Data protection
Subprocessors
Last reviewed: 14 July 2026. The providers actually used can depend on enabled features and the customer agreement. Contractual transfer safeguards apply where processing occurs outside the EU/EEA.
| Provider | Purpose | Data categories |
|---|---|---|
| Neon | Managed PostgreSQL database hosting | Account, tenant, compliance, security, and operational data |
| Vercel | Application hosting and delivery | Request, device, security, and application data |
| Stripe | Subscription billing | Customer, billing, transaction, and tax data |
| Resend | Transactional email delivery | Recipient, message, and delivery data |
| Sentry | Optional error and performance monitoring | Error, device, request, and diagnostic metadata, subject to consent where required |
| OpenRouter and selected model providers | Optional AI-assisted service functions | Only the content selected for the relevant AI function; customers should not submit unnecessary personal data |
Questions or objections concerning a new subprocessor may be sent to privacy@cramio.eu.