Service providers we use

As of 09/13/2026

We use the following service providers to operate our platform. This overview supplements our privacy policy and is updated whenever a provider changes.

This list also forms Annex 3 to the data processing agreement (fleetfeat.de/avv). We give our customers at least 14 calendar days' notice in text form before we engage or replace any provider listed here (§ 6 (2) of the agreement). If one of these providers replaces a sub-processor of its own, we inform our customers without undue delay once we become aware of it; the right to object remains in place in both cases (§ 6 (3) and (4)). Questions to datenschutz@fleetfeat.de.

A note on the Stripe chain: for our customers' data we are a processor ourselves. Section 8.2 of the Stripe Data Transfers Addendum therefore brings Module 3 of the standard contractual clauses into play, and we meet the obligations Stripe owes to controllers under it in Stripe's place. That is why we answer questions about the Stripe chain ourselves instead of passing them on.

Annex 3 — sub-processors

Vercel, Inc.

Purpose:
Hosting, operation of the application, AI language model connection via the Vercel AI Gateway
Role:
Processor (Art. 28 GDPR) for customer data and controller in its own right for service and contact data (Vercel DPA sec. 4.b)
Registered office:
USA
Data location:
The application runs in the EU (Frankfurt region, fra1) — evidenced on 8 September 2026 against the live production deployment in the Vercel account. Static content is served from the global edge network; operational and log data are held primarily in the USA (DPA sec. 13.1).
Third-country transfer:
Yes
Safeguard:
EU-US Data Privacy Framework (Vercel Inc. participates, status active according to dataprivacyframework.gov, checked on 13 September 2026); in addition, the EU standard contractual clauses (implementing decision 2021/914) apply, Module 2 for customer data and Module 1 for service data; governed by Irish law.
As of:
09/13/2026

Supabase Pte. Ltd.

Purpose:
Database and file storage (EU region)
Role:
Processor (Art. 28 GDPR)
Registered office:
Singapore
Data location:
EU (Frankfurt, eu-central-1 region) — contractually assured where that region is selected (DPA sec. 6.1); the project region was checked for production and development on 21 July 2026. The data importer remains the Singapore entity (DPA Schedule 2 sec. 1.7(c)).
Third-country transfer:
Yes
Safeguard:
EU standard contractual clauses (implementing decision 2021/914), Module 2 (DPA Schedule 2); Irish law, Irish courts.
As of:
09/08/2026

Stripe Payments Europe, Limited

Purpose:
Payment processing (prepared, not currently in use)
Role:
Processor (Art. 28 GDPR) and controller in its own right for fraud detection, anti-money-laundering and identity checks, billing and improving its own services (Stripe DPA sec. 2)
Registered office:
Ireland
Data location:
EU — the contracting entity is the Irish company; onward transfer to Stripe, LLC in the USA.
Third-country transfer:
Yes
Safeguard:
EU-US Data Privacy Framework: Stripe, LLC is self-certified, and section 2 of the Data Transfers Addendum gives that mechanism precedence. As a fallback, the EEA standard contractual clauses (implementing decision 2021/914) apply in Modules 1, 2 and 3 (section 4 of the addendum); they take over as soon as the certification lapses.
As of:
09/08/2026

Plus Five Five, Inc. (Resend)

Purpose:
Email delivery (via Amazon SES)
Role:
Processor (Art. 28 GDPR)
Registered office:
USA
Data location:
USA. Delivery runs through Amazon SES in the EU (Ireland, eu-west-1 region), measured on the bounce path in DNS on 7 September 2026. The provider itself gives no assurance of an EU data location.
Third-country transfer:
Yes
Safeguard:
EU-US Data Privacy Framework (Plus Five Five, Inc. participates, status active according to dataprivacyframework.gov, checked on 13 September 2026); in addition, the EU standard contractual clauses (implementing decision 2021/914) apply, Module 2 (DPA sec. 6.2.2); under sec. 6.3.9 they are deemed signed upon acceptance of the terms of service.
As of:
09/13/2026

Functional Software, Inc. (Sentry)

Purpose:
Error logs
Role:
Processor (Art. 28 GDPR)
Registered office:
USA
Data location:
EU (Frankfurt) — the account setting “Data Storage Region: European Union” was evidenced on 7 September 2026; the application reports errors to the EU endpoint ingest.de.sentry.io.
Third-country transfer:
In theory, for support access
Safeguard:
EU standard contractual clauses (implementing decision 2021/914), Module 2 (DPA Schedule 3 sec. 2.1); in addition, the provider is certified under the EU-US Data Privacy Framework.
As of:
09/07/2026

Google Cloud EMEA Limited

Purpose:
Internal communication
Role:
Processor (Art. 28 GDPR)
Registered office:
Ireland
Data location:
Under review (as of 09/08/2026)
Third-country transfer:
Yes
Safeguard:
EU standard contractual clauses (implementing decision 2021/914), Module 2 — incorporated through the Cloud Data Processing Addendum (version of 8 June 2026).
As of:
09/07/2026

Cloudflare, Inc.

Purpose:
Off-site backup of files and database (stored in the EU)
Role:
Processor (Art. 28 GDPR)
Registered office:
USA
Data location:
EU — the backup storage is restricted to the EU jurisdiction (set up and verified on 16 August 2026); the access endpoint carries the corresponding EU identifier.
Third-country transfer:
Yes
Safeguard:
EU-US Data Privacy Framework (Cloudflare, Inc. participates, status active according to dataprivacyframework.gov, checked on 13 September 2026; DPA version 6.4, sec. 6.4); in addition, the EU standard contractual clauses (implementing decision 2021/914) apply, Module 2 (DPA version 6.4, sec. 6.2(a)(i)).
As of:
09/13/2026

Google Cloud EMEA Limited

Purpose:
Maps and conversion of addresses into coordinates
Role:
Controller in its own right — not a processor (Google Controller-Controller Data Protection Terms, sec. 4.1)
Registered office:
Ireland
Data location:
No assurance is given to us: Google processes as a controller in its own right on its own, worldwide infrastructure. The contracting entity is the Irish company.
Third-country transfer:
Yes
Safeguard:
No safeguard under Art. 46 GDPR is provided by fleetfeat because this is not processing on our behalf: the recipient is the Irish company within the EEA, and Google is responsible for the onward processing (Controller-Controller Data Protection Terms, sec. 4.1 and 5.3). Google's own privacy policy applies to it.
As of:
09/03/2026

Sub-processors used by our providers

The following providers do not work for fleetfeat but for the service providers listed above. We name them because they touch personal data; the authoritative source for the full chain is the sub-processor list published by each provider.

Which data we process for which purpose, and on what legal basis, is set out in our privacy policy.

Changes