Sub-processors
Version 1.0.2 · In force from · Ever Technologies LTD
Why this page exists
When you use the Ever website to process personal data, we act as your processor and you are the controller. Article 28 GDPR says we may not bring in another processor without your authorisation, and that you must be told in advance when we intend to add or replace one so that you have a real chance to object.
This page is that disclosure. It names every provider we engage to process personal data for the hosted Service, says what each one does, where it does it, and what categories of data reach it. Our Data Processing Addendum refers to this page, and your general authorisation to the providers listed here is given through it.
It is also written for people who are not our customers — someone whose employer uses the Service, or whose data ends up here for some other reason — because "who else can see this" is a fair question and the answer should not be available only to the person paying the invoice.
What counts as a sub-processor
A sub-processor is a third party we engage that processes personal data on our behalf and on our instructions, under a written contract meeting Article 28 GDPR. A provider that keeps the servers running, delivers your email, catches our errors or answers your support chat is a sub-processor.
Three things are not sub-processors, and lumping them in would make this page less accurate rather than more complete:
- A provider that never touches personal data. A design tool or an accounting package we use internally is not in the path of your data.
- A company that decides its own purposes. A payment processor acting on its own regulated obligations — fraud prevention, anti-money-laundering, card-scheme rules — is a controller in its own right for that part, not our processor. Those recipients are described in the Privacy Policy instead.
- Something we run ourselves. Our databases, object storage, secrets manager and container platform are ours. There is no third party to disclose. The infrastructure section below explains what we operate and what genuinely sits in front of it.
What this page covers
The hosted Service we operate at ever.co, for Ever specifically. Other products in our range have their own list on their own domain, and the providers differ between them — do not read this one as covering a product it does not name.
It does not cover a deployment you run yourself. If you install our open-source software on your own infrastructure, you choose your own providers with your own credentials and contracts. The third tier below exists to make that distinction visible rather than to blur it.
This page is versioned and dated. The version in force, and the date it took effect, are at the end.
How to read this list
The three tables that follow mean genuinely different things, and reading them as one flat list will give you the wrong answer.
Here is why the split exists. Our products are open-source at their core and built to be connected to other things, so more than 160 distinct third-party providers appear somewhere in our source code across our whole range of products. The overwhelming majority of them are never engaged by us for anything. Some are optional integrations that do nothing until somebody switches them on. Many are reachable only in a deployment that somebody else runs, with their own account and their own credentials.
Publishing all of them as "our sub-processors" would be inaccurate, and inaccurate in the worst direction: it would tell you your data reaches companies it never touches, while burying the handful that it actually does. A list that is technically exhaustive and practically misleading is not a disclosure. So there are three tiers.
Tier 1 — always engaged
If you use the hosted Service, these providers are in the path. There is no setting that removes them, because they are part of how the Service is delivered to everyone.
This is the real Article 28 sub-processor list. It is the tier to use when you are completing a data protection impact assessment, mapping your transfers, or deciding whether you can use the Service at all. It is short, and it is short because we run our own infrastructure rather than renting someone else's.
Tier 2 — engaged only if you turn something on
A provider in this tier is engaged only when a specific feature, connector or integration is enabled. Enable nothing and it is never involved, and no data of yours ever reaches it.
Who does the enabling depends on the feature:
- You or your workspace administrator, by switching on a feature or connecting an account in the product's settings — a payment provider, an analytics tool, a chat widget, a calendar or repository connector.
- An individual user, by making a personal choice — signing in with a social account, for example, or connecting their own third-party tool.
The table names the feature or setting that activates each provider, so you can check your own configuration against it rather than take our word for the current state. If you want to know precisely which of these are live for your workspace today, ask us at [email protected] and we will tell you.
Enabling one of these is a decision to send your data somewhere else, and it is yours to make. The provider's own terms and privacy notice then apply to what it does, alongside our contract with it.
Tier 3 — self-hosted deployments only
Several of our products are published as open source and can be run on your own infrastructure. When you do that, you choose the database, the object storage, the email relay, the AI provider and everything else, using your own accounts and your own credentials.
The providers in this tier are listed only so that you can see what the software can be pointed at. They are not our sub-processors, and they never become ours by appearing here.
In a deployment you run: we process nothing, we have no access to it, we are not your processor for it, and nothing on this page or in our Data Processing Addendum describes it. You choose those providers, you contract with them, you hold the credentials, and the obligations to your own users are yours alone. The open-source section of our Terms of Service sets out the same split.
If you run a deployment yourself and need to publish a sub-processor list of your own, this tier is a useful starting inventory. It is not your list — only you know which of these you actually configured.
What the columns mean
- Sub-processor — the contracting legal entity, not the brand on the website. Where a provider has a separate European establishment that contracts with us, that is the one named.
