Skip to content

Tending subprocessor schedule

Last reviewed: 16 September 2026

This schedule supports Tending's data processing agreement. Exact contractual entities and transfer mechanisms should be checked against the live supplier agreements before issuing a signed DPA.

Service Purpose Data involved Primary location / routing note
Neon Hosted PostgreSQL database Organisation data, accounts, relationship records, connected-source context Tending's production project is in AWS eu-west-2 (London, UK)
Vercel Application hosting, request execution, deployment and operational delivery Request data and operational/service metadata required to serve the application Vercel infrastructure; processing location depends on the configured service and request path
Resend Transactional email and supported email-capture flows Recipient/sender addresses, message delivery data and capture content where used Per Resend contractual/service configuration
Stripe Subscription and payment processing Billing identifiers, customer/subscription metadata; card details are handled by Stripe rather than stored by Tending Per Stripe contractual/service configuration
OpenRouter AI routing Prompt/response content for selected AI features plus request metadata Tending requires zdr: true and data_collection: deny on requests
Eligible OpenRouter model providers Model inference behind OpenRouter Prompt/response content transiently required to perform inference Variable by selected eligible endpoint; constrained by OpenRouter ZDR/non-collection routing
ElevenLabs Voice transcription where configured Audio submitted for transcription and resulting text Per ElevenLabs contractual/service configuration
OpenAI Voice transcription where configured and any explicitly configured direct OpenAI processing Audio/text submitted for the selected feature Per OpenAI contractual/service configuration

Connected services

Google (Gmail/Calendar), Slack and ClickUp can be deliberately connected by individual Tending users. They are sources/destinations selected by the customer rather than automatically enabled subprocessors for every Tending organisation. Tending stores encrypted connection credentials and short-lived imported context required to provide the chosen integration. Disconnecting a source deletes its imported context events from Tending; data a user has explicitly kept as an ordinary Tending record follows the organisation's normal retention rules.

Change control

When adding or materially changing a subprocessor:

  1. update this schedule and the public privacy notice where relevant;
  2. check the provider's DPA, security terms, retention/training policy and transfer mechanism;
  3. confirm the change does not weaken Tending's stated AI or data-location controls;
  4. notify contracted controllers where their agreement requires notice or an objection period; and
  5. record the effective date of the change.