Ops
Product How it flows Security
ES CA EN
Book a demo

Legal

Sub-processors

Last updated: 2026-09-16

Legal notice Privacy Security Sub-processors

To provide the Ops service, Alejandro Aumedes Terés (the processor) uses the sub-processors listed below. Each is bound by a written contract with data protection obligations no less protective than our data processing agreement with the customer, and processes personal data only as far as its function requires.

We will give customers at least 30 days' notice before adding or replacing a sub-processor. During that period a customer may object on reasonable data protection grounds; if we cannot resolve the objection, the customer may terminate the affected service.

Current sub-processors

Sub-processor Function Data processed Location Transfers
IONOS SE Hosting: servers, disks and DNS All data in the instance database and uploaded files; DNS query metadata Germany (EU) None — EU
IONOS SE (object storage) Off-site backups Full database backups, encrypted before upload (we hold the keys; IONOS sees only ciphertext) EU None — EU
Resend Service email: sign-in codes and notifications Recipient's email address and name, message content Amazon SES, EU region (Ireland) US company: EU Standard Contractual Clauses, processing in the EU region
Microsoft Ireland Operations Ltd — Azure OpenAI Only if the customer turns on the assistant or expense auto-fill: answering questions and reading receipts The questions and the project or customer data needed to answer them; receipt images and PDFs Azure EU region None — EU
Microsoft Ireland Operations Ltd — Graph and Entra ID Only if the customer turns it on: sending invoices by email from the customer's account, and Entra ID sign-in Sender and recipient metadata; directory identifiers of the signing-in user EU (Microsoft EU Data Boundary) None — EU; customer-controlled tenant

Not sub-processors

  • Zitadel, the identity service, runs on our own IONOS infrastructure; it is not a third-party service and is covered by the hosting entry.
  • Let's Encrypt issues TLS certificates and processes only domain names, not personal data.
  • The customer's own identity provider (its Microsoft or Google tenant) is controlled by the customer.
  • The customer's own mail server: when invoices are sent with the customer's SMTP or Graph credentials, that channel belongs to the customer.

Change log

Date Change
2026-09-16 First publication. Azure OpenAI added for the assistant and expense auto-fill.
Ops

Operations, handled.

Legal notice Privacy Security Sub-processors

© 2026 theaumol