A sub-processor is a third party we engage to process personal data on our behalf in order to deliver the Service. The table below lists the categories of sub-processor we currently use, what each does, the personal data it processes, and where it is located. This page also supports the general sub-processor authorisation in our Data Processing Addendum.
| Sub-processor category | Role | Data processed | Location |
|---|---|---|---|
| Cloud database & file-storage provider | Application database and private file storage. | All application data, including the personal data in client, invoice, and expense records, and account data. | EU |
| Cloud hosting & infrastructure provider | Hosting and compute for the application and background processing. | All data in processing while the application runs (compute layer). | EU |
| Payment processing provider | Payment processing and subscription billing. | Account email address and billing data. Full card details are handled by the processor; we never store them. | United States (SCCs / EU-US Data Privacy Framework) |
| Transactional email provider | Transactional email delivery (verification, reset, invites, alerts). | Recipient name, email address, and email tokens. | EU |
| Analytics provider | Consent-gated website usage analytics (loaded only after opt-in). | Anonymised IP address and usage events. | United States (SCCs / EU-US Data Privacy Framework) |
Your connected providers are not our sub-processors
The third-party cloud and AI provider accounts you attach yourself are read-only cost and usage integrations that you control, not EvenHelm sub-processors. You provide the credentials, you decide which accounts to link, and we read only your own aggregated cost and usage figures with least-privilege, read-only access. No customer content, client data, or prompts are ever sent to any AI provider.
Changes to this list
We may add or replace sub-processors as the Service evolves. When we do, we will update this page and, where required, give advance notice to customers under our Data Processing Addendum — at least 30 days — so that customers may object on reasonable, documented data-protection grounds before the change takes effect.