Legal

Sub-Processors

Last updated: July 28, 2026

1. About this list

To deliver the Asteri platform we use a small number of third-party processors. They process personal data only on documented instructions from us, under written data processing agreements that meet the requirements of GDPR Art. 28 and the UK Data Protection Act 2018.

We notify customers of any material change to this list at least 30 days before the change takes effect. To subscribe to change notifications, email privacy@getasteri.com with the subject "Subscribe: Sub-Processor Updates."

2. Current sub-processors

ProviderPurposeDataRegion
Stripe, Inc.Payment processing (cards, ACH, subscriptions). Stripe Connect for service-business payouts.Cardholder data (tokenized — never touches our servers), billing address, email, payment metadata.United States (with global processing edges).
PlanetScale, Inc.Managed Postgres database hosting (primary application database).All customer records, organization data, communications, files metadata.United States (US-East). EU residency available on request for Enterprise.
Cloudflare, Inc.Object storage (R2) for files, photos, attachments, exports. Edge network and DDoS protection.Uploaded files (invoices, estimates, floor photos, avatars, signed documents).Global edge with US storage by default. Region restrictions available.
Telnyx LLCSMS / MMS messaging and voice calling.Customer phone numbers, message contents, call audio/recordings, voicemail, delivery and call metadata.United States.
Resend, Inc.Transactional and marketing email delivery.Recipient email, sender identity, subject, message body, delivery metadata.United States.
OpenAI, L.L.C.Large language model APIs powering AI features (smart chat, proposals, floor inspector, marketing studio).Prompt and context content (may include service details, customer notes, photos) sent at request time. Per OpenAI API terms, content is not used to train OpenAI models and is retained only for abuse monitoring.United States.
Flespi.io (Gurtam)Vehicle telemetry ingestion and fleet GPS tracking.Vehicle GPS coordinates, telematics events (speed, idle, harsh events), device identifiers.European Union / Lithuania.
Google LLCOptional Google Sign-In, Gmail, Calendar, Drive, Business Profile, Google Ads, and Data Manager integrations.Only user-authorized Google identity, Workspace, business-listing, advertising, and conversion data required by the selected integration. OAuth tokens are stored encrypted.United States (with global edges).
Sentry (Functional Software, Inc.)Application error monitoring and performance telemetry.Stack traces, request metadata, environment info. PII is scrubbed before send.United States.
Vercel, Inc.Web application hosting and edge delivery.Server logs, request metadata. No customer data persisted on Vercel infrastructure.Global edge with US primary region.

3. International transfers

Where personal data is transferred outside the EEA, UK, or Switzerland, we rely on one or more of the following safeguards: Standard Contractual Clauses (SCC  2021/914), the UK International Data Transfer Addendum, the EU-U.S. Data Privacy Framework where the sub-processor is certified, or the customer's own explicit consent for ad-hoc transfers.

4. Data Processing Agreement

Our standard Data Processing Agreement is available to all customers on request. Email privacy@getasteri.com with the subject "DPA Request" and include your organization name. We counter-sign and return within 5 business days. EEA / UK / Swiss customers receive the SCC-annexed version by default.

5. Related policies