TapfleetLegal
Sign in
← All documents· updated 2026-09-06
Template — review with counsel before publishing

Subprocessors

Last updated: 2026-09-06

These are the third parties Tapfleet, operated by Batuhan Ünverdi, uses to run the Service and that may process customer personal data on our behalf. This page is the list referred to in Annex III of the DPA, and it is kept current: a subprocessor is not put into the production path before it appears here.

1. Current subprocessors

SubprocessorRoleLocationData it can see
dehost (DEHOST İnternet ve Bilişim Teknolojileri)Control plane and panel compute, PostgreSQL database and file storage for builds and artifacts — the pilot deploymentAnkara, Türkiye
Hetzner Online GmbHSame role, planned EU region — not in use during the pilotFalkenstein, Germany (EU)
MacStadium (Orka)macOS hosts for the iOS device pool — not used during the pilot, which runs customer-hosted devices onlyDublin, Ireland (EU)
GitHub, Inc.Source hosting for our own code, and the GitHub App integration that posts checks on customer pull requestsPer GitHub's hostingFor customer checks only: pull-request metadata, diffs and check-run status, on the repositories the customer explicitly installs the App on
BrowserStackBroker for rented real devices, used only when an organisation opts in and supplies its own BrowserStack accountPer BrowserStack's own regionsThe app build and on-device session activity for brokered runs only. BrowserStack re-signs the build on its side
Slack TechnologiesDelivery of run and failure notifications to a channel the organisation configuresPer Slack's hostingOnly the notification payload — run status, top failure, report link. Secrets are masked before any outbound message
PagerDuty, Inc.Critical-issue alerting for organisations that configure itPer PagerDuty's hostingOnly the alert payload — issue title, severity, project
Stripe Payments Europe, Ltd.Subscription billing and payment processing for paid plansIreland (EU), with Stripe's global processingBilling contact email and name, the organisation's Stripe customer and subscription records, and metered usage totals. Card details go directly to Stripe and never reach our servers
Resend, Inc.Delivery of transactional email — invitations, digests, data-export links, verification and password mailUnited States (SCCs)Recipient email address, subject and body of the message we send, and Resend's delivery metadata (accepted, delivered, bounced)
Functional Software, Inc. (Sentry)Crash and error reporting for the control plane and the panel, only when a DSN is configuredEU region (*.ingest.de.sentry.io)Error payloads: stack trace, request path and method, and the user or organisation id attached to the failing request. Session cookies and authorization headers are stripped and every string is run through the secret masking rules before the event is sent (src/sentry.ts)

Notes on scope:

  • dehost is the only subprocessor in the path of every run during the pilot; devices are customer-hosted. Stripe is in the path of every paid account; Resend is in the path of any mail we send you. Crash reporting is not enabled.
  • The pilot is hosted in Türkiye, which has no EU adequacy decision: an EU customer's data is transferred outside the EEA under Standard Contractual Clauses. Resend processes in the United States, also under SCCs. An EU region is planned before general availability.
  • Region is pinned per organisation. During the pilot the only region in service is Türkiye. There is no cross-region replication of customer data.
  • A runner you host yourself never leaves your own network. We see only the results and artifacts it uploads.

2. Not our subprocessors

Some services process your data because you connected them and instructed us to route to them. They act as your own processors under your own agreements, and we are not a party to those contracts:

ServiceWhy it is yours, not ours
Your model provider (Anthropic, OpenAI, or another)The Service is bring-your-own-key. A model call happens only when your organisation has stored its own key, is authorised by that key, and is billed to your own provider account. What may be sent is bounded by your model data policy (hierarchy, screenshots, logs — screenshots and logs off by default). With no key stored, no call to an external model provider is made at all
Your own agent endpointWe deliver signed failure bundles to an HTTP endpoint you operate and configure
Slack, PagerDuty, Jira, GitLab, and other channels you connectWhere you configure the destination with your own credentials, the delivery is on your instruction. Slack and PagerDuty also appear in section 1 because we operate the delivery path
BrowserStack, where you supply your own accountThe device rental is on your own contract with them
Your CI system, your repositories and your ticket systemWe read them only through connectors you configure and only within the scope you grant

3. Change notice

Before a new subprocessor starts processing customer personal data, we will:

  1. add it to the table in section 1 with its role, location and data categories, and move the "Last updated" date;
  2. notify customers at least 30 days in advance, at the notice address on the account;
  3. give the customer that notice period to object on reasonable data protection grounds, under section 7 of the DPA. If we cannot offer an alternative, the customer may terminate the affected part of the Service without penalty for the unused prepaid term.

An emergency replacement — where a subprocessor fails and the Service cannot run without a substitute — is made with as much notice as circumstances allow, and the objection right still applies afterwards.

To be notified of changes to this page, contact batuhanunverdii@gmail.com.

4. Internal source

This page is the customer-facing view of the vendor register in docs/compliance/vendor-management.md, which also records each vendor's owner, review cadence and the evidence held for it. The two are diffed for consistency at each review; where they disagree, the vendor register is corrected and this page is republished.