EVENHELM
Legal

Sub-processors

The third-party providers we rely on to run EvenHelm. Each is bound by contract to protect personal data and to use it only as we instruct.

Effective date: 28 June 2026Last updated: 28 June 2026

A sub-processor is a third party we engage to process personal data on our behalf in order to deliver the Service. The table below lists the categories of sub-processor we currently use, what each does, the personal data it processes, and where it is located. This page also supports the general sub-processor authorisation in our Data Processing Addendum.

Sub-processor categoryRoleData processedLocation
Cloud database & file-storage providerApplication database and private file storage.All application data, including the personal data in client, invoice, and expense records, and account data.EU
Cloud hosting & infrastructure providerHosting and compute for the application and background processing.All data in processing while the application runs (compute layer).EU
Payment processing providerPayment processing and subscription billing.Account email address and billing data. Full card details are handled by the processor; we never store them.United States (SCCs / EU-US Data Privacy Framework)
Transactional email providerTransactional email delivery (verification, reset, invites, alerts).Recipient name, email address, and email tokens.EU
Analytics providerConsent-gated website usage analytics (loaded only after opt-in).Anonymised IP address and usage events.United States (SCCs / EU-US Data Privacy Framework)

Your connected providers are not our sub-processors

The third-party cloud and AI provider accounts you attach yourself are read-only cost and usage integrations that you control, not EvenHelm sub-processors. You provide the credentials, you decide which accounts to link, and we read only your own aggregated cost and usage figures with least-privilege, read-only access. No customer content, client data, or prompts are ever sent to any AI provider.

Changes to this list

We may add or replace sub-processors as the Service evolves. When we do, we will update this page and, where required, give advance notice to customers under our Data Processing Addendum — at least 30 days — so that customers may object on reasonable, documented data-protection grounds before the change takes effect.