A subprocessor is a third party we engage to process personal data on behalf of our customers. This page lists them, what each one does, and where each processes data. It forms Annex III of our Data Processing Addendum and is incorporated into it.
Every subprocessor is subject to due diligence before engagement and to a written agreement imposing data protection obligations no less protective than those we owe our customers. We remain fully liable to you for their performance.
Why there are two tables. Only the vendors in Section 2 can access the contents of your workspace. Section 3 lists vendors that handle information where we are the controller — sales enquiries, billing contacts, support correspondence — and which never receive your workspace content. We keep these separate so you can see exactly which companies could reach your team's data, rather than having to infer that from a single undifferentiated list.
These vendors process personal data on behalf of our customers. The first two host or transmit the contents of your workspace — messages, projects, tasks, SOPs, time records, leave records, files, and member profiles. The rest receive far less, and the Data processed column states exactly what each one receives.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase Pte. Ltd. Singapore |
Primary database, file and attachment storage, authentication, realtime updates, and delivery of sign-in codes | All Customer Data at rest, including all workspace content and member profiles | United States (West US, Oregon) |
| Vercel Inc. United States |
Application hosting, content delivery, runtime and error logging | All Customer Data in transit; log data including IP addresses, account identifiers, and request URLs | United States |
| Resend (Plus Five Five, Inc.) United States |
Transactional and notification email — invitations, assignment notices, reminders, and time off notifications | Recipient name and email address, and the notification content. That content can include an excerpt of a chat message, a task or channel name, and the details of a time off request including any reason given for a decision | United States |
| PostHog, Inc. United States |
Product usage analytics inside the Aiome application, so we can determine which features are used and where people encounter difficulty, and error tracking, so we learn about faults without waiting for someone to report one | A pseudonymous internal user identifier, the workspace identifier, the names of actions taken, event properties limited to true/false flags, counts and fixed categories, and standard device and browser information. For errors, the technical details of the fault and where in the application it happened. It never receives names, email addresses, chat message text, task, project or SOP titles or contents, leave notes, timesheet notes, or uploaded files. There is no screen recording and no automatic capture of the text people click. An error report can incidentally contain a record or workspace identifier that appeared in a web address |
United States (Virginia) |
| Cloudflare, Inc. United States |
Bot protection (Turnstile) on the sign-in page — determining whether a sign-in attempt comes from a person or an automated script, before any sign-in code is sent | IP address and standard browser and device characteristics of whoever opens the sign-in page, and the pass-or-fail outcome of the check. It never receives workspace content, names, or email addresses | Global (nearest Cloudflare location) |
| Upstash, Inc. United States |
Rate limiting — short-lived counters that cap how often each network address or account can call sensitive routes such as sign-in, so they cannot be flooded or abused | IP addresses, the email address a sign-in code was requested for, and internal account identifiers, each held only as a counter that expires within an hour. It never receives workspace content | United States (AWS us-east-2, Ohio) |
These vendors support our own business — marketing, sales, and support. None of them receives the contents of a customer workspace, except to the extent a person voluntarily includes such content in a message they send us.
| Vendor | Purpose | Data processed | Location |
|---|---|---|---|
| HighLevel Inc. (GoHighLevel) United States |
Marketing website hosting, DNS, CRM, contact form submissions, marketing email and SMS, support conversations inbox, and visitor statistics for aiome.io | Name, work email, company, team size, message content, and marketing preferences of website visitors and enquirers. For visitor statistics, counts of page views, separate visitors, and form submissions for each page of aiome.io, together with the technical information a web server ordinarily receives | United States |
| Featurebase (CORDNET OÜ) Estonia |
Support articles, feedback collection, and feature requests | Name, email address, and the content of feedback or support requests submitted by users | 🇪🇺 Netherlands, Germany, Ireland |
| Zoho Corporation (Zoho Workplace) United States |
Our business email — the mailbox in which support and sales correspondence is received and stored | The contents of email correspondence with us, including sender name and address | United States |
One service that receives no personal data. To show public holidays in the time off calendar, Aiome asks a public holiday reference service (Nager.Date) which dates are holidays in a given country and year. It receives a country and a year, and nothing about you or your team. It is named here for completeness rather than as a subprocessor.
| Provider | Role | Data processed | Location |
|---|---|---|---|
| Paddle.com Inc. (United States) for buyers in the United States, and Paddle.com Market Ltd (United Kingdom) for buyers elsewhere | Merchant and seller of record — an independent controller, not our subprocessor | Payment card details, billing name and address, tax status, transaction records. Aiome never receives or stores full card numbers. | Global |
Because Paddle acts as the seller of record for your purchase, your purchase contract is with Paddle rather than with Aiome. Paddle determines the purposes and means of processing your payment data and does so under its own privacy notice, and it is responsible for calculating and remitting sales tax and VAT. It is listed here for transparency rather than as a subprocessor, and the subprocessor change procedure in Section 6 does not apply to it. See our Refunds page for how this affects cancellations and refunds.
None currently engaged. As of the date of this page, Aiome does not send Customer Data to any AI or large language model provider, and no AI provider processes the contents of your workspace.
If we introduce a feature that uses a third-party AI model to process Customer Data, that provider will be added to the table in Section 2 and you will receive at least 30 days' notice before the processing begins, with the right to object under Section 6.
When that happens, we commit to engaging only providers whose terms prohibit training on our customers' data, and to giving workspace administrators a control governing whether these features operate on their workspace. See Section 6 of our Privacy Policy.
Before engaging a new subprocessor to process Customer Data, we will give at least 30 days' notice by:
If you would like the notice sent to additional people — a security or procurement contact, for example — tell us at aiome.io/contact and we will add them.
Your right to object. You may object to a new subprocessor on reasonable data protection grounds within 30 days of notice. We will discuss it in good faith, and if it cannot be resolved you may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the unused period. See Section 8 of the DPA.
Where we must replace a subprocessor urgently to maintain the security or continuity of the Service, we will give notice as soon as reasonably practicable.
We record every change here so you can see what changed and when.
| Date | Change |
|---|---|
| August 9, 2026 | Added Cloudflare, Inc. (bot protection on the sign-in page) and Upstash, Inc. (rate limiting), on the day those protections went live. Added before launch, while no customer workspaces existed, so the 30-day notice period in Section 6 did not yet apply to anyone. |
| August 9, 2026 | Initial publication. |
Related documents: Data Processing Addendum · Privacy Policy · Security · Terms of Service