Sub-processors
Last updated: 23 July 2026
OpDash uses a small set of trusted third-party companies (“sub-processors”) to run its service. A sub-processor is a vendor that may process personal data on our behalf when you use OpDash. We only engage sub-processors that provide sufficient guarantees under the GDPR, and we have a data-processing agreement (Article 28 GDPR) with each one before any personal data flows through it.
Where your data lives
OpDash is built EU-first. All primary customer data is stored in the European Union: our application database, error logs, application logs, product analytics, and rate-limiting store. Our application compute runs in the EU (Ireland). A small number of sub-processors are established outside the EU (United States) — notably the AI providers, our payment processor, and our hosting/edge and bot-protection providers. For each such transfer we rely on an appropriate GDPR Chapter V safeguard — Standard Contractual Clausesand/or the vendor’s EU–US Data Privacy Framework certification — as set out in that vendor’s agreement. We also minimise the personal data sent to these providers by design.
Current sub-processors
Supabase — Application database (primary data store)
Data: All customer and end-user data stored in OpDash — account, contacts and leads, conversations, billing records
Location: EU (Ireland)
Vercel — Application hosting and edge network
Data: Request metadata and client IP address at the edge; application traffic
Location: Global edge; OpDash functions pinned to the EU (Ireland)
Anthropic — AI model that generates assistant replies
Data: Conversation content sent to the model to produce a reply
Location: United States
Voyage AI — Text embeddings for knowledge search
Data: Content of a customer's ingested documents and website, converted to embeddings
Location: United States
Stripe — Payments, subscriptions, and tax
Data: Billing and payment details, business contact information, tax data
Location: United States / EU (Stripe Payments Europe)
Cloudflare — Bot protection at signup (Turnstile)
Data: Client IP address and a challenge token, to distinguish humans from bots at signup
Location: Global
Upstash — Rate-limiting and abuse-prevention store
Data: Short-lived rate-limit counters keyed by hashed IP / session token (no raw IP)
Location: EU
Sentry — Application error monitoring
Data: Exception and diagnostic payloads (request id, opaque ids, hashed IP — no raw personal data by design)
Location: EU (Germany)
Axiom — Application logging
Data: Structured log lines (request id, hashed IP — no raw personal data by design)
Location: EU
PostHog — Product analytics
Data: Named funnel events, cookieless (no cookies or device storage; no autocapture or session recording)
Location: EU Cloud
UptimeRobot — Uptime monitoring and alerting
Data: Your team's alert-contact email; pings a public health URL
Location: United States / EU
Amazon SES (AWS) — Transactional and notification email (application)
Data: Recipient email addresses (workspace staff); the new-lead alert also carries the lead's contact detail. No message body is retained at the processor
Location: EU (Ireland, eu-west-1)
Resend — Transactional email — marketing website only
Data: Recipient email addresses for the marketing site (opdash.co) waitlist, welcome, and unsubscribe emails
Location: United States
Not yet in use
The following are planned and are not currently engaged. We will add them to this list before they go live:
- Twilio — SMS notifications (would process end-user phone numbers).
- A calendar provider — booking and scheduling (would process booking-attendee data).
Changes to this list
We will update this page when we add or replace a sub-processor. Where required, we will give advance notice so that customers can review the change. To be notified of changes, contact us at the address below.
Contact
Questions about this list, our sub-processors, or our data-protection practices: privacy@opdash.co.