse — A sub-processor is one WE engage to process on your behalf. You connect your own POS account and the data flows to us from it. They are a source of your data, not a processor we chose.
  • ZATCA and other tax authorities — A recipient under your own legal obligation to file, not a processor acting on our instructions.
  • Our logging and monitoring — Self-hosted on infrastructure we operate. No third party receives the data, so there is nothing to disclose or object to.