- Purpose — what it does for the Service, specifically enough to be checked. Not "business operations".
- Location — where the processing takes place, or the provider's place of establishment where processing is distributed. Where a provider contracts through a European establishment but processes elsewhere, this column says both, because the two are different facts and only naming the first would flatter us.
- Transfer mechanism — for a provider outside the European Economic Area, the Chapter V instrument we actually rely on for that specific provider: an adequacy decision, the Standard Contractual Clauses, or nothing yet. Where it reads "To be confirmed", we have not yet evidenced an instrument for that provider, and we would rather say so here than print one we cannot produce. That is a live piece of work, not a formula. Providers established inside the EEA need no mechanism and say so. For the third tier the transfer is not ours at all — you choose the provider and hold the contract. The general rules behind this column are in the international transfers section of our Privacy Policy, and we will give you a copy of the safeguards for a named provider on request.
- Personal data — the categories that reach that provider. Categories, not a promise about volume: a provider that receives email addresses receives them for the people who trigger the feature, not for everyone.
Why this list is deliberately longer than it needs to be
We list providers we may engage, not only the ones engaged today. Where we have configured a provider, kept one available behind a feature flag, used one recently, or expect to use one for a purpose already described here, it appears in the tables below — even if no data has reached it this month, and even where we currently run the equivalent ourselves.
We do this on purpose, and you should read the tables with it in mind:
- A provider appearing here is not proof that your data has reached it. It means the provider is within the scope of what we have told you we may do, at the tier shown. The tier is the part that tells you when it is engaged.
- Where we self-host something today — our analytics, our job runner, our databases, our object storage — we say so, and we also name the hosted service we would move to, so that a later change is covered by a disclosure you have already seen rather than by a fresh surprise.
- The alternative is worse. A list that names only today's exact set has to be re-issued, and re-consented, every time an engineer changes a setting. A list drawn slightly wide stays true through ordinary operational change, which is what makes it dependable.
What we will not do is use this as cover. Breadth here does not license a purpose we have not described, a category of data we have not listed, or a transfer without a mechanism. If we start sending a new kind of personal data, or sending it for a new reason, that is a change to this page and to the notice period below — not something the width of a table quietly absorbs.
If you need to know precisely which providers are live for your workspace today, rather than which ones may be, ask us at [email protected] and we will tell you.
What is deliberately not in the tables
- Infrastructure we operate ourselves. Our databases, object storage, cache, secrets manager and container platform are not sub-processors, because there is no third party involved. The next section describes what we run and what really does sit in front of it.
- Recipients that are not processors — payment providers acting under their own regulatory obligations, professional advisers, public authorities, and an acquirer in a corporate transaction. Those are covered in the Privacy Policy.
- Sites you choose to visit by following a link out of the Service. Once you are on someone else's site, their notice applies.
Annex: Ever
Why this list exists here, which is not the reason given above
The page opens on Article 28 — we act as your processor, you are the controller, and you authorise the providers we bring in. On ever.co none of that applies. Nobody is our customer here, nobody instructs us, Ever Technologies LTD is the controller for everything this site collects, and this site publishes no Data Processing Addendum for anyone to authorise anything under.
We publish the list anyway, for a simpler reason. If you send us an enquiry or a CV, or if you just read a page, other companies handle some part of that, and you are entitled to know which.
Tier 1 — every visit, and every submission
There is no setting on this site that removes any of these.
