Sub-processors
The third parties that process customer data on our behalf, what each one does, and where it does it. This page is the list referred to in our data processing agreement.
Last updated 24 September 2026
Current sub-processors
Each of these processes personal data contained in the email you send, or in the records of that email, so that we can run the service. Nothing else has access to customer data.
| Name | Purpose | Location |
|---|---|---|
| Amazon Web Services | Amazon SES: sending email and receiving delivery, bounce and complaint events | eu-north-1, Sweden |
| Amazon Web Services | Amazon S3: message body storage, only on deployments where S3 storage is enabled | eu-north-1, Sweden |
| Stripe Payments Europe, Limited | Payment processing for paid plans: card details entered on our billing page, billing name and address, invoices and receipts | Ireland, with card data processed in the EU and the United States under Stripe's own transfer safeguards |
| Hosting provider (named here once the production box is chosen) | Hosting for the API, worker and dashboard | EU |
Card numbers never reach us: the payment processor's fields sit inside our billing page and the number is sent to the processor directly. What we hold of a card is its brand, last four digits and expiry.
Not in use yet
Planned but not connected to the service today, and processing no customer data at present. We will give notice before it starts, and move it into the table above.
- Cloudflare: CDN and DDoS protection for the public site and API. Not in use, and processing no data.
Notice of changes
We give at least 30 days' notice before adding or replacing a sub-processor. Notice goes by email to account holders, and this page is updated with the date at the top.
To be told about changes, or to object to one on data protection grounds, write to privacy@staging.avelto.dev. The right to object, and what happens if we cannot resolve an objection, are set out in our data processing agreement.