https://app.veloratech.live/legal/subprocessors
Velora Legal
Subprocessor List
Version 1.0Effective Current
Part V - Subprocessor List
This list identifies third parties that may process Customer Personal Data on Velora’s behalf in the production service. Customer grants general authorization under the DPA subject to the notice/objection process there. Provider legal entities and processing locations may change under their published terms; Velora should review this list before each material update.
| Provider | Purpose | Location / transfer context | Notes |
|---|---|---|---|
| Supabase | Database, authentication, storage, server-side data infrastructure | EEA/other configured regions and provider subprocessors | DPA available from Supabase; current DPA includes international-transfer safeguards and published subprocessors. |
| n8n | Workflow orchestration and execution | EU cloud hosting; some subprocessors may process in EU/US | n8n publishes a DPA and subprocessor list; cloud security page states EU hosting and encryption at rest/in transit. |
| OpenAI | AI inference, extraction, classification, summarization and generation through the API | EEA/US/other provider infrastructure depending service configuration | OpenAI DPA effective 2026; API/business data is not used for model training by default unless explicitly opted in; published subprocessor list and transfer mechanisms apply. |
| Postmark / AC PM, LLC (ActiveCampaign) | Inbound and outbound transactional/application email delivery and routing | United States and listed hosting subprocessors | Postmark DPA incorporates SCCs and lists its subprocessors. Email content and metadata may transit its systems. |
| Vercel | Hosting and delivery of the customer-facing Next.js application and server functions | Production region includes Dublin (dub1); Vercel may process in the US and other locations under its DPA | Vercel DPA applies to Pro/Enterprise plans and includes subprocessors and transfer provisions. |
| Stripe (once enabled for customer billing) | Subscription checkout, invoicing, payment processing and related fraud/security functions | EEA/US/global payment infrastructure | Stripe acts as processor for some payment processing and as controller for specified regulated/fraud purposes. Payment-card details should be collected by Stripe and not stored in Velora. |
Tavily / public-web market discovery: Velora’s current design intends public-web discovery to operate without Customer Personal Data. Tavily is therefore not listed above as a Customer Personal Data subprocessor for the current architecture. If a future feature sends Customer Personal Data to Tavily or another search provider, Velora must update the DPA/Subprocessor List and complete the applicable transfer/security review before that use.