Sub-processors
The companies below process Customer Data on v3ndor.io's behalf when we engage them to support specific platform features. Each is bound by a written agreement with confidentiality, security, and data- protection obligations no less protective than those in the Terms of Service and our Data Processing Agreement (GDPR Art. 28(3)).
Infrastructure & platform
| Sub-processor | Purpose | Region | Engaged since |
|---|---|---|---|
| Microsoft Azure (Microsoft Corporation) | Compute (Container Apps), database (PostgreSQL Flexible Server), storage (Blob), secrets (Key Vault), monitoring (Log Analytics) | East US 2 — no secondary DR region in production yet | [YYYY-MM-DD] |
| Microsoft Entra ID | Identity, authentication (OIDC), MFA | Microsoft Online Services | [YYYY-MM-DD] |
| Azure Communication Services (Microsoft Corporation) | Transactional email delivery (alerts, digests, support replies) | United States — ACS is a global service; message bodies are stored at rest in the United States | [YYYY-MM-DD] |
Operations & support
None. We engage no third-party sub-processor for customer support, error tracking, or service-status communication. In-app help and ticket triage run inside the v3ndor.io platform itself, and production error visibility is handled by Azure Monitor / Log Analytics under the Microsoft Azure entry above. Any future addition is subject to the 30-day notice below.
Third-party services contacted at runtime
These are not sub-processors in the Art. 28 sense — they receive no personal data and store nothing on our behalf — but they are external services our platform calls while serving your workspace, so we disclose them here rather than leave a security questionnaire to discover them.
| Service | What we send | Why | How to switch it off |
|---|---|---|---|
Brandfetch (cdn.brandfetch.io) |
The domain name of a vendor in your inventory. No customer identifiers, no user data, no request context. | Fetches that vendor’s logo so your vendor list is scannable. Results are cached by us, so a given domain is looked up once. |
Set V3NDOR_STRICT_SELF_HOST=true (or
V3NDOR_ALLOW_LOGO_UPSTREAM=false) on your tenant and
no logo lookup leaves our infrastructure — vendors fall back
to initials. Ask us to enable it during onboarding if you have a
data-locality or no-egress requirement.
|
Google favicon service (t1.gstatic.com, www.google.com/s2/favicons) |
The same vendor domain name, only if Brandfetch has no logo for it. | Fallback logo lookup. |
A vendor’s domain name is generally not personal data, but it does reveal that the domain is of interest to someone. If your vendor list is itself confidential, switch the lookup off as above.
Marketing website & analytics
The marketing website (v3ndor.io) and the platform are intentionally separate:
- The platform — what you log into — uses no third-party analytics or trackers. See Cookie Policy.
- The marketing website currently runs no analytics sub-processor. Its Content-Security-Policy admits no third-party script or asset host, and
connect-srcallows only our own origin plus the Google and Microsoft identity endpoints used for sign-in. Any analytics sub-processor added later is listed here before it goes live.
Notification of changes
We will notify Customer admins by email and update this page at least 30 days before adding a new sub-processor or replacing an existing one. Customers may object during the notice period; if we cannot resolve the objection commercially, the customer may terminate the affected service for convenience and receive a pro-rated refund of prepaid fees.
To be added to the sub-processor change-notification list, email dpa@v3ndor.io with the subject Subscribe sub-processor notices.
Verification
Each sub-processor's compliance posture is reviewed at onboarding and annually thereafter, with attention to: their SOC 2 / ISO 27001 status, sub-processor chain, breach history, and EU/UK data-transfer mechanism. Reviews are recorded in our internal vendor-risk register (which, fittingly, is built on v3ndor.io).
← Back to Legal hub