Subprocessors

Last updated: October 8, 2025

This page lists third-party subprocessors that Floa Software Solutions Ltd ("Floa," "we," "us") engages to help deliver, secure, and support our Services. Terms used but not defined here have the meanings in our Data Processing Addendum (DPA).

How we use subprocessors (at a glance)

  • General authorisation. Per our DPA, you authorise Floa to use subprocessors.
  • Our responsibility. We impose data-protection obligations on subprocessors no less protective than our DPA and remain responsible for their performance.
  • Notice of changes. We will update this page to reflect additions or replacements.
  • Objections. You may object on reasonable, data-protection grounds within 10 days of publication by emailing privacy@getfloa.com. If unresolved, you may suspend the affected feature or terminate the impacted Services (pro-rata refund for prepaid, unused fees where applicable).

Data residency & transfers

  • We aim to process and store Customer Personal Data in EU/UK regions where feasible (e.g., Azure West Europe and EU database regions).
  • Where transfers outside the UK/EEA occur, we rely on EU SCCs (2021/914) and, for the UK, the UK Addendum, plus supplementary measures (e.g., TLS, encryption at rest, access controls).

Current subprocessors (core)

These providers are part of our core stack and will typically process Customer Personal Data whenever you use the platform.
SubprocessorPurposeCategories of DataProcessing Location(s)Entity CountryTransfer MechanismNotes
Microsoft AzureCloud hosting, compute, storage, CDN, networking (incl. Front Door/Static Web Apps)Account data, content stored/served by the app, usage/telemetryEUUSASCCs + UK Addendum (as needed)Encryption in transit/at rest; role-based access controls
Azure Application Insights (Microsoft)Monitoring, logs, performance metricsPseudonymous telemetry (events, timings, headers/IP (may be truncated))EUUSASCCs + UK AddendumUsed for observability and incident response
Azure OpenAI (Microsoft)AI inference (processing prompts/inputs to generate outputs)Text/files you submit for generation; output metadataEUUSASCCs + UK AddendumWe opt out of provider training by default where supported
SupabaseManaged Postgres DB, auth, storageAccount data, content you upload, metadataEUUSASCCs + UK AddendumEncryption at rest; fine-grained RLS policies

Messaging & communications (feature-dependent)

These processors apply only if you enable outbound messaging or related features.
SubprocessorPurposeCategories of DataProcessing Location(s)Entity CountryTransfer MechanismNotes
Twilio / SendGridTransactional email & SMS/WhatsApp deliveryRecipient identifiers (email/phone), message content, delivery metadataEU/US (routing dependent)USASCCs + UK AddendumAnti-abuse and deliverability tooling
ResendEmail sending via APIRecipient identifiers, message content, delivery metadataEU/US (routing dependent)USASCCs + UK AddendumEdge-function integration option

Billing & payments (feature-/plan-dependent)

Used when you purchase or manage a paid subscription.
SubprocessorPurposeCategories of DataProcessing Location(s)Entity CountryTransfer MechanismNotes
StripePayment processing, subscription billing, invoicingBilling contact, payment tokens, transaction metadataEU/US (processor routing)USA/UKSCCs + UK AddendumCard data handled by the processor; we do not store raw PANs
XeroAccounting & invoicingInvoice details, billing contact, amounts, tax IDsEU/US (service hosting)New ZealandSCCs + UK AddendumBookkeeping and statutory records

Customer support, CRM & marketing (context-dependent)

May process personal data you share with us for support, onboarding, or marketing site interactions.
SubprocessorPurposeCategories of DataProcessing Location(s)Entity CountryTransfer MechanismNotes
AttioCRM, marketing emails/forms (website)Lead/contact info, communications metadataEU/US (service hosting)USASCCs + UK AddendumFor website leads and product updates
Microsoft 365Email & file storage (support comms, attachments)Email headers/content, attachments you sendEU/US (workspace routing)USASCCs + UK AddendumSupport inbox privacy@getfloa.com

Analytics & error tracking (website/app)

Analytics tools may use cookies/SDKs. Where required, we obtain consent and apply IP masking or similar.
ProviderPurposeCategories of DataProcessing Location(s)Entity CountryTransfer MechanismNotes
Google Analytics (GA4)Product & website analyticsPseudonymous IDs, event data, device/geo (approx.), IP (masked)EU/US (processing)USASCCs + UK AddendumConsent-based where required; IP anonymization
SentryError trackingError payloads, stack traces, limited request contextEU/US (project setting)USASCCs + UK AddendumHelps diagnose and resolve bugs

Third parties you may interact with directly (not subprocessors)

Some third parties act as independent controllers, not our processors—for example advertising pixels (e.g., Meta, TikTok) or payment pages hosted directly by a payment provider. Their processing is governed by their own privacy policies. See our Privacy Policy and Cookies pages for details and consent controls.

Change log

We maintain a transparent history of material subprocessor changes.
  • 8 Oct 2025 — Initial publication of public list; clarified AI provider training opt-out stance.

Objections & questions

  • Objections (10-day window): Email privacy@getfloa.com with your Customer name, impacted feature(s), and specific data-protection grounds.
  • Questions: We're happy to provide high-level security/transfer information (policy summaries, pen-test summaries) on request.

Notes & defaults

  • AI model training: We do not permit third-party foundation model training on Customer Personal Data by default.
  • Supplementary measures: TLS, encryption at rest, strict access controls, and transfer risk assessments are applied where appropriate.
  • Regional choices: Where a regional option exists (e.g., EU hosting), we select EU/UK by default for Customer Personal Data unless operational needs or your configuration require otherwise.

We value your privacy

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Learn more