Back to the privacy policy
Legal

Sub-processors

Last updated: [DATE]

Infrastructure

WhoWhat forWhat they receiveWhere
HetznerApplication server and PostgreSQL database, managed through Dokploy. Your data at rest lives here.Everything the product stores: account, workspace, client, project, invoice, transaction and document records.Helsinki, Finland (EU).
VercelCurrent production hosting and scheduled jobs, plus cookieless Web Analytics on both the site and the app.Request data in transit. Aggregate page view counts, with no cookie and no cross site identifier.United States by default.
Cloudflare R2Object storage for every uploaded file and for nightly database backups.File contents and filenames, generated exports, full database dumps.EU jurisdiction, under Cloudflare's jurisdictional restriction on the bucket. The "auto" endpoint setting governs routing only, not where the bucket's data resides.

Communications

WhoWhat forWhat they receiveWhere
ResendAll outbound email (verification, invitations, invoice and proposal delivery, digests) and the inbound address you forward receipts to.Recipient address, message body, and for inbound mail the attachments and participants.United States.

AI providers

This is the group that matters most, because your business content is what gets sent. What each provider does with content once it arrives is governed by their terms, not ours.

WhoWhat forWhat they receiveWhere
Google (Gemini API)First choice for every AI feature: receipt reading, document classification, contract review, transaction categorisation, drafting and chat.Receipt and invoice files, document text, transaction descriptions, project and client context, your chat messages. Client enrichment also reaches Google Search through search grounding.Google Cloud, region not pinned.
Mistral AIFallback provider when Gemini is rate limited or unavailable.The same content as above, for whichever call falls through to it.France, EU.
OpenAISupported in our provider cascade but not currently switched on. No key is configured, so nothing reaches OpenAI today.None at present.United States, if enabled.

Banking and payments

WhoWhat forWhat they receiveWhere
PlaidBank connections for the United States and Canada. Read only, transactions only.Institution, account identifiers, balances and transactions. We send an opaque user id, never your name.United States and EU.
Enable BankingOpen banking connections across the EU, UK and EEA. Read only.Accounts, balances, transactions and the account holder details your bank returns.Finland, EU.
StripeLets your clients pay your invoices by card, through your own connected Stripe account.Invoice number, line item names, amounts and currency. Your client's card details go straight to Stripe and never touch Worklyn.United States.
PolarYour own Worklyn subscription and checkout.Account email and name, plus metadata linking the checkout to your user and workspace.United States.

Connections you turn on yourself

None of these are contacted unless you connect them, and disconnecting stops it.

WhoWhat forWhat they receiveWhere
GoogleSign in, Google Calendar sync, and Gmail receipt sync. The Gmail scope is a separate, read only flow that never gates signing in.Profile and email, calendar events, receipt and invoice attachments.United States.
MicrosoftSign in, Outlook Calendar, Teams meeting links, and Outlook receipt sync.Profile and email, calendar events, meeting links, mail attachments.United States and EU.
LinkedIn and GitHubSign in only.Profile and email.United States.
XeroAccounting sync.Invoices, transactions, contacts and chart of accounts.New Zealand and global.
Intuit QuickBooksAccounting sync.Invoices, transactions and contacts.United States.
ComposioOAuth broker for the AI assistant connectors: Linear, Jira, Asana, Trello, ClickUp, Monday, Notion, Google Docs, Drive and Sheets, Airtable, Dropbox, Slack, Zoom, HubSpot, Salesforce, Pipedrive, GitHub, QuickBooks and Toggl.Composio holds the OAuth tokens for those tools so we never store them. Tool requests and results pass through it.United States.

Loaded by your browser

These run in the page, which means your IP address reaches them directly.

WhoWhat forWhat they receiveWhere
logo.devMerchant and client logos on transactions and client records.The merchant domain in the image URL, and your IP address.United States.
Google Maps PlacesAddress autocomplete inside the app.The address text you type, and your IP address.United States.
Google FontsWebfonts on this marketing site only. The product self hosts its fonts.Your IP address.United States.

Not in use

Three things you might expect to see here, and why they are not: Lemon Squeezy was replaced by Polar and its code is parked, so no billing data reaches it. Fortnox is registered as an accounting option but is not wired up. Our background job runner falls back to running work in the app itself, so no job payloads leave our own infrastructure.

How we pick them

We add a sub-processor only when a feature genuinely needs one, and we pick the option that sees the least. That has meant bank connections that can read and never pay, a separate narrow mail scope so signing in never carries mailbox access, provider tokens deleted rather than stored because nothing reads them, and features that would send more than they need kept behind a switch until they earn it. Before anything goes live we look at what it would actually receive, what its terms say about retention and training, and whether the same job can be done with less.

When this list changes

Material additions or replacements are emailed to workspace owners and published here before they take effect. The date at the top is the marker. If a change does not sit right with you, export everything from your account settings and close the account, and you take your data with you.

Questions: hello@worklyn.co.