| Sub-processor | Purpose | Location | Transfer mechanism | Personal data |
|---|---|---|---|---|
| Cloudflare, Inc. | DNS, content delivery, TLS termination, web application firewall and the tunnels that carry traffic from the edge to our own servers for ever.co, for the documentation at docs.ever.co, and for the content management system behind both. Every request to every page passes through it. | United States, with edge termination worldwide | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and device characteristics, requested URLs and request headers, TLS and connection metadata, cookies in transit |
| ActiveCampaign, LLC (Postmark) | Delivery of everything the forms on ever.co produce — the enquiry and demo request, the job application, and the pricing notification request — each sent as an email to an internal mailbox. A CV or other document you attach travels inside that message. | United States | Standard Contractual Clauses (EU 2021/914) | name, email address, telephone number and employer you type into a form, the free text of your enquiry or covering message, the CV or other document you attach, carried inside the message, delivery, bounce and open metadata |
| Google Ireland Limited (reCAPTCHA) | Bot protection on the public forms of ever.co — enquiry, careers, pricing notification and newsletter. It loads only on a page carrying one of those forms. Treated as strictly necessary for the reasons given in our Cookie Policy. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and device characteristics, mouse, touch and timing signals from the form page |
| Google Ireland Limited (Google Fonts) | Delivery of the webfonts that the site stylesheet requests from your browser while the page loads. It is in this tier because it is fetched on every page view and no setting on the site removes it. It stores nothing on your device; what it receives is the request itself. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and browser details, the page that requested the font |
| GitHub, Inc. (a Microsoft Corporation company) | Source hosting, continuous integration and the container registry that build and ship this website and its documentation. It is how the site is built and deployed, not where anything you send us is kept. | United States | Standard Contractual Clauses (EU 2021/914) | build, release and deployment metadata, developer and automation account identifiers, nothing submitted through the forms on the site |
| Cloudflare, Inc. (R2 object storage) | Holds the encrypted off-site copy of our backups - Postgres WAL and dumps, Velero, etcd, Proxmox configuration and MinIO mirrors - as the third tier of the backup chain (node8 NVMe, then Ceph RGW, then Cloudflare R2). Encrypted by us before it leaves our network. | United States | Standard Contractual Clauses (EU 2021/914) | client-side encrypted backup archives only - no plaintext is ever readable by the provider, the archives themselves derive from every category of data the products hold |
| Resend, Inc. | Sends transactional mail for the products and domains configured against it, relaying onward through Amazon SES. | United States | Standard Contractual Clauses (EU 2021/914) | recipient name and email address, message subject and body, delivery and bounce metadata |
| Google Ireland Limited (Google Workspace) | Hosts the corporate mailboxes that receive every support, privacy and rights request our own documents tell data subjects to write to, plus the recruitment mailbox that holds candidate CVs. | Ireland (contracting) / United States and global (Google LLC) | Standard Contractual Clauses (EU 2021/914) | all inbound and outbound company email, support, DSAR and privacy correspondence with data subjects, candidate CVs and application correspondence (ever-tech careers), customer and supplier correspondence and attachments |
| Cloudflare, Inc. (Turnstile) | Checks that the person completing registration, onboarding or an anonymous flow is not a bot; on ever-works the API refuses the anonymous flow when no CAPTCHA provider is configured, which is why it is unconditional there. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and device signals, mouse, touch and timing interaction signals, Turnstile challenge cookie |
| Clerk, Inc. | Holds the account identity for the hosted cloc platform - name, email address, avatar, password or federated identity, sessions and multi-factor settings - so that our own database does not, and brokers the short-lived source-control credential used when the Service acts in a user's name. | United States | Standard Contractual Clauses (EU 2021/914) | name, email address and avatar, password hash or federated identity, session, device and sign-in records, organisation membership and role, social-connection claims where a user signs in that way, the short-lived source-control credential brokered for a single request and not stored |
| Tavily | The default provider for public web search and page extraction, used by agents researching a topic and by the automated research that runs when an account is created, where the queries are built from the new account holder's name and email domain. | United States | To be confirmed — we do not yet evidence a mechanism | search queries, including a person's name and their employer's email domain, the addresses of pages retrieved and the extracted page content, our API key and request metadata |
| ui-avatars.com | Generates placeholder avatars where a person has no avatar of their own. The person's name or GitHub username is placed in the image URL, so it is disclosed to this provider every time the image is rendered in a customer's browser. | UNKNOWN - not published by the provider | To be confirmed — we do not yet evidence a mechanism | the developer's name or GitHub username, in the request URL, the viewing user's IP address and user agent |
| Prospect One sp. z o.o. (jsDelivr) | Serves the Lottie animation runtime hard-coded into the ever-works login and register pages, so every person who opens the login page hands their IP to it before authenticating. | Poland (operator); delivery worldwide | Standard Contractual Clauses (EU 2021/914) | IP address, user agent, referring page URL |
| UNKNOWN - community-run npm CDN; no obtainable DPA counterparty identified | Second permitted origin for the Lottie animation runtime on the ever-works login and register pages. | United States (unverified) | To be confirmed — we do not yet evidence a mechanism | IP address, user agent, referring page URL |
| Langfuse GmbH | Stores the full prompts and completions of AI features together with model, latency and cost metadata, so that agent behaviour can be traced and scored. | Germany | None needed — established in the EEA | full prompt and completion text, which can contain user-authored content and personal data, user and session identifiers, model, latency, token and cost metadata, developer scoring outputs |
| OpenRouter, Inc. | Is the model provider behind the default 'Ever Works AI' option and the hard-coded default for AI Chat on every provisioned tenant site, receiving the raw prompt and forwarding it to whichever upstream model the selected model id resolves to. | United States | To be confirmed — we do not yet evidence a mechanism | full prompt text, including any customer or end-user content pasted into an agent - repo text, CVs, job descriptions, chat messages, generated completions, agent tool-call arguments, API key metadata and usage accounting |
Two rows in that table deserve a sentence rather than a scan.
