Subprocessors
Last updated: 2026-05-28
Empatalk uses the following subprocessors to deliver the service. Each vendor is bound by a Data Processing Agreement (DPA) under GDPR Article 28 and processes only the data categories listed below.
| Vendor | Service & purpose | Data categories | Region | DPA |
|---|---|---|---|---|
| Vercel Inc. | Application hosting + edge network Serves the empatalk.app web application and APIs | IP address, user-agent, request headers, request bodies | EU (Frankfurt) + global edge | View DPA → |
| MongoDB Atlas (MongoDB Inc.) | Primary database Stores user accounts, survey answers, organizations | Email, display name, survey answers (incl. GDPR Article 9 categories), team membership | EU (Frankfurt) | View DPA → |
| Google Cloud (Firebase Authentication) | Authentication identity provider Validates email + password / OAuth sign-in and issues session tokens | Email, IP address, sign-in metadata | EU | View DPA → |
| Stripe Payments Europe Ltd. | Subscription billing + invoicing Processes paid-plan subscriptions and stores billing records | Email, billing address, card metadata (tokenised), invoice history | EU (Ireland) | View DPA → |
| OpenAI Ireland Ltd. | LLM API for survey-derived guidelines + rewrites Generates personalised communication guidelines and message rewrites from survey answers | Survey answers (incl. GDPR Article 9 categories), user-typed message drafts | EU (Ireland) routing where supported; US for older endpoints | View DPA → |
| Resend Inc. | Transactional email delivery Sends welcome, password-reset, billing, and re-engagement emails | Email, display name, email content, delivery metadata | EU | View DPA → |
| Functional Software, Inc. (Sentry) | Error monitoring + performance tracing Captures runtime exceptions and slow-request traces for triage | IP address (truncated), user agent, request path, request ID, Firebase UID (no PII in messages) | EU (Frankfurt) — `o*.ingest.de.sentry.io` | View DPA → |
| Slack Technologies LLC | Slack bot integration (opt-in) Enables the /empatalk slash command in workspaces a user explicitly installs the bot into | Slack workspace ID, Slack user ID, message text submitted to the bot | US (Slack global) | View DPA → |
We commit to giving 30 days' notice before adding a new subprocessor. Customers on a paid plan can email hello@empatalk.app to subscribe to subprocessor-change notifications.