Sub-processors
Last updated: 23 July 2026
OpDash uses a small set of trusted third-party companies (“sub-processors”) to run its service. A sub-processor is a vendor that may process personal data on our behalf when you use OpDash. We only engage sub-processors that provide sufficient guarantees under the GDPR, and we have a data-processing agreement (Article 28 GDPR) with each one before any personal data flows through it.
Where your data lives
OpDash is built EU-first. All primary customer data is stored in the European Union: our application database, error logs, application logs, product analytics, and rate-limiting store. Our application compute runs in the EU (Ireland). A small number of sub-processors are established outside the EU (United States) — notably the AI providers, our payment processor, and our hosting/edge and bot-protection providers. For each such transfer we rely on an appropriate GDPR Chapter V safeguard — Standard Contractual Clauses and/or the vendor’s EU–US Data Privacy Framework certification — as set out in that vendor’s agreement. We also minimise the personal data sent to these providers by design.
Current sub-processors
Supabase — Application database (primary data store)
Data: All customer and end-user data stored in OpDash — account, contacts and leads, conversations, billing records
Location: EU (Ireland)
Vercel — Application hosting and edge network
Data: Request metadata and client IP address at the edge; application traffic
Location: Global edge; OpDash functions pinned to the EU (Ireland)
Anthropic — AI model that generates assistant replies
Data: Conversation content sent to the model to produce a reply
Location: United States
Voyage AI — Text embeddings for knowledge search
Data: Content of a customer's ingested documents and website, converted to embeddings
Location: United States
Stripe — Payments, subscriptions, and tax
Data: Billing and payment details, business contact information, tax data
Location: United States / EU (Stripe Payments Europe)
Cloudflare — Bot protection at signup (Turnstile)
Data: Client IP address and a challenge token, to distinguish humans from bots at signup
Location: Global
Upstash — Rate-limiting and abuse-prevention store
Data: Short-lived rate-limit counters keyed by hashed IP / session token (no raw IP)
Location: EU
Sentry — Application error monitoring
Data: Exception and diagnostic payloads (request id, opaque ids, hashed IP — no raw personal data by design)
Location: EU (Germany)
Axiom — Application logging
Data: Structured log lines (request id, hashed IP — no raw personal data by design)
Location: EU
PostHog — Product analytics
Data: Named funnel events plus autocaptured page interactions and heatmaps; sets a cookie and uses local storage. Loaded only after the visitor accepts statistics cookies.
Location: EU Cloud
UptimeRobot — Uptime monitoring and alerting
Data: Your team's alert-contact email; pings a public health URL
Location: United States / EU
Resend — Transactional and marketing email
Data: Recipient email addresses — signup confirmation and password-reset email for your OpDash account, and the marketing site (opdash.co) mailing list
Location: United States (messages are sent from the EU/Ireland region)
Not yet in use
The following are planned and are not currently engaged. We will add them to this list before they go live:
- Amazon SES (AWS), EU (Ireland) — notification email from the application, such as an alert to your team when the assistant captures a new lead (would process your team’s email addresses and the lead’s contact details).
- Twilio — SMS notifications (would process end-user phone numbers).
- A calendar provider — booking and scheduling (would process booking-attendee data).
Changes to this list
We will update this page when we add or replace a sub-processor. Where required, we will give advance notice so that customers can review the change. To be notified of changes, contact us at the address below.
Contact
Questions about this list, our sub-processors, or our data-protection practices: privacy@opdash.co.