- The mail provider carries your CV. The enquiry and careers forms produce an email, and the document you attach travels inside it. That is the most consequential row above by a distance: it is the route by which a job application leaves our infrastructure.
- The font service is in this tier because your browser reaches it on every page view. No setting on the site removes it and no consent choice stops it. The Cookie Policy annex explains what that means and what we are doing about it.
Tier 2 — only when a consent choice, a feature or you bring them in
| Sub-processor | Purpose | Location | Transfer mechanism | Personal data |
|---|---|---|---|---|
| Google Ireland Limited (Google Analytics 4 and Google Tag Manager) | Traffic measurement on ever.co. The tag manager is a container rather than a tag: further tags can be added to the site through it without a change to the site's code, and anything it loads belongs to the same consent category as the container. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, analytics client identifier, pages viewed, referrer, device and browser details |
| PostHog, Inc. | Product and site analytics on ever.co, sent to the provider's United States cloud, with its own identifier stored on your device. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, an analytics identifier stored on your device, pages viewed, referrer and interface events |
| Liidio Oy (Leadfeeder), a Dealfront Group GmbH company | Business-audience identification on ever.co — resolving a visitor's IP address to the organisation it belongs to, and reporting that organisation's path through the site to our sales team. | Germany, European Union | None needed — established in the EEA | IP address, inferred employer or organisation, pages viewed and referrer |
| Functional Software, Inc. d/b/a Sentry | Error and performance reporting for the website's own pages, and for the documentation where it is configured there. | United States | Standard Contractual Clauses (EU 2021/914) | IP address and browser or operating-system details, the URL and route where an error occurred, stack traces and request context, which can contain fragments of what you were sending when it failed |
| Chatwoot Inc. | The live support chat widget on ever.co, engaged when you open it and start a conversation. | United States | Standard Contractual Clauses (EU 2021/914) | name and email address you give the widget, the content of the chat, IP address and session identifiers, the page you were on when you opened it |
| The Rocket Science Group LLC d/b/a Mailchimp | Newsletter and mailing-list management for addresses subscribed on ever.co through the footer box and the pricing notification modal — and, today, also for the address given to the enquiry and careers forms, which subscribe it. The privacy annex explains that and what we are changing. | United States | Standard Contractual Clauses (EU 2021/914) | email address and name, subscription status, list tags and campaign engagement, IP address at the time of subscription |
| DigitalOcean, LLC | Serves desktop installer downloads from the gauzy.co download page, holds media in Spaces where a deployment selects it as the file provider, still carries legacy container images and gated deploy workflows, and for cloc provisions servers on a customer's behalf. | United States | Standard Contractual Clauses (EU 2021/914) | uploaded files, screenshots and captured media held in Spaces, IP address and user agent of anyone downloading an asset or a desktop installer, container images and build metadata (no personal data), for cloc: server handles, sizes and lifecycle state of infrastructure provisioned on a customer's behalf |
| Amazon Web Services, Inc. | S3 is the object-storage backend an operator or tenant can select for uploads and monitoring media; CloudFront serves maintenance.ever.co and security.ever.co on our flagship domain; SES sits underneath our email relay as that relay's own sub-processor. | United States (Luxembourg for the EEA contracting entity) | Standard Contractual Clauses (EU 2021/914) | uploaded files, avatars and document images in S3, employee-monitoring screenshots, webcam stills, audio and screen recordings where S3 is the file provider, static assets served from CloudFront, exposing visitor IP and user agent, outbound email envelope and content where SES is in the path, certificate validation records (no personal data) |
| Uptime Robot Service Provider Ltd - UNVERIFIED. The commonly cited registration is Cyprus (Nicosia); confirm from the current Terms or Imprint before publishing any location claim. | Hosts the public status page at status.<our-domain>, so anyone who opens it hands their IP and user agent to the vendor. | Cyprus (unverified) | To be confirmed — we do not yet evidence a mechanism | IP address and user agent of every visitor to a status page, cookies set by the status page, monitored endpoint URLs and response metadata |
| Algolia SAS | Answers the search box on the documentation sites, receiving each reader's query and IP where Algolia credentials are configured. | France (EEA) or United States, depending on the contracting entity and the index region | To be confirmed — we do not yet evidence a mechanism | search queries typed by the reader, IP address, user agent, indexed page content |
| Vercel Inc. | Hosts the cloc platform; routes AI prompts to downstream model providers for gauzy through the AI Gateway; and remains the deployment target of surviving workflows and DNS delegations for several frontends that have since moved to our own cluster. | United States | Standard Contractual Clauses (EU 2021/914) | for cloc: full application traffic and runtime data (the platform actually runs there), IP address and user agent of visitors where a site is served from Vercel, page-view and Web Vitals events, for gauzy: prompt content and model responses routed through the AI Gateway, plus routing and usage metadata, deployment metadata |
