Sub-processors
Every company that can touch your data on the way to a booked meeting, what it does and where it does it. Published because a security review should not have to ask.
Last verified 19 August 2026
This document is maintained in English.
What a sub-processor is
A sub-processor is a company Veyra uses to run the service, which as a consequence can touch personal data you are the controller of. Payment, hosting, email delivery and the models that draft your outreach all fall into that category. You are entitled to know who they are before you buy, not after an incident.
Every one of them is bound by written terms no less protective than the data processing agreement, and none of them is permitted to use your data for its own purposes. Your data is never resold, and never pooled into someone else's model.
The current list
Every row below is verifiable from the code and the infrastructure that run the service today. The date above this list is the day it was last checked against the running system, not the day the page was written.
One row is conditional rather than constant. Google Analytics processes nothing at all unless a visitor accepts analytics in the cookie banner, and it touches only public website usage, never anything inside the product. It is listed anyway, because a list that only names the vendors that always run is not a list a security review can rely on.
| Sub-processor | What it does | Data it can touch | Where it processes |
|---|---|---|---|
| StripeStripe data processing agreement | Takes subscription payments, holds the customer and subscription record, and screens payments for fraud. | Billing email address, chosen plan and billing period, subscription metadata, and the card details you enter directly into Stripe. | Stripe Payments Europe, Limited, Ireland, with onward processing by Stripe, Inc. in the United States under standard contractual clauses. |
| CloudflareCloudflare data processing addendum | Turnstile bot protection on the checkout email step and the Summer Sweep claim box, so an address cannot be submitted by a script. | IP address and the challenge token, at the moment the check runs. Turnstile is built not to profile the visitor and sets no advertising identifier. | Cloudflare, Inc., United States, under standard contractual clauses. Challenges are answered at the network edge nearest the visitor, which for European visitors is inside the EU. |
| Google AnalyticsGoogle Ads data processing terms | Measures how the public website is used, and only for a visitor who accepted analytics in the cookie banner. It runs on the marketing site alone: it is absent from the product, and it never sees campaign data, prospect data or anything you enter into Veyra. | Website usage for that visit: pages viewed, referrer, device and browser, and an approximate location derived from a truncated IP address. No account data and no campaign data. Nothing at all when analytics is declined or withdrawn. | Google Ireland Limited, Ireland, with onward processing by Google LLC in the United States under standard contractual clauses. IP addresses are truncated before storage. |
| ResendResend data processing addendum | Delivers our own transactional mail, such as the Summer Sweep code email to the address that asked for it. It does not carry your campaigns. | Recipient email address and the content of that single message. | Resend, Inc., United States, under standard contractual clauses. |
| AnthropicAnthropic data processing addendum | Drafts outreach from the evidence gathered in the sweep and the voice examples you supplied, inside the playbook you set. | Business contact data and public signals about a prospect, plus your voice examples, included in the prompt. No special category data is sent. | Anthropic PBC, United States, under standard contractual clauses. Inputs sent through the commercial API are not used to train models. |
| Google Cloud StorageGoogle Cloud data processing addendum | Holds the encrypted off-site backup copy, so a fire or a failure in our own facility cannot take your data with it. | The same data the application holds, as an encrypted backup image rather than as readable records. | Google Cloud EMEA Limited, Ireland, in a European region. Backups do not leave the EEA. |
| WhatsApp, operated by MetaWhatsApp Business data processing terms | Carries WhatsApp outreach and the replies to it. Any WhatsApp message reaches its recipient over Meta's platform, whatever software sends it. | Recipient business phone number and the message content. | Meta Platforms Ireland Limited, Ireland, with onward processing outside the EEA under standard contractual clauses. |
What is deliberately not on the list
- The application, the database and the market sweep run on hardware we own and operate ourselves in Portugal. There is no hosting company between you and us, which is what the EU hosting claim actually rests on. The one exception is the encrypted off-site backup, which is listed above.
- Email campaigns are sent from the mailbox you connect, so your own mail provider carries them under your existing relationship with it, not ours.
- Support runs on email only. There is no ticketing tool, help desk or internal CRM holding your data.
How you hear about changes
This page is the authoritative list, and it changes on the day a vendor does. Customers are notified before a new sub-processor starts processing their data, so there is time to look at it.
We give 30 days notice by email to the address on your account before a new sub-processor starts handling your data, and we update this page at the same time. The notice says who the new processor is, what it will do, and where it will do it, so you are not left to work that out from a changed table.
If you object to one
You can object to a new sub-processor on reasonable data protection grounds. We will work with you to find a way around it, and if there is genuinely none, you can terminate the affected part of the subscription without penalty.
You can object in writing within those 30 days, on reasonable data protection grounds. Tell us what the concern is and we will try to meet it, by keeping your data off that processor if the architecture allows it or by finding another route. If we cannot, you may cancel before the change takes effect and we will refund the unused part of any term you have already paid for, which is the one case where money already paid does come back.
Questions about a vendor
Write to hello@veyrareach.com. If your security review needs the underlying agreements, transfer assessments or certifications for a specific vendor, ask and we will send what we have.
The rest of the legal set
Run your security review on us
Vendor list, transfer assessments, audit trail: bring the questionnaire to the demo.