Skip to main content

Sub-processors

Traceable engages the following sub-processors to deliver the platform. All sub-processors are contractually bound to handle data in accordance with GDPR and are restricted to processing only the data necessary for their specific function.

Most processing occurs on EU infrastructure. The one exception is the optional Document AI feature: when an operator opts in, the content of the documents submitted to Document AI is transferred to Anthropic, Inc. (United States) for AI extraction, under EU Standard Contractual Clauses (GDPR Art. 46). All other sub-processors operate from EU infrastructure, and no other customer data is processed outside the European Union.


Active Sub-processors

ProviderServiceData processedInfrastructure regionDPA / SCCs
SupabaseDatabase, authentication, file storageAll application data: user accounts, company data, DPP product records, uploaded documents, audit logs, session tokensEU — Dublin, Ireland (dub1 / AWS eu-west-1)Supabase DPA + AWS SCCs
VercelApplication hosting, serverless functions, edge networkRequest/response data transiting the application layer; no persistent storageEU — Frankfurt, Germany (fra1)Vercel DPA + SCCs
ResendTransactional email deliveryEmail address, name, email content (notifications, account confirmations, data request notifications)EU regionResend DPA
SentryError monitoring and performance tracingError stack traces, anonymised user context (user ID hash, not name or email), platform performance metricsEU regionSentry DPA
UpstashRate limiting (Redis)API request metadata (IP address, API key hash, request timestamp) for rate limit counters; no DPP contentEU West (Amsterdam / Frankfurt)Upstash DPA
Anthropic, Inc.Document AI — AI extraction of structured data from uploaded compliance documents (opt-in only)Content of the documents an operator submits to Document AI while the feature is enabled; not used to train AI modelsUnited StatesAnthropic DPA + EU Standard Contractual Clauses (GDPR Art. 46)

Sub-processor Details

Supabase

Role: Primary data processor — all Traceable customer data is stored in Supabase's PostgreSQL database and object storage.

Data: User accounts, company profiles, all DPP product data, uploaded compliance documents, audit logs, supplier and material data.

Security: AES-256 encryption at rest; TLS 1.3 in transit; Row-Level Security (RLS) on all tables; SOC 2 Type II compliant; ISO 27001 certified infrastructure (AWS eu-west-1).

Sub-processor disclosure: Supabase uses AWS as its infrastructure provider. AWS eu-west-1 (Ireland) is the hosting region. AWS is subject to the AWS-Supabase SCCs.

Vercel

Role: Application hosting — the Traceable web application and API run on Vercel's serverless platform.

Data: Vercel processes request and response payloads in transit. Vercel does not store application data; all persistence flows through to Supabase. Vercel may retain access logs (IP addresses, request paths, status codes) for a limited period for platform stability purposes.

Security: ISO 27001 certified; SOC 2 Type II; TLS 1.3 for all connections.

Resend

Role: Transactional email delivery — used for platform notifications, account confirmations, data request alerts, and team invitation emails.

Data: Recipient email address, sender name, email subject and body. Email content may include DPP-related notification context (product names, request deadlines) but does not include full DPP data or personal data beyond the recipient's email address.

Retention: Email delivery logs retained per Resend's standard policy (typically 90 days).

Sentry

Role: Error monitoring — used to capture application errors and performance traces to support platform stability.

Data: Error stack traces, anonymised user context (a hashed user ID — not name or email), browser/environment metadata, request paths (no request bodies or DPP data content). Sentry is configured to scrub personal data from error payloads before submission.

Retention: Error events retained for 90 days.

Upstash

Role: Rate limiting — Redis-based sliding window rate limiter applied to all API endpoints.

Data: API request metadata: IP address, API key identifier (hash), and request timestamp. Used only to maintain rate limit counters. No DPP content, no personal data beyond IP address is processed or retained beyond the counter window (typically 60 seconds).

Anthropic, Inc.

Role: Document AI — powers the optional AI extraction feature that reads uploaded compliance documents and proposes structured field values. Document AI is off by default and activates only after an operator opts in.

Data: The content of the documents an operator submits to Document AI while the feature is enabled. Document content is processed to extract structured data; it is not used to train AI models. Document AI is not invoked for operators who have not opted in.

International transfer: Anthropic processes this content on infrastructure in the United States. This is the one processing activity that takes customer data outside the EU. The transfer is covered by an Anthropic DPA incorporating EU Standard Contractual Clauses (GDPR Art. 46) and occurs only for operators who have enabled Document AI.


Changes to Sub-processors

Traceable will provide 30 days' advance notice to operators before engaging any new sub-processor or making a material change to an existing sub-processor's role, where such change affects the processing of customer personal data.

Notifications will be published in the Changelog and, where a DPA is in place, communicated directly to the operator's registered contact.


Further Reading

PageContents
InfrastructureHosting architecture and data residency guarantees
GDPR ImplementationData subject rights and lawful bases
Data EncryptionEncryption standards