| Wasabi Technologies, Inc. | Holds avatars, task attachments and time-tracker screenshots wherever the platform's or a tenant's file provider is set to Wasabi. | United States | Standard Contractual Clauses (EU 2021/914) | uploaded files and document attachments, avatars, employee time-tracker screenshots and captured monitoring media |
| Cloudinary Ltd. | Stores and transforms images and video where a deployment's or the platform's media provider is set to Cloudinary, and serves them to viewers directly from its own CDN. | Israel | Adequacy decision — Israel | uploaded images and video, screenshots and captured media, IP address and user agent of every viewer fetching an asset |
| UNKNOWN - operated by an individual developer; no identifiable legal entity, no privacy policy, no DPA counterparty | Supplies fallback avatar and logo placeholder images whose URLs are written into persisted user, organization and team records and then fetched directly by the visitor's browser. | United States (unverified) | To be confirmed — we do not yet evidence a mechanism | IP address, user agent, referring page URL |
| Twilio Inc. (SendGrid) | Sends and tracks marketing or transactional email for gauzy.co through dedicated sending, reply and link-tracking subdomains, and stands as an alternative sender for githands. | United States | Standard Contractual Clauses (EU 2021/914) | recipient email address and name, message content, open and click tracking events (links.gauzy.co), recipient IP and user agent via tracking pixels |
| Twilio Inc. (Programmable Messaging) | Sends SMS where a tenant configures Twilio as its SMS gateway using its own account SID and token. | United States | Standard Contractual Clauses (EU 2021/914) | recipient telephone number, message body, which can contain a capture link or workspace content, delivery and status metadata |
| Jitsu Labs, Inc. | Collects product events into an event pipeline where a write key is configured, on Jitsu's US cloud. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, user and workspace identifiers, page and feature events, device and browser characteristics |
| Hound Technology, Inc. (d/b/a Honeycomb.io) | Receives OpenTelemetry traces from the API where Honeycomb is selected as the OTEL provider, including request URLs and database statements that routinely carry identifiers. | United States | Standard Contractual Clauses (EU 2021/914) | trace and span data including request URLs, route parameters and DB statements, service and host identifiers, anything a span attribute carries, which can include user and tenant ids |
| SigNoz Inc. (Delaware, USA) for SigNoz Cloud; SigNoz itself is Apache-2.0 and self-hostable. | Receives OpenTelemetry traces, metrics and logs from the API wherever the OTLP endpoint is configured, including route parameters and SQL text. | United States | To be confirmed — we do not yet evidence a mechanism | distributed traces including HTTP routes, query strings and SQL statements, service and host metadata, metrics and logs, anything attached as a span attribute |
| Better Stack, s.r.o. | Receives shipped application logs where a log token is configured, including the ChatGPT connector service in ever-teams and the cloc platform's observability pipeline. | Czech Republic | None needed — established in the EEA | application log lines, which may embed user ids, request paths and IP addresses, uptime probe results |
| OpenAI, L.L.C. | Generates completions and transcribes audio for in-application AI features, using either a platform-held key (cloc) or a key the customer supplies (gauzy, ever-works, ever-teams, hust). | United States | Standard Contractual Clauses (EU 2021/914) | prompt content, including workspace records, job posts, candidate and employee profile text, issue and task text and chat messages, audio submitted for transcription, model responses, OAuth device-auth identity for the Codex CLI plugin |
| Anthropic, PBC | Generates completions for in-application AI features - the default model in hust, a plugin or bring-your-own-key option in gauzy and ever-works. | United States | Standard Contractual Clauses (EU 2021/914) | prompt content, which can include workspace data the user pastes or references, model responses |
| Google Ireland Limited (Gemini API) | Generates completions for the in-application AI assistant where a customer connects a Gemini key, through the AI Studio endpoint rather than Vertex AI. | Ireland (contracting entity); processing in United States (AI Studio) / Ireland (Vertex AI) | Standard Contractual Clauses (EU 2021/914) | prompt content, which can carry workspace, HR and candidate data, model responses |
| Mistral AI SAS | Generates completions where the Mistral plugin is enabled for a Work. | France | None needed — established in the EEA | prompt text, completions |
| X.AI LLC | Generates completions where a customer selects Grok and supplies a key. | United States | To be confirmed — we do not yet evidence a mechanism | prompt content, model responses |
| Groq, Inc. | Serves completions where a user supplies a Groq key and selects it as the provider. | United States | To be confirmed — we do not yet evidence a mechanism | prompt content, model responses |
| Together Computer, Inc. (trading as Together AI) | Serves completions where a user selects Together as the provider and supplies a key, called from our own Next.js server route. | United States | To be confirmed — we do not yet evidence a mechanism | prompt content, including chat message text, model responses |
