Subprocessors

Every provider that touches data, and what it gets.

Each provider that handles data on the Desk's behalf, what it receives, where it runs, and how you are told before one is added. The same list is schedule 3 of the data processing agreement.

Providers

ProviderReceivesWhere
Fly.ioHosts the application and customer databases; infrastructure snapshotsLondon deployment
Tigris or compatible S3 object storageOffsite database backups, encrypted by the Desk before upload. The provider holds ciphertext it cannot readLondon, United Kingdom (single-region since 17 September 2026)
PaddleAccount and payment details. Never uploaded listsPaddle's own regions
Resend or a configured SMTP providerPassword resets, account notices and assisted-help requests with the account reply addressProvider's own regions
AnthropicColumn header labels only, only when deterministic mapping fails and the feature is on. Never contact rowsProvider's own regions
Customer-chosen sendersMessages you approve, when sending is live. Not part of the free previewYour provider

This site serves its own fonts. Service-availability information is fetched from the LRD application. Following a provider or social link opens that provider’s site.

How this list is kept true

Each line below is a rule this list depends on, with where it is enforced. Every item below is met.

  • In placeEvery provider named in the privacy notice appears here with what it receives.
  • In placeFonts are served locally; availability uses the LRD application.
  • In placeBackup storage region stated precisely. Since 17 September 2026 backups are written to a single-region bucket in London, United Kingdom. Copies written earlier to the previous multi-region bucket are removed on the same 30-day schedule by every backup pass, and the retention check counts them. Same provider, so no change notice was owed; the list records this as a narrowing, which test/subprocessor-change-notice refuses if a provider was added or replaced.
  • In placeThe app’s own pages load no font or asset from a third party. Proven by test/privacy-claims-hold.
  • In placeChange-notice mechanism implemented and tested. The list lives in one place in the product and is hashed, so it cannot be edited quietly; a change under fourteen days is refused unless it records why security or continuity required it; the notice goes to every account and states the objection right. Proven by test/subprocessor-change-notice, and an unsent notice shows in the deep health check.
  • In placeAny scanning service added to the stack is listed before it handles a file. The malware scanner runs on the Desk’s own machine and no third party receives a file; the code can tell the difference, and pointing it at a hosted scanner would make that scanner a subprocessor and fail the check above until it is listed here.

The contractual version: data processing agreement, schedule 3. Adding or replacing a provider that would process uploaded lists comes with at least 14 days’ notice by account email.