Service providers we use
As of 09/13/2026
We use the following service providers to operate our platform. This overview supplements our privacy policy and is updated whenever a provider changes.
This list also forms Annex 3 to the data processing agreement (fleetfeat.de/avv). We give our customers at least 14 calendar days' notice in text form before we engage or replace any provider listed here (§ 6 (2) of the agreement). If one of these providers replaces a sub-processor of its own, we inform our customers without undue delay once we become aware of it; the right to object remains in place in both cases (§ 6 (3) and (4)). Questions to datenschutz@fleetfeat.de.
A note on the Stripe chain: for our customers' data we are a processor ourselves. Section 8.2 of the Stripe Data Transfers Addendum therefore brings Module 3 of the standard contractual clauses into play, and we meet the obligations Stripe owes to controllers under it in Stripe's place. That is why we answer questions about the Stripe chain ourselves instead of passing them on.
Annex 3 — sub-processors
Vercel, Inc.
- Purpose:
- Hosting, operation of the application, AI language model connection via the Vercel AI Gateway
- Role:
- Processor (Art. 28 GDPR) for customer data and controller in its own right for service and contact data (Vercel DPA sec. 4.b)
- Registered office:
- USA
- Data location:
- The application runs in the EU (Frankfurt region, fra1) — evidenced on 8 September 2026 against the live production deployment in the Vercel account. Static content is served from the global edge network; operational and log data are held primarily in the USA (DPA sec. 13.1).
- Third-country transfer:
- Yes
- Safeguard:
- EU-US Data Privacy Framework (Vercel Inc. participates, status active according to dataprivacyframework.gov, checked on 13 September 2026); in addition, the EU standard contractual clauses (implementing decision 2021/914) apply, Module 2 for customer data and Module 1 for service data; governed by Irish law.
- Evidence:
- As of:
- 09/13/2026
Supabase Pte. Ltd.
- Purpose:
- Database and file storage (EU region)
- Role:
- Processor (Art. 28 GDPR)
- Registered office:
- Singapore
- Data location:
- EU (Frankfurt, eu-central-1 region) — contractually assured where that region is selected (DPA sec. 6.1); the project region was checked for production and development on 21 July 2026. The data importer remains the Singapore entity (DPA Schedule 2 sec. 1.7(c)).
- Third-country transfer:
- Yes
- Safeguard:
- EU standard contractual clauses (implementing decision 2021/914), Module 2 (DPA Schedule 2); Irish law, Irish courts.
- Evidence:
- As of:
- 09/08/2026
Stripe Payments Europe, Limited
- Purpose:
- Payment processing (prepared, not currently in use)
- Role:
- Processor (Art. 28 GDPR) and controller in its own right for fraud detection, anti-money-laundering and identity checks, billing and improving its own services (Stripe DPA sec. 2)
- Registered office:
- Ireland
- Data location:
- EU — the contracting entity is the Irish company; onward transfer to Stripe, LLC in the USA.
- Third-country transfer:
- Yes
- Safeguard:
- EU-US Data Privacy Framework: Stripe, LLC is self-certified, and section 2 of the Data Transfers Addendum gives that mechanism precedence. As a fallback, the EEA standard contractual clauses (implementing decision 2021/914) apply in Modules 1, 2 and 3 (section 4 of the addendum); they take over as soon as the certification lapses.
- As of:
- 09/08/2026
Plus Five Five, Inc. (Resend)
- Purpose:
- Email delivery (via Amazon SES)
- Role:
- Processor (Art. 28 GDPR)
- Registered office:
- USA
- Data location:
- USA. Delivery runs through Amazon SES in the EU (Ireland, eu-west-1 region), measured on the bounce path in DNS on 7 September 2026. The provider itself gives no assurance of an EU data location.
- Third-country transfer:
- Yes
- Safeguard:
- EU-US Data Privacy Framework (Plus Five Five, Inc. participates, status active according to dataprivacyframework.gov, checked on 13 September 2026); in addition, the EU standard contractual clauses (implementing decision 2021/914) apply, Module 2 (DPA sec. 6.2.2); under sec. 6.3.9 they are deemed signed upon acceptance of the terms of service.
- Evidence:
- As of:
- 09/13/2026
Functional Software, Inc. (Sentry)
- Purpose:
- Error logs
- Role:
- Processor (Art. 28 GDPR)
- Registered office:
- USA
- Data location:
- EU (Frankfurt) — the account setting “Data Storage Region: European Union” was evidenced on 7 September 2026; the application reports errors to the EU endpoint ingest.de.sentry.io.
