OOpDash← Back to home

Sub-processors

Last updated: 23 July 2026

OpDash uses a small set of trusted third-party companies (“sub-processors”) to run its service. A sub-processor is a vendor that may process personal data on our behalf when you use OpDash. We only engage sub-processors that provide sufficient guarantees under the GDPR, and we have a data-processing agreement (Article 28 GDPR) with each one before any personal data flows through it.

Where your data lives

OpDash is built EU-first. All primary customer data is stored in the European Union: our application database, error logs, application logs, product analytics, and rate-limiting store. Our application compute runs in the EU (Ireland). A small number of sub-processors are established outside the EU (United States) — notably the AI providers, our payment processor, and our hosting/edge and bot-protection providers. For each such transfer we rely on an appropriate GDPR Chapter V safeguard — Standard Contractual Clausesand/or the vendor’s EU–US Data Privacy Framework certification — as set out in that vendor’s agreement. We also minimise the personal data sent to these providers by design.

Current sub-processors

SupabaseApplication database (primary data store)

Data: All customer and end-user data stored in OpDash — account, contacts and leads, conversations, billing records
Location: EU (Ireland)

VercelApplication hosting and edge network

Data: Request metadata and client IP address at the edge; application traffic
Location: Global edge; OpDash functions pinned to the EU (Ireland)

AnthropicAI model that generates assistant replies

Data: Conversation content sent to the model to produce a reply
Location: United States

Voyage AIText embeddings for knowledge search

Data: Content of a customer's ingested documents and website, converted to embeddings
Location: United States

StripePayments, subscriptions, and tax

Data: Billing and payment details, business contact information, tax data
Location: United States / EU (Stripe Payments Europe)

CloudflareBot protection at signup (Turnstile)

Data: Client IP address and a challenge token, to distinguish humans from bots at signup
Location: Global

UpstashRate-limiting and abuse-prevention store

Data: Short-lived rate-limit counters keyed by hashed IP / session token (no raw IP)
Location: EU

SentryApplication error monitoring

Data: Exception and diagnostic payloads (request id, opaque ids, hashed IP — no raw personal data by design)
Location: EU (Germany)

AxiomApplication logging

Data: Structured log lines (request id, hashed IP — no raw personal data by design)
Location: EU

PostHogProduct analytics

Data: Named funnel events, cookieless (no cookies or device storage; no autocapture or session recording)
Location: EU Cloud

UptimeRobotUptime monitoring and alerting

Data: Your team's alert-contact email; pings a public health URL
Location: United States / EU

Amazon SES (AWS)Transactional and notification email (application)

Data: Recipient email addresses (workspace staff); the new-lead alert also carries the lead's contact detail. No message body is retained at the processor
Location: EU (Ireland, eu-west-1)

ResendTransactional email — marketing website only

Data: Recipient email addresses for the marketing site (opdash.co) waitlist, welcome, and unsubscribe emails
Location: United States

Not yet in use

The following are planned and are not currently engaged. We will add them to this list before they go live:

  • Twilio — SMS notifications (would process end-user phone numbers).
  • A calendar provider — booking and scheduling (would process booking-attendee data).

Changes to this list

We will update this page when we add or replace a sub-processor. Where required, we will give advance notice so that customers can review the change. To be notified of changes, contact us at the address below.

Contact

Questions about this list, our sub-processors, or our data-protection practices: privacy@opdash.co.