| Vercel Inc. | Routes AI prompts from the Gauzy assistant to whichever downstream model provider the customer's selected model resolves to. | United States | Standard Contractual Clauses (EU 2021/914) | prompt content, model responses, request routing and usage metadata |
| Google Ireland Limited (Sign in with Google) | Authenticates a user who chooses 'sign in with Google', returning their email, name and picture, and in ever-rec also exports recordings to the user's own Google Drive when they connect it. | Ireland (contracting) / United States (operating) | Standard Contractual Clauses (EU 2021/914) | email address, name and profile picture, Google account identifier, OAuth access and refresh tokens, Google Drive file metadata and content the user chooses to export, where the Drive scope is granted (ever-rec) |
| Intuition Machines, Inc. (hCaptcha) | Scores signup and login attempts wherever the CAPTCHA provider is set to hCaptcha. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and browser/device fingerprint signals, mouse, touch and timing interaction signals, challenge solution and token |
| Meta Platforms Ireland Limited (Facebook Login) | Authenticates a user who chooses to sign in with Facebook, returning their email, name and profile picture. | Ireland (contracting entity); processing in Ireland (contracting for EEA users) / United States (Meta Platforms, Inc.) | Standard Contractual Clauses (EU 2021/914) | email address and name, Facebook user identifier, profile picture URL, OAuth tokens |
| LinkedIn Ireland Unlimited Company | Authenticates a user who chooses to sign in with LinkedIn, returning their email, name and the profile fields in the granted scope. | Ireland (contracting entity); processing in Ireland (EEA contracting) / United States (processing) | Standard Contractual Clauses (EU 2021/914) | email address and name, LinkedIn member identifier, OAuth tokens, profile fields returned within the granted scope |
| X Corp. (Twitter) | Authenticates a user who chooses to sign in with X, where that provider is enabled for the deployment. | United States | To be confirmed — we do not yet evidence a mechanism | handle and public profile, X user identifier, OAuth tokens |
| Microsoft Corporation (Microsoft Entra ID) | Authenticates a user or administrator who chooses a Microsoft work or personal account, reading profile details from Microsoft Graph, where FEATURE_MICROSOFT_LOGIN is enabled. | United States | Standard Contractual Clauses (EU 2021/914) | email address and display name, Microsoft tenant identifier and user object id, OAuth access and refresh tokens, directory profile fields returned by Graph within the granted scope |
| Okta, Inc. (Auth0) | Authenticates an organisation's people where that organisation chooses to route sign-in through its own hosted Auth0 tenant. | United States | Standard Contractual Clauses (EU 2021/914) | email address and profile, OAuth/OIDC tokens, login IP address, device and user agent, authentication and MFA event logs |
| Atlassian Pty Ltd (Jira, Trello) | Syncs tasks, issues and attachments with a Jira or Trello site the customer connects using its own account. | Australia (Atlassian Pty Ltd) / Netherlands (Atlassian B.V.) / United States (Atlassian, Inc.) | Standard Contractual Clauses (EU 2021/914) | issue, project, card and board records, reporter and assignee identity, attachments, screenshots and recordings pushed to an issue, API key and OAuth tokens |
| Slack Technologies, LLC (a Salesforce, Inc. company) | Posts notifications into, and reads events from, a Slack workspace the customer connects by installing our app into its own workspace. | United States (group); Ireland (EEA contracting for Slack's own customers) | Standard Contractual Clauses (EU 2021/914) | channel and workspace identifiers, message content we post or receive, Slack user identity, including member email addresses, OAuth tokens and webhook payloads, shared recordings, screenshots and their links (ever-rec) |
| Zapier, Inc. | Forwards workspace records into whatever third-party apps a customer wires into a Zap, so the onward destinations are the customer's choice and outside our contract. | United States | Standard Contractual Clauses (EU 2021/914) | records pushed through a Zap (tasks, timesheets, contacts), OAuth tokens and authorization codes, arbitrary event payloads forwarded to whatever apps the customer wires up |
| Activepieces Inc. | Runs automation flows that read and receive whatever workspace records a customer wires in, on Activepieces' US cloud unless repointed at a self-hosted instance. | United States / Canada | Standard Contractual Clauses (EU 2021/914) | records pushed through a flow, which can be any workspace data, API keys, webhook payloads |
| Celonis SE (Make.com) | Runs automation scenarios that read and receive whatever workspace records the customer wires in, from EU infrastructure. | Germany / Czech Republic | None needed — established in the EEA | records pushed through a scenario, webhook payloads, OAuth tokens |
| Noti-Fire Apps Ltd. (Novu) | The in-application notification inbox and a delivery channel for notifications, where it is configured against Novu's hosted service rather than an instance you run. | Israel | Adequacy decision — Israel | a hashed subscriber identifier, computed server-side under NOVU_SECRET_KEY, notification content, email address where Novu is used as a delivery channel |
| Plausible Insights OÜ | Cookieless site analytics on a Work site, where the Work Owner enables it. | Estonia | None needed — established in the EEA | page views and referrer, coarse device and country, derived and not stored as an IP address |
