Sub-processors
Effective 30 July 2026
Nelkins Technologies uses the third parties below to operate Broker OS. Each processes data only for the stated service purpose and under applicable contractual and security controls. Provider access is limited to permissions the user or administrator has authorised.
| Sub-processor | Purpose | Data handled |
|---|---|---|
| Vercel | Application hosting and delivery | Request metadata, application traffic and operational logs |
| Managed PostgreSQL database host | Primary application data storage | Tenant operational data and encrypted credentials |
| Google OAuth, Gmail sending and authorised read-only mailbox access | Connected identity, OAuth grants, messages sent by the user, authorised message metadata and bounded previews | |
| Microsoft | Microsoft identity, Graph email sending and delegated mailbox synchronisation | Connected identity, OAuth grants, messages sent by the user, authorised message metadata and bounded previews |
| Stripe | Subscription billing | Billing contact, customer and subscription identifiers; card details remain with Stripe |
| Sentry | Error monitoring | Error events and diagnostic metadata configured to minimise personal data |
| WhatsApp Business or configured messaging provider | Outbound messaging the user triggers | Recipient, message content and delivery metadata |
| Configured email delivery provider | Transactional and operational email | Recipient address, message content and delivery metadata |
| Approved AI inference provider(s) | User-facing drafting and Nelkins Intelligence features | Tenant-scoped prompt context required for the requested result; not authorised for shared-model training |
We will give notice of material changes to this list. Questions or DPA requests can be sent to privacy@nelkins-os.xyz.