Skip to content

Legal

Subprocessors

Subprocessors

Last updated: July 31, 2026

We use the following subprocessors to run the porthatch products. A new subprocessor is published on this page at least 30 days before it takes effect, and the notice also goes by email to the address on every active account — so the reliable way to track changes is this page plus your inbox, and it's worth checking here before a renewal.

Infrastructure

Subprocessor Purpose Data location Privacy policy
Cloudflare Workers runtime, edge routing, KV cache, Queues, Workflows, R2 (Placet uploads, Sluice CSVs) Requests are served from the edge location nearest the visitor. The R2 buckets holding uploaded media and Sluice CSVs carry Cloudflare's EU jurisdictional restriction: those objects are stored only in the European Union, and that is a guarantee rather than a placement. KV (caches, no customer content) is replicated across Cloudflare's network by design, and Queues hold messages only while they are being delivered — for those two we rely on Cloudflare's SCCs. Cloudflare remains a US-parented company whatever the storage region. cloudflare.com/privacy
Neon Managed Postgres for account, workspace, audit, and product metadata EU — Frankfurt (aws-eu-central-1) neon.tech/privacy
GitHub Storage for the nightly encrypted database backup, kept as a build artifact for 30 days. The dump covers the whole database — every account, every product schema — and is the only copy outside Neon. US github.com/privacy

Billing

Subprocessor Purpose Data location Privacy policy
Paddle Merchant of Record: checkout, card processing, sales-tax/VAT, subscription and credit-pack billing, and the customer portal. We do not see card numbers — they go directly to Paddle. UK / EU + US paddle.com/legal/privacy

Communications

Subprocessor Purpose Data location Privacy policy
Resend Transactional email delivery: magic-link sign-in, payment-failure notices, and subscription notifications US resend.com/legal/privacy

Observability

Subprocessor Purpose Data location Privacy policy
Sentry Application error tracking. Stack traces, request context. We never attach a user identity to an event, and email addresses are stripped from the event payload — message, exception values, URLs and breadcrumbs — before it leaves the Worker. EU — Germany (organisation is on Sentry's EU region) sentry.io/privacy
Axiom Structured logs and metrics. Request ids, route, status, latency. No PII. EU — Frankfurt (eu-central-1 ingest edge) axiom.co/privacy

Product-specific (only relevant if you use that product)

Subprocessor Used by Purpose Data location Privacy policy
Notion Cordon Database proxy — your Notion content stays in Notion; we hold only an integration token and a proxy audit US (vendor). We store no Notion content — the token and audit rows live in Neon (EU) notion.so/notion/Privacy-Policy
Airtable Veneer Base proxy — your Airtable content stays in Airtable; we hold only a Personal Access Token (encrypted at rest) and a proxy audit US (vendor). We store no Airtable content — the token and audit rows live in Neon (EU) airtable.com/privacy
Stripe Duehatch Source of the invoices you chase. You connect your own Stripe account with a read-only restricted key; unlike Notion and Airtable we do copy content — open invoices and the customer records attached to them (name, email, amount, due date) sync into our database so the chase sequence can run. US (vendor). The synced copy lives in Neon (EU); the restricted key is stored encrypted. stripe.com/privacy
EmailListVerify Sluice "deep" tier Third-party SMTP probe for email validation. Activated only on the deep tier; standard tier doesn't reach an external vendor. Receives the email addresses being verified — third-party personal data supplied by the customer. Netherlands (hosted by WorldStream B.V.) for customers established in the EEA/UK. Which regime applies to Porthatch's own account is being confirmed with the vendor — see the note below emaillistverify.com/privacy · DPA

EmailListVerify carries the most sensitive data in the portfolio. Three products hold personal data belonging to people who never signed up for Porthatch: Placet keeps a reviewer's email with their approval decision, Duehatch stores the name, email and outstanding amount of your customers, and Sluice takes whole lists of addresses. What makes Sluice Deep different is not that the data is third-party — it's that this is the only place where that third-party data is forwarded to an external vendor rather than staying inside our own EU infrastructure. For all three you are the controller and we are the processor, and the warranties you give us about lawful basis and Article 13–14 notice are in Terms §4.

Their published position is that EEA/UK-established customers are served from EU servers under their DPA. Porthatch is not EEA-established, so we have asked the vendor to confirm in writing which servers process our account's requests, and this row will state the answer rather than the inference. Until then, treat the location as unconfirmed. Standard-tier verification never leaves our own infrastructure.

How we vet new subprocessors

Before adding a new subprocessor we check:

  • Public privacy policy + DPA terms compatible with our customers' GDPR posture
  • Compliance certifications (SOC2 Type II, ISO 27001) where applicable
  • Encryption-in-transit + encryption-at-rest defaults
  • Sub-processor list (so we don't add a subprocessor that fans out to another we haven't vetted)

Publishing the change is part of connecting the vendor, not an afterthought: this page is updated and the notice emailed to every active account before the vendor is wired into production, with the 30-day clock started from that publication.

How to object

If a new subprocessor is incompatible with your compliance posture, email privacy@porthatch.app within 30 days of the notice. You can exit the service with a pro-rated refund of the remaining billing period; you can download any completed results before you go.