| HubSpot, Inc. | Two-way contact synchronisation, engaged only when a customer connects its own HubSpot account. Data moves in both directions once connected. | United States (HubSpot, Inc.) / Ireland (HubSpot Ireland Limited, for HubSpot's own EEA customers) | Standard Contractual Clauses (EU 2021/914) | contact and company records the customer chooses to sync, names, email addresses, employers and job titles in those records, the OAuth credential for the connection |
| iubenda s.r.l. | Delivers hosted legal documents to visitors who open the /legal route in the Gauzy application, which still fetches the policy from iubenda in the visitor's browser. | Italy | None needed — established in the EEA | IP address, user agent, consent preferences and the timestamp of the choice |
| Google Ireland Limited (Google Maps Platform) | Renders maps and completes typed addresses for contacts, clients and organisations where the Maps and Places features are enabled with an API key. | Ireland (contracting entity); processing in Ireland (contracting) / United States (processing) | Standard Contractual Clauses (EU 2021/914) | IP address, typed address fragments and place queries, latitude and longitude of contacts, clients and organisations, session tokens for autocomplete billing |
With one honest caveat. Several of these are meant to wait for a consent choice and today do not. The Cookie Policy annex names exactly which, and says what is being changed. Read it before you rely on the analytics and marketing rows above being conditional in practice.
There is no third tier
The page above describes a tier of providers that appear only in a deployment somebody runs themselves. This is a website, not software anyone else runs, so that tier is empty here and is not printed. If you are looking for the self-hosted inventory for one of our products, it is on that product's own sub-processor page, not this one.
What is deliberately not in either table
The content management system behind these pages, the database under it, the object storage that holds the images, and the servers and container platform all of it runs on are ours — our own hardware in the European Union. Listing them would suggest a third party where there is none. What genuinely sits in front of them is in tier 1.
Hosting and infrastructure
The tables above are short for a reason, and the reason is worth stating plainly: we run our own infrastructure. The Service is not a tenancy in a public cloud account. It runs on physical servers we own, in facilities we control, inside the European Union, on a virtualisation and container platform we operate ourselves.
The database, the object storage that holds your files, the cache and queue layers, the secrets manager and the deployment system are all components we run. None of them is a third party, so none of them appears as a sub-processor — there is nobody else to disclose. What we do with them is described on our Security page.
Where processing actually happens
- Your data at rest, and the applications that process it, sit on our own hardware in the European Union. That is the primary location for accounts, content, files and the databases behind them.
- Requests reach us through a global content delivery and security network. Traffic is terminated at the edge location nearest to whoever is making the request, which can be anywhere in the world, before being carried to our infrastructure in Europe. That provider is in the always-engaged tier above, and the transfer mechanism for it is described in our Privacy Policy.
- Off-site backup copies are held with an external object storage provider, encrypted by us before they leave our network. That provider holds ciphertext and no key, and cannot read what it stores.
- Our source code, build pipeline and container images are hosted with a third-party provider. That is how the Service is built and deployed rather than where your data lives day to day, but it is a genuine third party and it is disclosed as one.
Where a product does something different
A small number of products use a third-party managed database, managed storage or hosted platform for a specific function instead of our own infrastructure. Where that is the case for Ever, the provider appears in the always-engaged tier above and the product annex says which data goes there.
We are explicit about this because "self-hosted" is exactly the sort of claim that gets made once and then stops being true for one product in the range. If your data for a given feature sits with someone else, the table says so.
The regions you should design around
If you are completing a transfer mapping or a data protection impact assessment, the honest summary is: primary processing in the European Union on infrastructure we operate; edge termination worldwide; a small number of named providers established outside the European Economic Area, each with its own transfer mechanism. Every one of those providers is in the tables above, and the mechanism for each is in the international transfers section of the Privacy Policy.
If you need a copy of the safeguards for a named provider — the Standard Contractual Clauses and which modules apply — write to [email protected] and we will send them.
When this list changes
The notice period
We give at least 30 days' notice before a new or replacement sub-processor starts processing personal data for the hosted Service. The 30 days run from the date the notice is published or sent, whichever comes first, and they exist so that your objection right is a real one rather than a formality you learn about afterwards.
How you find out
- This page changes first. It carries the date it took effect and a dated record of what changed, so the page itself is the notice.
