Tending subprocessor schedule
Last reviewed: 16 September 2026
This schedule supports Tending's data processing agreement. Exact contractual entities and transfer mechanisms should be checked against the live supplier agreements before issuing a signed DPA.
| Service | Purpose | Data involved | Primary location / routing note |
|---|---|---|---|
| Neon | Hosted PostgreSQL database | Organisation data, accounts, relationship records, connected-source context | Tending's production project is in AWS eu-west-2 (London, UK) |
| Vercel | Application hosting, request execution, deployment and operational delivery | Request data and operational/service metadata required to serve the application | Vercel infrastructure; processing location depends on the configured service and request path |
| Resend | Transactional email and supported email-capture flows | Recipient/sender addresses, message delivery data and capture content where used | Per Resend contractual/service configuration |
| Stripe | Subscription and payment processing | Billing identifiers, customer/subscription metadata; card details are handled by Stripe rather than stored by Tending | Per Stripe contractual/service configuration |
| OpenRouter | AI routing | Prompt/response content for selected AI features plus request metadata | Tending requires zdr: true and data_collection: deny on requests |
| Eligible OpenRouter model providers | Model inference behind OpenRouter | Prompt/response content transiently required to perform inference | Variable by selected eligible endpoint; constrained by OpenRouter ZDR/non-collection routing |
| ElevenLabs | Voice transcription where configured | Audio submitted for transcription and resulting text | Per ElevenLabs contractual/service configuration |
| OpenAI | Voice transcription where configured and any explicitly configured direct OpenAI processing | Audio/text submitted for the selected feature | Per OpenAI contractual/service configuration |
Connected services
Google (Gmail/Calendar), Slack and ClickUp can be deliberately connected by individual Tending users. They are sources/destinations selected by the customer rather than automatically enabled subprocessors for every Tending organisation. Tending stores encrypted connection credentials and short-lived imported context required to provide the chosen integration. Disconnecting a source deletes its imported context events from Tending; data a user has explicitly kept as an ordinary Tending record follows the organisation's normal retention rules.
Change control
When adding or materially changing a subprocessor:
- update this schedule and the public privacy notice where relevant;
- check the provider's DPA, security terms, retention/training policy and transfer mechanism;
- confirm the change does not weaken Tending's stated AI or data-location controls;
- notify contracted controllers where their agreement requires notice or an objection period; and
- record the effective date of the change.