Citeply
PricingPrivacyKVKKRefundsDPAVendorsTermsLegal noticeTrustStatusSupport

Data protection

Subprocessor register

Providers that may process limited data, separated by current core use and explicit feature activation.

Last updated 14 August 2026

How this register works

A provider receives only the data needed for the purpose and activation state described below. A listed optional provider does not receive customer content merely because it appears in this register. Provider legal entities and service regions may depend on the customer, contracting account, or provider terms.

Current core providers

Cloudflare, Inc.

Core service
Purpose
Application delivery, R2 object storage, network security, DNS, and the Citeply-operated ClamAV scanning boundary
Data categories
Technical request and security data, uploaded customer objects, and document bytes transiently processed during scanning
Processing location
Configured and global Cloudflare service regions

Neon, LLC and applicable affiliates

Core service
Purpose
Managed PostgreSQL for structured application data
Data categories
Account, workspace, questionnaire, evidence, audit, billing lifecycle, support, and security records
Processing location
Configured AWS Europe (Frankfurt) project region; provider support and infrastructure locations may also apply

Resend, Inc.

Email-enabled flows
Purpose
Transactional email, invitation delivery, account messages, and metadata-only operational alerts
Data categories
Recipient email, workspace name, invitation or account link, operational event identifiers, and delivery metadata
Processing location
United States and documented provider service regions

Paddle.com Market Limited, Paddle.com Inc., or the applicable Paddle affiliate

Direct purchases
Purpose
Authorized reseller and merchant-of-record checkout, tax, invoices or receipts, renewals, cancellations, fraud controls, refunds, and seller payouts
Data categories
Buyer identity, billing, transaction, tax, fraud, and subscription data
Processing location
Contracting entity and service regions determined by the buyer location

Conditional providers

Microsoft Corporation and affiliates

Only when an authorized administrator or user enables the relevant Microsoft capability
Purpose
Microsoft Graph file or mail access, Excel add-in identity, and optional Azure Document Intelligence OCR
Data categories
Microsoft identity and tenant identifiers; user-selected files; configured mailbox attachments; document bytes only when optional OCR is enabled
Processing location
Customer Microsoft tenant region and documented Microsoft service regions

Changes and objections

Citeply will update this register before a material new subprocessor begins processing customer content. Where a signed DPA specifies advance notice, Citeply will use the registered business contact and apply the notice and objection period in that DPA. An objection must identify a reasonable data-protection concern; the parties will work in good faith on a commercially reasonable mitigation or alternative.

International transfers

Cross-border processing uses the transfer mechanism applicable to the parties and data, including an adequacy decision, standard contractual clauses, UK addendum, Turkish standard contract, or another legally recognized safeguard. Customers may request the applicable mechanism through the privacy contact.

Related documents

See the DPA, Privacy Notice, KVKK Notice, and Trust Center.

© 2026 Citeply · Operated by Engin MutluEvidence-backed answers. Human-approved claims.