How we manage this list
- Every entry names a vendor, purpose, and region.
- We do not add sub-processors silently. Material additions are communicated to affected customers before they take effect.
- Each sub-processor is contractually bound to data-protection obligations materially equivalent to those in our DPA.
- For onward transfers outside the EEA / UK we rely on adequacy decisions, Standard Contractual Clauses, or the UK IDTA.
Sub-processors that may touch customer telemetry
| Vendor | Purpose | Region | Transfer basis |
|---|---|---|---|
| Google Cloud Platform | Compute, ingestion and queuing, object storage, and key management in the EU processing region. | EU | Within EU; no SCCs required. |
| Neon | Managed Postgres for telemetry and control-plane databases. | EU | Within EU; no SCCs required. |
| Vercel | Marketing site, docs, and frontend hosting. Customer telemetry is not intentionally processed in Vercel infrastructure. | EU edge | Within EU; no SCCs required. |
| Cloudflare | DNS, WAF, TLS, and edge routing for greenslope.io. | Global edge | SCCs / UK IDTA where needed. |
| Slack (Salesforce) | Outbound alert delivery to customer-owned Slack workspaces via the GreenSlope Slack App. | US | SCCs / UK IDTA. |
| GitHub | GitHub App for release, commit, and pull-request context. Repository access is read-only. | US | SCCs / UK IDTA. |
| Gemini on Vertex AI (Google Cloud) | AI-assisted triage summaries and postmortem drafts using an EU regional endpoint. Customer data is not used for model training. | EU | Within EU; no SCCs required. |
Sub-processors that touch account or operational data
These vendors process account, billing, support, or analytics data, not ingested customer telemetry.
| Vendor | Purpose | Region | Transfer basis |
|---|---|---|---|
| Paddle | Merchant of Record for payment processing, invoicing, tax, refunds, and chargebacks. | UK / EU / US | Paddle terms govern card and billing data. |
| Google Workspace | Internal email and productivity, including support mailboxes. | EU | Within EU; no SCCs required. |
| PostHog Cloud EU | Consented Website Analytics and Account Access Analytics plus minimized server-side In-App Usage Analytics and feature evaluation. Browser autocapture and session replay are disabled. | EU | Within EU; no SCCs required. |
| Sentry (EU region) | Error and performance diagnostics for the GreenSlope Website and GreenSlope App under a strict allowlist that excludes request bodies, credentials, cookies, queries, form values, and direct identifiers such as email or name. | EU | Within EU; no SCCs required. |
| Email delivery provider | Transactional email such as password resets, alert emails, and account notifications. Specific vendor recorded here when selected. | EU | Within EU; no SCCs required. |
Subscribing to changes
Email legal [at] greenslope [dot] io asking to be notified when this list changes.
Historical changes
First publication: 22 April 2026. Updated 9 July 2026 to remove browser replay and document the strict Sentry data boundary.