Data protection
Subprocessor register
Providers that may process limited data, separated by current core use and explicit feature activation.
Last updated 14 August 2026How this register works
A provider receives only the data needed for the purpose and activation state described below. A listed optional provider does not receive customer content merely because it appears in this register. Provider legal entities and service regions may depend on the customer, contracting account, or provider terms.
Current core providers
Cloudflare, Inc.
Core service- Purpose
- Application delivery, R2 object storage, network security, DNS, and the Citeply-operated ClamAV scanning boundary
- Data categories
- Technical request and security data, uploaded customer objects, and document bytes transiently processed during scanning
- Processing location
- Configured and global Cloudflare service regions
Neon, LLC and applicable affiliates
Core service- Purpose
- Managed PostgreSQL for structured application data
- Data categories
- Account, workspace, questionnaire, evidence, audit, billing lifecycle, support, and security records
- Processing location
- Configured AWS Europe (Frankfurt) project region; provider support and infrastructure locations may also apply
Resend, Inc.
Email-enabled flows- Purpose
- Transactional email, invitation delivery, account messages, and metadata-only operational alerts
- Data categories
- Recipient email, workspace name, invitation or account link, operational event identifiers, and delivery metadata
- Processing location
- United States and documented provider service regions
Paddle.com Market Limited, Paddle.com Inc., or the applicable Paddle affiliate
Direct purchases- Purpose
- Authorized reseller and merchant-of-record checkout, tax, invoices or receipts, renewals, cancellations, fraud controls, refunds, and seller payouts
- Data categories
- Buyer identity, billing, transaction, tax, fraud, and subscription data
- Processing location
- Contracting entity and service regions determined by the buyer location
Conditional providers
Microsoft Corporation and affiliates
Only when an authorized administrator or user enables the relevant Microsoft capability- Purpose
- Microsoft Graph file or mail access, Excel add-in identity, and optional Azure Document Intelligence OCR
- Data categories
- Microsoft identity and tenant identifiers; user-selected files; configured mailbox attachments; document bytes only when optional OCR is enabled
- Processing location
- Customer Microsoft tenant region and documented Microsoft service regions
Changes and objections
Citeply will update this register before a material new subprocessor begins processing customer content. Where a signed DPA specifies advance notice, Citeply will use the registered business contact and apply the notice and objection period in that DPA. An objection must identify a reasonable data-protection concern; the parties will work in good faith on a commercially reasonable mitigation or alternative.
International transfers
Cross-border processing uses the transfer mechanism applicable to the parties and data, including an adequacy decision, standard contractual clauses, UK addendum, Turkish standard contract, or another legally recognized safeguard. Customers may request the applicable mechanism through the privacy contact.
Related documents
See the DPA, Privacy Notice, KVKK Notice, and Trust Center.