On this page 7 sections
About this list
HeavenlyTrade S.R.L.S., trading as Tallently, uses the providers below to operate the service. A provider is a subprocessor when it processes Customer Personal Data on Tallently’s behalf under the Data Processing Agreement.
We assess a provider’s role, security and contractual commitments before authorising it. We require data protection terms appropriate to the service and remain responsible for subprocessor processing as required by law.
Current subprocessors
| Provider | Purpose | Data involved | Processing location | Transfer safeguards |
|---|---|---|---|---|
| Supabase, Inc. — legal terms | Database, authentication, private file storage and realtime updates | Account data, business profiles, customer content, documents and audit records | Primary project region: London, United Kingdom; limited global support access | UK/EU adequacy where applicable, SCCs and UK Addendum |
| Vercel, Inc. — legal terms | Application hosting, server functions, content delivery and operational metrics | Network data, request metadata, application logs and transient service data | Primary compute: London, United Kingdom; global delivery network | SCCs, UK Addendum and other lawful transfer mechanisms |
| Formspree, Inc. — legal terms | Early-access registration and account-request form processing | Prospect contact details, business-profile answers, consent choices and form metadata; never passwords | Amazon Web Services infrastructure in the United States | EU Standard Contractual Clauses and provider security controls |
| API Hero Ltd (Trigger.dev) — legal terms | Background-job orchestration for document processing and export tasks | Document files, extracted fields, internal identifiers and processing logs | United States cloud infrastructure; provider established in the United Kingdom | SCCs and UK Addendum |
| Anthropic Ireland, Limited — legal terms | AI classification and structured data extraction | Uploaded documents, business-profile context and extraction instructions | Ireland with international processing, including the United States | SCCs and other lawful transfer mechanisms under Anthropic’s DPA |
| ActiveCampaign, LLC (Postmark) — legal terms | Transactional email, account email and inbound document email | Email addresses, message metadata, message bodies and attachments | United States, including Chicago-area and AWS infrastructure | SCCs, UK Addendum and applicable Data Privacy Framework commitments |
| Stripe Payments Europe, Limited — legal terms | Subscription checkout, billing, invoices and customer portal | Contact, billing, subscription and payment-related data; Tallently does not store full card details | Ireland with global processing, including the United States | SCCs, UK Addendum and applicable Data Privacy Framework commitments |
| Cloudflare, Inc. — legal terms | DNS services and routing of Tallently support and privacy email aliases | DNS request data and email routing metadata/content when an alias is contacted | Global network, including the United States | SCCs and applicable Data Privacy Framework commitments |
Provider-specific notes
- Primary service region. Tallently application functions and the Supabase project are configured in London to keep core compute and stored customer records close together.
- Early-access forms. Formspree processes prospect and business-profile information submitted through Tallently registration and account-request forms. Tallently does not send passwords, 2FA codes or full tax identifiers to Formspree.
- AI processing. Documents are sent to Anthropic’s commercial API for classification and extraction. Anthropic’s commercial terms prohibit training models on customer content from the service.
- Inbound email. Postmark receives messages sent to a customer’s Tallently email-in address and forwards their content to the processing pipeline. Postmark’s standard service documentation currently describes a 45-day message-content and metadata retention period.
- Payments. Stripe independently determines some processing required for payment security, fraud prevention and financial compliance. Full card details are not made available to Tallently.
- Cloudflare. Tallently uses Cloudflare for DNS and email-alias routing, not as the primary host for customer documents.
International transfers
Some providers operate from the United States or use global infrastructure. Where a transfer from the EEA, UK or Switzerland requires a safeguard, Tallently relies on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, an applicable adequacy decision or Data Privacy Framework certification, and supplementary technical and organisational measures where appropriate. See the DPA transfer terms for details.
Changes and objections
To receive change notices, email privacy@tallently.com with the subject “Subscribe to subprocessor updates” and identify your organisation. A Customer may object during the notice period on reasonable data-protection grounds using the process in the DPA.
Customer-directed third-party services
A service is not necessarily a Tallently subprocessor merely because a Customer chooses to export data or connect its own account. When optional accounting integrations become available, the Customer may direct a transfer to the relevant provider under the Customer’s own agreement with that provider.
Intuit/QuickBooks and Xero are not included in the current list because Tallently’s present production service does not use them as subprocessors. We will update this page before they begin processing Customer Personal Data on Tallently’s behalf.
Contact
Questions about a provider, processing location or transfer safeguard can be sent to privacy@tallently.com. Please include your organisation name and the provider concerned.