- Third-country transfer:
- In theory, for support access
- Safeguard:
- EU standard contractual clauses (implementing decision 2021/914), Module 2 (DPA Schedule 3 sec. 2.1); in addition, the provider is certified under the EU-US Data Privacy Framework.
- Evidence:
- As of:
- 09/07/2026
Google Cloud EMEA Limited
- Purpose:
- Internal communication
- Role:
- Processor (Art. 28 GDPR)
- Registered office:
- Ireland
- Data location:
- Under review (as of 09/08/2026)
- Third-country transfer:
- Yes
- Safeguard:
- EU standard contractual clauses (implementing decision 2021/914), Module 2 — incorporated through the Cloud Data Processing Addendum (version of 8 June 2026).
- As of:
- 09/07/2026
Cloudflare, Inc.
- Purpose:
- Off-site backup of files and database (stored in the EU)
- Role:
- Processor (Art. 28 GDPR)
- Registered office:
- USA
- Data location:
- EU — the backup storage is restricted to the EU jurisdiction (set up and verified on 16 August 2026); the access endpoint carries the corresponding EU identifier.
- Third-country transfer:
- Yes
- Safeguard:
- EU-US Data Privacy Framework (Cloudflare, Inc. participates, status active according to dataprivacyframework.gov, checked on 13 September 2026; DPA version 6.4, sec. 6.4); in addition, the EU standard contractual clauses (implementing decision 2021/914) apply, Module 2 (DPA version 6.4, sec. 6.2(a)(i)).
- As of:
- 09/13/2026
Google Cloud EMEA Limited
- Purpose:
- Maps and conversion of addresses into coordinates
- Role:
- Controller in its own right — not a processor (Google Controller-Controller Data Protection Terms, sec. 4.1)
- Registered office:
- Ireland
- Data location:
- No assurance is given to us: Google processes as a controller in its own right on its own, worldwide infrastructure. The contracting entity is the Irish company.
- Third-country transfer:
- Yes
- Safeguard:
- No safeguard under Art. 46 GDPR is provided by fleetfeat because this is not processing on our behalf: the recipient is the Irish company within the EEA, and Google is responsible for the onward processing (Controller-Controller Data Protection Terms, sec. 4.1 and 5.3). Google's own privacy policy applies to it.
- As of:
- 09/03/2026
Sub-processors used by our providers
The following providers do not work for fleetfeat but for the service providers listed above. We name them because they touch personal data; the authoritative source for the full chain is the sub-processor list published by each provider.
- We reach the AI language model providers — currently Google and Anthropic — through the Vercel AI Gateway. Processing is configured for inference in the European Union and for zero data retention; using the input to train the models is contractually prohibited. Verified against Vercel's sub-processor list. (verified on 08/21/2026)
- Resend sends via Amazon SES in the Ireland region (eu-west-1). Measured on the bounce path in DNS; Resend's published sub-processor list remains authoritative. (verified on 09/07/2026)
Which data we process for which purpose, and on what legal basis, is set out in our privacy policy.
Changes
- 09/13/2026 — Cloudflare: safeguard clarified — the EU-US Data Privacy Framework is now given as the primary safeguard, with standard contractual clauses in addition. Reason: DPF certification evidenced, source dataprivacyframework.gov.
- 09/13/2026 — Vercel: safeguard clarified — the EU-US Data Privacy Framework is now given as the primary safeguard, with standard contractual clauses in addition. Reason: DPF certification evidenced, source dataprivacyframework.gov.
- 09/13/2026 — Resend: safeguard clarified — the EU-US Data Privacy Framework is now given as the primary safeguard, with standard contractual clauses in addition. Reason: DPF certification evidenced, source dataprivacyframework.gov.
- 09/08/2026 — Added the “Role” column; Stripe and Vercel are now shown as controllers in their own right for part of the processing. Added data location, third-country transfer and safeguard for Vercel, Supabase and Stripe. Safeguard for Stripe: EU-US Data Privacy Framework, with standard contractual clauses as a fallback. Corrected the Stripe contracting entity: Stripe Payments Europe, Limited (Dublin) instead of Stripe, LLC. Annex 3 to the data processing agreement raised to version 1.1.
- 09/07/2026 — List declared Annex 3 to the data processing agreement; no change to the providers.
- 09/03/2026 — Cloudflare, Inc. (off-site backup) and Google Cloud EMEA Limited (maps/geocoding) added.
- 08/25/2026 — First version with six providers.