Who processes data for us, what they receive and where.
Last updated: 2026-09-27
A sub-processor is a company we use to run Proposal Expert that processes personal data of our customers and their clients. This page is the complete list, and we keep it up to date. Our security page and our privacy policy both refer to it.
How AI features use your content
AI features such as AI Write, AI drafts, scoring and analysis send the text they work on to Google's Gemini API. That text can contain personal data from your proposal, such as client names and contact details. Nothing is sent until someone uses an AI feature. Google processes the text as our sub-processor. We do not use your content to train AI models. If your workspace uses its own AI key, AI writing goes to the provider you chose. Scoring and chat translation still use Gemini.
Sub-processors we use
These companies process personal data on our behalf to run the service.
Railway
Hosting of the application, the background jobs and the database.
Data: Everything stored in the service: accounts, proposals including client names and contact details, and logs
Location: EU (Amsterdam, Netherlands)
Transfer safeguard: Standard Contractual Clauses
When: Always
Cloudflare
Content delivery, DDoS protection and web firewall in front of the site, and storage of our off-site database backups. We encrypt the backups before upload, so Cloudflare cannot read them.
Data: IP addresses and request data of every visit, in transit. Encrypted database backups
Location: Global network
Transfer safeguard: EU-US Data Privacy Framework and Standard Contractual Clauses
When: Always
Resend
Sending e-mail: sign-in codes, shared proposals, signing requests and notifications.
Data: Name and e-mail address of the recipient, and the content of the e-mail
Location: United States
Transfer safeguard: Standard Contractual Clauses
When: Always
Google (Gemini API)
AI features: writing, drafts, scoring, analysis and translation of support chat messages.
Data: The text sent to an AI feature, which can include client names and contact details
Location: EU or United States, as Google's terms allow
Transfer safeguard: EU-US Data Privacy Framework and Standard Contractual Clauses
When: Only when someone uses an AI feature
Stripe
Subscription billing and invoices. Card details go straight to Stripe and never reach our servers.
Data: Name, e-mail address, workspace and plan
Location: EU and United States
Transfer safeguard: EU-US Data Privacy Framework and Standard Contractual Clauses
When: Only for paid subscriptions
Slack
Security and operations alerts to our own team.
Data: E-mail addresses and IP addresses in security alerts
Location: United States
Transfer safeguard: EU-US Data Privacy Framework and Standard Contractual Clauses
When: Always
Other services with limited data
These services receive only an IP address or a company address, usually because a browser loads a font, map or video from them directly.
Google Ads
Measuring sign-ups that come from our ads.
Data: IP address and page visit. Without your consent the tag runs without cookies.
Location: Global network
Transfer safeguard: EU-US Data Privacy Framework and Standard Contractual Clauses
When: Public website only, never on shared proposals
OpenStreetMap (Nominatim)
Turning company addresses into map coordinates.
Data: Company addresses
Location: See the provider's terms
Transfer safeguard: See the provider's terms
When: Only when a map or address search is used
CARTO
Map tiles on map views.
Data: IP address of the browser
Location: See the provider's terms
Transfer safeguard: See the provider's terms
When: Only when a map or address search is used
YouTube, Vimeo, Loom
Videos embedded in a proposal. YouTube loads in privacy-enhanced mode and Vimeo with do-not-track.
Data: IP address of the browser
Location: See the provider's terms
Transfer safeguard: See the provider's terms
When: Only when a proposal contains such a video
Giphy
An animated image in some onboarding e-mails, loaded by the mail program.
Data: IP address of the browser
Location: United States
Transfer safeguard: See the provider's terms
When: Always
Integrations you enable
These services receive data only after a workspace admin connects them. Your workspace chooses them and decides what is shared. Your own agreement with the provider applies.
For completeness, these are the other services the platform talks to. None of them receives personal data.
Google Fonts: Fonts in the editor, in brand kits and in shared proposals. Our server fetches them from Google and serves them from our own domain. Your browser and your recipients' browsers never contact Google.
FreeTSA (freetsa.org): Trusted timestamps (RFC 3161) for signatures and the audit log. Only a SHA-256 hash is sent, never the document.
timeapi.io: A backup clock for signatures when the timestamp service does not answer.
Have I Been Pwned: Checking whether a new password appears in known data breaches. Only the first five characters of a hash of the password are sent.
FingerprintJS (open source): A library that runs in the browser to stop abuse of free accounts. Nothing is sent to FingerprintJS. We store only a hash of the result.
Unsplash, Pexels: Stock photo search. Our server sends only the search term.
Web Push: Delivering push notifications you subscribed to. The content is end-to-end encrypted.
Frankfurter: Currency exchange rates of the European Central Bank.
FireHOL, Tor Project, IPsum: Lists of malicious IP addresses that we download. Nothing is sent.
Changes to this list
We update this page before a new sub-processor starts processing personal data. Customers with a signed data processing agreement are told by e-mail in advance and can object.
Data processing agreement
Do you use Proposal Expert for personal data of your clients? A data processing agreement (DPA) under Article 28 GDPR is available on request. We send it to you to review and sign. It refers to this list of sub-processors.