Sub-processors
Last reviewed 02-Oct-2026. Cevoriq runs in two data regions: US (cevoriq.com) and EU (eu.cevoriq.com). This page lists the companies that process customer or personal data on our behalf, where they do it, and when they are used. We notify customers in advance before adding or replacing a sub-processor; the notice period is set out in each customer’s Data Processing Agreement.
Where we have not yet verified a vendor’s processing location, the table says so (“Unconfirmed — under verification”) instead of guessing. See Data Residency for what stays in your region.
1. Sub-processors
Companies we choose, which process customer or personal data.
| Sub-processor | Purpose | Data | US region (cevoriq.com) | EU region (eu.cevoriq.com) | When it applies |
|---|---|---|---|---|---|
| Supabase | Primary PostgreSQL database, US region | All tenant application data (users, technicians, customers, work orders, incidents, audit log, etc.) | AWS us-east-1, US | Not used | Always (US tenants) |
| Neon | Primary PostgreSQL database, EU region | All tenant application data, as above | Not used | AWS eu-central-1, Frankfurt, DE | Always (EU tenants) |
| Vercel | Application hosting and serverless compute (both cells) | All data in transit through the app; request logs (IP, user agent, URLs). Logs: under verification retention and location | Function regions iad1, cle1, sfo1, pdx1 (US) | Function regions fra1, cdg1, dub1, arn1 (EU). The exact region is set per project in the Vercel dashboard: under verificationUnconfirmed — under verification | Always |
| Vercel Blob | File storage fallback when no regional object store is configured (also used for the cold archive) | Uploaded files and attachments (e.g. purchase-order documents) | Store location under verificationUnconfirmed — under verification | Applies only if the EU R2 store is missing. Not yet confirmed whether this can happen in prod (under verification)Unconfirmed — under verification | Only if configured and no regional object store exists for that region |
| Cloudflare R2 | Object storage for uploaded files, per-region buckets; also holds EU database backups | Uploaded files and attachments; EU encrypted DB backup files | R2 bucket in the US region. Bucket location hint under verificationUnconfirmed — under verification | EU-jurisdiction R2 bucket (<account>.eu.r2.cloudflarestorage.com) | Always where a regional object store is configured (see Vercel Blob for the fallback) |
| Clerk | Authentication, sessions, organisations, RBAC | Name, email, auth identifiers, session metadata, IP/user agent at sign-in | Clerk-hosted. Location under verificationUnconfirmed — under verification | Same single Clerk instance is assumed. under verification whether EU users are processed in the USUnconfirmed — under verification | Always |
| Resend | Transactional email | Recipient email address, name, and email content (notifications, invites, waitlist) | Resend-hosted. Location under verificationUnconfirmed — under verification | Same provider for both regions. Location under verificationUnconfirmed — under verification | Only if configured; otherwise no email is sent |
| Google (Gemini API) | Default AI provider for AI features | Prompt content: tenant data that a user sends to AI features (ticket/incident text, documents for extraction, report questions) | Google-hosted. Location under verificationUnconfirmed — under verification | Same. Location under verificationUnconfirmed — under verification | Default AI provider when an AI feature is used and the platform key is set |
| OpenAI | Alternative AI provider | As row 8 | Location under verificationUnconfirmed — under verification | Location under verificationUnconfirmed — under verification | Only if the tenant selects it. Platform key used if one is set; otherwise the tenant's own key (BYO) |
| Anthropic | Alternative AI provider | As row 8 | Location under verificationUnconfirmed — under verification | Location under verificationUnconfirmed — under verification | Only if the tenant selects it (platform key, or BYO) |
| Microsoft Azure (OpenAI Service) | Alternative AI provider | As row 8 | Set by the tenant's endpoint | Set by the tenant's endpoint | Only if the tenant selects it (platform key, or BYO) |
| AWS Bedrock | Alternative AI provider | As row 8 | Tenant-chosen AWS region | Tenant-chosen AWS region (e.g. eu-central-1) | Only if the tenant selects it. BYO-only: the platform holds no Bedrock key, so it runs in the tenant's own AWS account |
| Upstash (QStash) | Scheduled-job delivery: signed HTTP calls to cron routes | Route URLs and signed request metadata. No customer records are expected in the payload (under verification the payloads) | Location under verificationUnconfirmed — under verification | Location under verificationUnconfirmed — under verification | Always (all scheduled routes) |
| GitHub (Actions + artifact storage) | Nightly database backup for the US region: GitHub-hosted runner dumps the DB, encrypted dump stored as a workflow artifact for 30 days | Full US database contents (encrypted at rest as an artifact) | GitHub-hosted runner (US) and US-resident artifact | Not used (EU runs on external: and is skipped by the matrix) | Always (US) |
| Oracle Cloud Infrastructure | EU backup runner (Always Free VM cevoriq-backup-eu, eu-frankfurt-1) that dumps the EU DB and writes to the EU R2 bucket | Full EU database contents, in transit through the VM | Not used | Frankfurt, DE | Always (EU) |
| Google Analytics | Website analytics on marketing pages | Visitor IP, device/browser data, page views, cookie identifiers (visitors, not tenant records) | Google-hosted. Location under verificationUnconfirmed — under verification | Same | Only if configured, and only after the visitor opts in |
| Browser push services (e.g. Google FCM, Mozilla autopush, Apple). The service is set by the device's browser, not by us | Web Push notifications to technicians | Notification payload: event kind, ticket number, start time, deep link; the push subscription endpoint | Set by the browser vendor | Set by the browser vendor | Only if VAPID keys are configured and the technician opts in to notifications |
2. Integrations you connect
These run only when a customer sets them up with its own account and credentials. Data flows between the customer’s own account and Cevoriq under the customer’s own agreement with that vendor. They are not our sub-processors.
| Sub-processor | Purpose | Data | US region (cevoriq.com) | EU region (eu.cevoriq.com) | When it applies |
|---|---|---|---|---|---|
| Samsara | Fleet telematics sync (vehicles, odometer) | Vehicle identifiers, odometer, fleet data from the tenant's Samsara account | The tenant's own vendor account | The tenant's own vendor account | Only when a tenant connects its own account |
| Geotab | Fleet telematics sync | As Samsara | The tenant's own vendor account | The tenant's own vendor account | Only when a tenant connects its own account |
| ServiceNow | Incident/ticket integration and field mapping | Incident/ticket records and mapped fields, both directions | The tenant's own vendor account | The tenant's own vendor account | Only when a tenant connects its own account |
3. Notes
- AI providers and your own keys. When a customer supplies its own API key or endpoint, the AI provider processes the data under the customer’s own account and contract with that provider. AWS Bedrock is always used this way.
- Single global services. Some services have no per-region setting. Until a location is confirmed above, assume data they handle may be processed outside the EU.
Questions about this list, or a request for the signed agreement: support@cevoriq.com.