Sub-processors
Last Modified: May 30, 2026 · Version 2026-05-30
This page lists the third parties that Clustra Technologies Ltd. engages to help us deliver the Service. Together with the Data Processing Agreement, it forms Annex III of the DPA and discloses what every Sub-processor does, what data they receive, where they Process it, and the safeguards we rely on for cross-border transfers.
Notification of Changes
We provide at least 30 days' advance notice before engaging a new Sub-processor or replacing an existing one. Notice is sent by email to the Workspace Administrator and posted as an in-product notice. Customers may also subscribe to this page's change log by emailing privacy@clustra.org with the subject "Subscribe: sub-processor updates".
If you object to a new Sub-processor on reasonable data-protection grounds within the notice period, the process described in §6 of the DPA applies.
Service Sub-processors
The following Sub-processors are necessary for Clustra to provide the Service. Some Workspaces may engage with additional optional integrations the Customer chooses to connect (for example, Google Mail or Google Calendar in the Customer's own account); those integrations are governed by the Customer's direct relationship with the third party and are not listed below.
Infrastructure & Storage
| Sub-processor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Vercel (opens in new tab) Vercel Inc. (United States) | Hosting and delivery of the Clustra web and marketing properties | IP, user agent, request metadata, telemetry needed to serve the application | United States; global edge network | SCCs (EEA) / UK Addendum / NDPA-approved mechanism |
| DigitalOcean (opens in new tab) DigitalOcean, LLC (United States) | Hosting of the Clustra API server and supporting workloads | Application data in transit and at rest, operational logs | United States and European Union regions | SCCs / UK Addendum / NDPA mechanism |
| MongoDB Atlas (opens in new tab) MongoDB, Inc. (United States) | Managed MongoDB cluster storing global user, workspace, and security data | Identity PII (encrypted at rest), workspace metadata, security event records, billing metadata | Cloud region selected at provisioning time | SCCs / UK Addendum / NDPA mechanism |
| Neon (opens in new tab) Neon, Inc. (United States) | Managed PostgreSQL for per-feature application databases (helpdesk, plan, mail, chat, calendar, notes, recap) | Customer Content stored by the corresponding application | United States (us-east1) | SCCs / UK Addendum / NDPA mechanism |
| Redis Cloud (opens in new tab) Redis Ltd. (United States / Israel) | Managed Redis for authentication sessions, OAuth state, application cache | Session metadata (user ID, IP, user agent, timestamps), short-lived tokens | United States (us-east1) | SCCs / UK Addendum / NDPA mechanism |
| Google Cloud Storage (opens in new tab) Google LLC (United States) | Object storage for files uploaded into Workspaces | Files uploaded by Customer members under per-user storage paths | United States (us-east1) | SCCs / UK Addendum / NDPA mechanism; EU–U.S. Data Privacy Framework where applicable |
Identity & Secrets
| Sub-processor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Google OAuth (opens in new tab) Google LLC (United States) | Sign-in via Google for users who choose Google as their identity provider | Verified email, given name, family name, sub identifier returned by Google during sign-in. Clustra does not store Google refresh tokens. | United States | EU–U.S. Data Privacy Framework / SCCs where applicable |
| Infisical (opens in new tab) Infisical, Inc. (United States) | Key management for TOTP shared secrets and per-workspace data-encryption keys; application secrets storage | Encryption key material; 2FA TOTP shared secrets; no Customer Content | United States (self-hosted or cloud) | SCCs / UK Addendum / NDPA mechanism |
Payments
| Sub-processor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Paystack (opens in new tab) Paystack Payments Limited (Nigeria) and its affiliates | Payment processing, subscription management, invoicing | Billing email and contact name, plan, seat count, currency, provider-side customer and invoice identifiers. Paystack receives and tokenises payment instruments; Clustra does not store raw card data. | Nigeria and Paystack processing regions | Direct contractual safeguards; NDPA mechanism for transfers out of Nigeria where applicable |
Error Monitoring & Product Analytics
| Sub-processor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Sentry (opens in new tab) Functional Software, Inc. dba Sentry (United States) | Error monitoring for the web and server applications | Stack traces, request context (sensitive headers, tokens, and email patterns redacted at source), user ID reference only | United States | EU–U.S. Data Privacy Framework / SCCs where applicable |
| PostHog (opens in new tab) PostHog, Inc. (United States) | Product analytics; fires only after the user grants analytics consent | Page views, autocaptured interactions, identify events containing the signed-in user’s ID, email, and name | United States cloud (or EU cloud where selected) | EU–U.S. Data Privacy Framework / SCCs where applicable |
Internal Security Alerting
| Sub-processor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Slack (opens in new tab) Slack Technologies, LLC, a Salesforce company (United States) | Private channel for internal security event triage and on-call alerting | Event type and the scoping identifier required for triage (IP, user ID, or workspace ID). No Customer Content is sent. | United States | EU–U.S. Data Privacy Framework / SCCs where applicable |
Email Delivery
| Sub-processor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| ZeptoMail (opens in new tab) Zoho Corporation Pvt. Ltd. (India), operating the ZeptoMail service | Delivery of transactional email (verification, password reset, member invitations, billing notices, support replies, account deletion confirmation) | Recipient email address, sender, subject, message body, delivery metadata | United States data center | SCCs / UK Addendum / NDPA mechanism |
Cross-Border Transfers
Where a Sub-processor Processes Customer Personal Data outside the data exporter's jurisdiction, the transfer mechanisms listed in each row above apply. The detailed clause selections for the Standard Contractual Clauses and UK Addendum are set out in Annex IV of the DPA. We additionally apply supplementary technical measures including encryption in transit and at rest, blind indexing of identity Personal Data, segregation of cryptographic keys, and least-privilege access controls; see the Security Policy for the full set.
Historical Changes
We maintain a running log of Sub-processor changes here so that Customers can verify what changed and when.
- 2026-05-30 — page published. Reflects the Sub-processors in use as of this date.
Contact
Sub-processor questions and change-log subscription: privacy@clustra.org
Data Protection Officer: dpo@clustra.org
This page is provided for informational purposes and does not constitute legal advice. The contractual safeguards that apply to a specific Customer are governed by that Customer's Agreement and Data Processing Agreement.