Subprocessors
These providers support the current service. The role column explains what information each receives and whether it supports customer workspaces or an optional interaction. We do not claim that all processing, support or delivery takes place in the EU.
Service providers and optional services
| Processor | Role | Location and scope | Docs |
|---|---|---|---|
| Supabase | Authentication identities, workspace database records and uploaded files. | Project hosting region is deployment-specific; provider operations may involve other countries. | Provider privacy information |
| Vercel | Web hosting, application requests and technical logs, including sanitized security-policy diagnostics when enabled. Sanitized operation timings, failures, email-attempt and cleanup-job health; optional browser diagnostics require consent. | Application deployment configuration requests Frankfurt (fra1); edge delivery and provider operations are not limited to that region. | Provider privacy information |
| Brevo | Service email delivery and enquiry notifications, including addresses and message contents. | Provider infrastructure and subprocessors; refer to its current notice and the applicable agreement. | Provider privacy information |
| Calendly | Optional meeting booking: connection information, name, email, meeting details and any answers you enter. | United States and provider service locations; only loaded in the page after your choice. | Provider privacy information |
| Optional Google sign-in and the identity information returned during that flow. | Google’s global services; see its privacy notice. | Provider privacy information | |
| PostHog | Optional consent-based product analytics: selected completed actions, time and pseudonymous identifiers; no HR contents, recordings or automatic page tracking. | EU Cloud (Frankfurt), EU ingestion endpoint. Provider support and subprocessors may involve international transfers. | Provider privacy information |
How to read this list
Supabase, Vercel and Brevo support service operations. Calendly supports optional booking, and Google sign-in is used only when selected. Providers may act as processors for service data and as controllers for their own account, security or website activities. An optional booking or sign-in provider does not receive the contents of your BookkeeperHR workspace through that integration.
Published provider notices do not confirm the settings or agreements on a particular customer deployment. Contact support@bookkeeperhr.com for the applicable processing agreement, hosting details and international-transfer safeguards.
Reviewed for the optional PostHog integration on 2026-09-22. Collection requires explicit consent and deployment configuration. Review this list, consent and retention before changing providers, plans or captured data. Applicable customer agreements and notice requirements still apply.
Last reviewed: 2026-09-23