Sub-processors
Traceable engages the following sub-processors to deliver the platform. All sub-processors are contractually bound to handle data in accordance with GDPR and are restricted to processing only the data necessary for their specific function.
Most processing occurs on EU infrastructure. The one exception is the optional Document AI feature: when an operator opts in, the content of the documents submitted to Document AI is transferred to Anthropic, Inc. (United States) for AI extraction, under EU Standard Contractual Clauses (GDPR Art. 46). All other sub-processors operate from EU infrastructure, and no other customer data is processed outside the European Union.
Active Sub-processors
| Provider | Service | Data processed | Infrastructure region | DPA / SCCs |
|---|---|---|---|---|
| Supabase | Database, authentication, file storage | All application data: user accounts, company data, DPP product records, uploaded documents, audit logs, session tokens | EU — Dublin, Ireland (dub1 / AWS eu-west-1) | Supabase DPA + AWS SCCs |
| Vercel | Application hosting, serverless functions, edge network | Request/response data transiting the application layer; no persistent storage | EU — Frankfurt, Germany (fra1) | Vercel DPA + SCCs |
| Resend | Transactional email delivery | Email address, name, email content (notifications, account confirmations, data request notifications) | EU region | Resend DPA |
| Sentry | Error monitoring and performance tracing | Error stack traces, anonymised user context (user ID hash, not name or email), platform performance metrics | EU region | Sentry DPA |
| Upstash | Rate limiting (Redis) | API request metadata (IP address, API key hash, request timestamp) for rate limit counters; no DPP content | EU West (Amsterdam / Frankfurt) | Upstash DPA |
| Anthropic, Inc. | Document AI — AI extraction of structured data from uploaded compliance documents (opt-in only) | Content of the documents an operator submits to Document AI while the feature is enabled; not used to train AI models | United States | Anthropic DPA + EU Standard Contractual Clauses (GDPR Art. 46) |
Sub-processor Details
Supabase
Role: Primary data processor — all Traceable customer data is stored in Supabase's PostgreSQL database and object storage.
Data: User accounts, company profiles, all DPP product data, uploaded compliance documents, audit logs, supplier and material data.
Security: AES-256 encryption at rest; TLS 1.3 in transit; Row-Level Security (RLS) on all tables; SOC 2 Type II compliant; ISO 27001 certified infrastructure (AWS eu-west-1).
Sub-processor disclosure: Supabase uses AWS as its infrastructure provider. AWS eu-west-1 (Ireland) is the hosting region. AWS is subject to the AWS-Supabase SCCs.
Vercel
Role: Application hosting — the Traceable web application and API run on Vercel's serverless platform.
Data: Vercel processes request and response payloads in transit. Vercel does not store application data; all persistence flows through to Supabase. Vercel may retain access logs (IP addresses, request paths, status codes) for a limited period for platform stability purposes.
Security: ISO 27001 certified; SOC 2 Type II; TLS 1.3 for all connections.
Resend
Role: Transactional email delivery — used for platform notifications, account confirmations, data request alerts, and team invitation emails.
Data: Recipient email address, sender name, email subject and body. Email content may include DPP-related notification context (product names, request deadlines) but does not include full DPP data or personal data beyond the recipient's email address.
Retention: Email delivery logs retained per Resend's standard policy (typically 90 days).
Sentry
Role: Error monitoring — used to capture application errors and performance traces to support platform stability.
Data: Error stack traces, anonymised user context (a hashed user ID — not name or email), browser/environment metadata, request paths (no request bodies or DPP data content). Sentry is configured to scrub personal data from error payloads before submission.
Retention: Error events retained for 90 days.
Upstash
Role: Rate limiting — Redis-based sliding window rate limiter applied to all API endpoints.
Data: API request metadata: IP address, API key identifier (hash), and request timestamp. Used only to maintain rate limit counters. No DPP content, no personal data beyond IP address is processed or retained beyond the counter window (typically 60 seconds).
Anthropic, Inc.
Role: Document AI — powers the optional AI extraction feature that reads uploaded compliance documents and proposes structured field values. Document AI is off by default and activates only after an operator opts in.
Data: The content of the documents an operator submits to Document AI while the feature is enabled. Document content is processed to extract structured data; it is not used to train AI models. Document AI is not invoked for operators who have not opted in.
International transfer: Anthropic processes this content on infrastructure in the United States. This is the one processing activity that takes customer data outside the EU. The transfer is covered by an Anthropic DPA incorporating EU Standard Contractual Clauses (GDPR Art. 46) and occurs only for operators who have enabled Document AI.
Changes to Sub-processors
Traceable will provide 30 days' advance notice to operators before engaging any new sub-processor or making a material change to an existing sub-processor's role, where such change affects the processing of customer personal data.
Notifications will be published in the Changelog and, where a DPA is in place, communicated directly to the operator's registered contact.
Further Reading
| Page | Contents |
|---|---|
| Infrastructure | Hosting architecture and data residency guarantees |
| GDPR Implementation | Data subject rights and lawful bases |
| Data Encryption | Encryption standards |