A sub-processor is a company that handles some of your data so Worklyn can do its job: hosting it, storing your files, sending your invoices, reading your receipts. This is the whole list, not a selection. It is built by reading our own code, so it stays honest as the product changes.
Infrastructure
| Who | What for | What they receive | Where |
|---|---|---|---|
| Hetzner | Application server and PostgreSQL database, managed through Dokploy. Your data at rest lives here. | Everything the product stores: account, workspace, client, project, invoice, transaction and document records. | Helsinki, Finland (EU). |
| Vercel | Current production hosting and scheduled jobs, plus cookieless Web Analytics on both the site and the app. | Request data in transit. Aggregate page view counts, with no cookie and no cross site identifier. | United States by default. |
| Cloudflare R2 | Object storage for every uploaded file and for nightly database backups. | File contents and filenames, generated exports, full database dumps. | EU jurisdiction, under Cloudflare's jurisdictional restriction on the bucket. The "auto" endpoint setting governs routing only, not where the bucket's data resides. |
Communications
| Who | What for | What they receive | Where |
|---|---|---|---|
| Resend | All outbound email (verification, invitations, invoice and proposal delivery, digests) and the inbound address you forward receipts to. | Recipient address, message body, and for inbound mail the attachments and participants. | United States. |
AI providers
This is the group that matters most, because your business content is what gets sent. What each provider does with content once it arrives is governed by their terms, not ours.
| Who | What for | What they receive | Where |
|---|---|---|---|
| Google (Gemini API) | First choice for every AI feature: receipt reading, document classification, contract review, transaction categorisation, drafting and chat. | Receipt and invoice files, document text, transaction descriptions, project and client context, your chat messages. Client enrichment also reaches Google Search through search grounding. | Google Cloud, region not pinned. |
| Mistral AI | Fallback provider when Gemini is rate limited or unavailable. | The same content as above, for whichever call falls through to it. | France, EU. |
| OpenAI | Supported in our provider cascade but not currently switched on. No key is configured, so nothing reaches OpenAI today. | None at present. | United States, if enabled. |
Banking and payments
| Who | What for | What they receive | Where |
|---|---|---|---|
| Plaid | Bank connections for the United States and Canada. Read only, transactions only. | Institution, account identifiers, balances and transactions. We send an opaque user id, never your name. | United States and EU. |
| Enable Banking | Open banking connections across the EU, UK and EEA. Read only. | Accounts, balances, transactions and the account holder details your bank returns. | Finland, EU. |
| Stripe | Lets your clients pay your invoices by card, through your own connected Stripe account. | Invoice number, line item names, amounts and currency. Your client's card details go straight to Stripe and never touch Worklyn. | United States. |
| Polar | Your own Worklyn subscription and checkout. | Account email and name, plus metadata linking the checkout to your user and workspace. | United States. |
Connections you turn on yourself
None of these are contacted unless you connect them, and disconnecting stops it.
| Who | What for | What they receive | Where |
|---|---|---|---|
| Sign in, Google Calendar sync, and Gmail receipt sync. The Gmail scope is a separate, read only flow that never gates signing in. | Profile and email, calendar events, receipt and invoice attachments. | United States. | |
| Microsoft | Sign in, Outlook Calendar, Teams meeting links, and Outlook receipt sync. | Profile and email, calendar events, meeting links, mail attachments. | United States and EU. |
| LinkedIn and GitHub | Sign in only. | Profile and email. | United States. |
| Xero | Accounting sync. | Invoices, transactions, contacts and chart of accounts. | New Zealand and global. |
| Intuit QuickBooks | Accounting sync. | Invoices, transactions and contacts. | United States. |
| Composio | OAuth broker for the AI assistant connectors: Linear, Jira, Asana, Trello, ClickUp, Monday, Notion, Google Docs, Drive and Sheets, Airtable, Dropbox, Slack, Zoom, HubSpot, Salesforce, Pipedrive, GitHub, QuickBooks and Toggl. | Composio holds the OAuth tokens for those tools so we never store them. Tool requests and results pass through it. | United States. |
Loaded by your browser
These run in the page, which means your IP address reaches them directly.
| Who | What for | What they receive | Where |
|---|---|---|---|
| logo.dev | Merchant and client logos on transactions and client records. | The merchant domain in the image URL, and your IP address. | United States. |
| Google Maps Places | Address autocomplete inside the app. | The address text you type, and your IP address. | United States. |
| Google Fonts | Webfonts on this marketing site only. The product self hosts its fonts. | Your IP address. | United States. |
Not in use
Three things you might expect to see here, and why they are not: Lemon Squeezy was replaced by Polar and its code is parked, so no billing data reaches it. Fortnox is registered as an accounting option but is not wired up. Our background job runner falls back to running work in the app itself, so no job payloads leave our own infrastructure.
How we pick them
We add a sub-processor only when a feature genuinely needs one, and we pick the option that sees the least. That has meant bank connections that can read and never pay, a separate narrow mail scope so signing in never carries mailbox access, provider tokens deleted rather than stored because nothing reads them, and features that would send more than they need kept behind a switch until they earn it. Before anything goes live we look at what it would actually receive, what its terms say about retention and training, and whether the same job can be done with less.
When this list changes
Material additions or replacements are emailed to workspace owners and published here before they take effect. The date at the top is the marker. If a change does not sit right with you, export everything from your account settings and close the account, and you take your data with you.
Questions: hello@worklyn.co.