Skip to main content

Legal

Sub-processors

Effective date: 2026-08-02. This page lists the third-party sub-processors that Company Asset Tracker uses to deliver the asset-tracking service. We publish this list so customer administrators can verify our supply chain and exercise their rights under GDPR Article 28.

Each sub-processor signs a data processing agreement with us before any data flows. We audit the list quarterly and update this page whenever a vendor is added or removed.

Current sub-processors

VendorFunctionData sharedRegion
Amazon Web ServicesApplication compute & database hostingAll workspace data, encrypted at restus-east-1 (primary), eu-west-1 (EU tenants)
PostmarkTransactional email deliveryRecipient name + email, message bodyUnited States
StripePayment processingCard billing details (we never see the card number)United States, EU
SentryError monitoring & crash reportsStack traces, scrubbed of PII before transmissionUnited States
CloudflareDNS, CDN, edge cacheHTTP request metadata (IP, user agent, headers)Global edge network

Identity providers (SSO)

When you sign in via SSO, the matching identity provider receives only the data needed to verify your sign-in — never your asset data:

  • Google Workspace — email + profile (when SSO is configured with Google)
  • Microsoft Entra ID — email + tenant ID (when SSO is configured with Microsoft)

Region selection

Customer administrators can choose to host their workspace in the United States (us-east-1) or the European Union (eu-west-1). Region is selected at signup and locked thereafter — moving workspaces across regions requires a formal export/re-import handoff coordinated with our support team.

Changes to this list

We give customer administrators at least 30 days' notice via email before adding a new sub-processor. Objections can be sent to privacy@companyassettracker.com; we will work with you to find an alternative if a particular sub-processor is incompatible with your compliance posture.