Subprocessors
Placeholder draft · Last updated 6 July 2026
Placeholder draft — this document has not yet completed legal review and is not legal advice. Final text must be reviewed before client contracting.
1. What this page covers
This page lists the third-party vendors that process data on OgmaQ's behalf to deliver the service ("subprocessors"), separates them from providers that are not yet (or not currently) in use, and states OgmaQ's position on AI providers. It is kept up to date as the service evolves.
2. Current subprocessors
| Vendor | Purpose | Data processed | Data location | Status |
|---|---|---|---|---|
| Supabase | Database, authentication, storage and API infrastructure | Customer workspace data, account/profile data, authentication data, operational records and audit-support records | EU · eu-central-1 (Frankfurt) | Confirmed in use |
| Cloudflare | Web hosting (Pages), DNS, email routing, CDN and caching, TLS, WAF and bot management, and performance/security features | Request metadata, IP addresses, public-site/app delivery metadata and related technical/security logs | Global edge network | Confirmed in use |
| Resend | Transactional email delivery — authentication, account and service-notification emails, and (once the notification mailer is deployed) workflow notification emails such as "you were mentioned" alerts | Recipient email address and the content of transactional emails. Workflow notification emails are deliberately minimal — a record reference, the mentioning colleague's display name and sign-in links; never message text or workspace record content | EU · eu-west-1 (Ireland) | Confirmed in use |
Web fonts are self-hosted on both the public website and the application — no font request is made to Google or any other third-party font service, so Google Fonts is no longer a subprocessor (see the revision history below).
3. Providers not currently active or still to be confirmed
| Provider category | Purpose | Current status |
|---|---|---|
| Payment provider | Billing and subscription management | Not currently used |
| Customer support / helpdesk provider | Customer support and support-ticket handling | Not currently used |
| Analytics provider | Product or website analytics | Not currently used |
| AI provider | Customer-facing AI functionality or customer tenant-data AI processing | Not currently used |
These categories are listed for transparency about the expected shape of the service. They are not current subprocessors and should not be treated as such until a specific vendor is confirmed and moved into the current table above.
4. AI providers
AI and customer data: OgmaQ's customer-facing product currently has no AI functionality. OgmaQ does not process customer tenant data through AI providers, no AI vendor is currently a subprocessor of customer tenant data, and customer workspace content is not used to train AI models. Any future customer-facing AI-assisted functionality would require separate documentation, configuration, customer-facing disclosure and review before being enabled. Internal company tooling used outside the customer-facing product is separately scoped and controlled, and does not involve customer tenant data.
5. Changes to this list
Before adding a new subprocessor that would process customer tenant data, we will update this page. The notification and objection process for subprocessor changes will be defined during legal review and reflected in the Data Processing Agreement.
6. Revision history
Material changes to this list are recorded here so customers can see how it has evolved. Entries are added over time; older revisions are not removed.
| Date | Change | Notes |
|---|---|---|
| 20 July 2026 | Extended the documented Resend scope from authentication/account emails to also cover workflow notification emails ("you were mentioned" alerts) introduced with the notification mailer (v2.73). These emails carry a record reference, the mentioning colleague's display name and sign-in links only — never message text or workspace record content. The mailer ships fail-closed and sends nothing until it is deployed and configured. | Placeholder draft pending legal review (counsel-track DEC-10). |
| 19 July 2026 | Removed Google Fonts from the current-subprocessor list: web fonts have been self-hosted on both the public website and the application since 16 July 2026 (v2.65), so no font request leaves OgmaQ's own hosting. This entry corrects the list to match that change. | Placeholder draft pending legal review. |
| 7 July 2026 | Confirmed Resend's sending region (EU · eu-west-1, Ireland) and recorded a signed Resend data-processing agreement on file. No analytics provider is active (Cloudflare Web Analytics was disabled). | Placeholder draft pending legal review (v2.46.2). |
| 7 July 2026 | Confirmed the Supabase project region (EU · eu-central-1), added Resend as the transactional email subprocessor, recorded Supabase and Cloudflare data-processing terms, and removed the "being set up" caveat from contact aliases after mailbox routing was configured and tested. | Placeholder draft pending legal review (v2.46.1). |
| 7 July 2026 | Added a dedicated revision-history section and clarified the AI-provider position. | Placeholder draft pending legal review. |
| 6 July 2026 | Introduced the current-vs-not-currently-active provider split and the AI-provider statement. | Placeholder draft pending legal review. |
7. Contact
Questions about this list: [email protected] (general contact: [email protected]). These role-based aliases route to the OgmaQ team; [email protected] is the general contact if you are unsure which to use.