- By email, if you ask for it. Write to [email protected] and we will add your address to the notification list. We then email you before each change, at the same time the page is updated. We recommend a role address rather than an individual's — a notice sent to someone who has left your organisation has been sent and not received.
- In the product, for changes that affect a feature you are using, through a notice to workspace administrators.
What the notice tells you
The provider's legal name, what it will do, where it is established, the categories of personal data it will receive, the transfer mechanism if it is outside the European Economic Area, the date it takes effect, and whether it is a new provider or replaces one already on the list. If it replaces one, we say which.
Urgent replacements
Sometimes we have to move faster than 30 days — a provider suffers a security incident, terminates its service, loses the legal basis it relied on, or fails in a way that makes staying with it worse than leaving.
Where that happens we may engage the replacement sooner, and we will notify you as quickly as we can with the reason we could not wait. Your right to object is not affected: it simply runs from the notice instead of before the change. We do not use this route as a convenience, and a notice sent under it says plainly why the normal period was not followed.
Changes that do not need notice
Removing a provider does not need a notice period — it reduces the number of people handling your data. A provider changing its own name, or the group entity that contracts with us changing without a change in where or how the processing happens, is recorded here as an administrative update rather than announced as a new engagement. A provider moving its processing to a different country is not administrative, and gets the full notice.
The record
We keep the change history for this page so that you can reconstruct who was engaged during a given period. That matters if you are updating your own records of processing, refreshing an impact assessment, or answering a question about a period in the past. Ask [email protected] if you need the state of the list as it stood on a particular date.
Objecting to a sub-processor
Who can object
The customer — the organisation or person who contracts with us and acts as controller for the data in the workspace. If you are an individual whose data we hold, this is not your route: your rights are in the Privacy Policy, and if your data sits in an employer's workspace, your employer is the controller and the request goes to them.
How to object
Write to [email protected] within 30 days of the notice, and tell us:
- which provider you are objecting to;
- your reasons, on data protection grounds — a transfer you cannot justify, a conflict with a commitment you have given your own users, a regulator's position that applies to you, a documented security concern;
- which of your workspaces or environments the objection covers.
The reasons matter. This is a right to object on data protection grounds, not a veto over our choice of suppliers, and an objection with no stated ground gives us nothing to work with. Tell us what the problem is and we can usually solve it.
What we do next
We acknowledge your objection within five business days and respond substantively within 30 days. In between we look for a way to make the objection unnecessary:
- A different provider for your workspace, where one exists that does the job.
- A different configuration — narrowing what is sent, changing a region, or turning off the feature that needs the provider at all, if you can live without it.
- Excluding your workspace from the provider, where that is technically possible.
- Additional safeguards or contractual terms where your concern is about a specific risk rather than the provider as a whole.
Where it is technically possible to hold off, we will not start using the provider you have objected to for your data while the objection is open. Where it is not possible — because the provider is part of how the Service is delivered to everyone — we will tell you that plainly and quickly, rather than letting the clock run out on you.
If we cannot resolve it
If we cannot offer you a solution you can accept, you may terminate the affected subscription by written notice, without penalty, and we will refund the fees you have prepaid for the period after termination. That is the remedy: neither of us owes the other damages for a good-faith disagreement about a supplier.
Give us notice within 30 days of our final response, and we will keep your data available for export for the usual 30-day window described in the Terms of Service so that leaving does not cost you the data.
If you are on a free tier there is nothing to refund, and the same route is simply to stop using the Service and export your data.
Objecting to a provider already on the list
You do not have to wait for a change. You can raise a concern about a provider already listed at any time, using the same address and the same process, without the 30-day deadline. The realistic outcome differs by tier: a tier 2 provider can usually be switched off for you; a tier 1 provider generally cannot, because it is part of how the Service works — and if the answer is going to be no, you will get it as a straight no with the reason.
How to reach us about this list
- Questions about a provider, a request for the safeguards behind a transfer, or a request to join the change notification list — [email protected].
- An objection to a sub-processor — [email protected], as set out above.
- The Data Processing Addendum, a due diligence request, or a security questionnaire — [email protected].
We are Ever Technologies LTD, registered in Bulgaria under company number 204599535, with its registered office at Mladost 2, bl. 211, ent. A, Sofia 1799, Bulgaria. We are the controller for our own processing and your processor for the data in your workspace. By post, write to the registered office and mark the letter for the attention of the privacy team. We correspond in English.
You may also complain to a data protection supervisory authority. Ours is the Commission for Personal Data Protection (Комисия за защита на личните данни), the CPDP, at https://www.cpdp.bg/. You may instead complain to the authority for the country where you live or work.
This document is version 1.0.2 of the sub-processor list for ever.co, in force from 2026-08-02. It lists the providers engaged as at that date. Earlier versions, with the dates they applied, are at https://ever.co/subprocessors.