Subprocessors
Last updated: September 2026
About this list
This page lists the third parties that process personal data on our behalf in order to provide Flowr. It forms part of the Data Processing Agreement.
We will give notice of a new or replacement subprocessor before it begins processing, so that customers have an opportunity to object as set out in the DPA.
Providers are listed only where they actually process personal data in the running service. Software libraries and vendors that do not receive personal data are not listed.
Infrastructure and application
- Microsoft (Azure) — hosting of the application, database, backups and operational logs. Processing region: West Europe (EU). Data: all Customer Data and application telemetry.
- Vercel — hosting and delivery of the marketing website and the application front end, and the serverless functions behind the contact and early-access forms. Data: request metadata, IP addresses, authentication tokens in transit, and contact/early-access form submissions. Transfers outside the EEA may occur; safeguards as described below.
- Clerk — sign-in and account identity. Data: name, email address and authentication identifiers. Transfers outside the EEA may occur; safeguards as described below.
Commercial and support
- Stripe — payment processing and subscription billing. Data: billing contact details, VAT identification and payment method details, which we never see or store ourselves. Transfers outside the EEA may occur; safeguards as described below.
- Crisp — in-application support chat. Data: name, email address and the content of messages you send us. Provider established in France (EU).
- Airtable — storage of contact and early-access form submissions from the website. Data: name, email address, company, role and message. Transfers outside the EEA may occur; safeguards as described below.
- Sentry — application error reports. Data: technical request context, which can include identifiers. Processing region: Germany (EU).
Artificial intelligence
AI processing occurs only where Flowr Assist is enabled for the organisation, and only when someone asks for a suggestion. It is disabled by default.
- Anthropic — model access for AI-assisted drafting and review, where enabled. Data: the project information described in the Privacy Policy. Transfers outside the EEA may occur; safeguards as described below.
- Where an organisation supplies its own provider key, requests run under that organisation's own account with that provider. The relationship with that provider is the customer's own, and that provider is not our subprocessor for those requests.
Development, maintenance and technical support
- Jilyss Advisory SARL — Morocco. Purpose: development and maintenance of the Flowr software, and exceptional technical support of the production environment.
- There is no routine access to production Customer Data. Standing access is limited to read-only visibility of infrastructure configuration and operational metrics, with no database access and no ability to read application secrets.
- Where exceptional technical access to production data is required, it is authorised by Kho’n Sul’t, granted to a named individual for a limited period, recorded in the database audit log, and revoked on completion. Immediate termination of an authorised session is performed by disabling the account or the network path where required.
- Morocco is not the subject of a European Commission adequacy decision. Transfers and access are subject to the safeguards described below.
International transfers
Production Customer Data is hosted in the European Union (Azure West Europe). Some of the providers above are established outside the EEA, or may access data from outside it, and we do not claim otherwise.
Where personal data is transferred outside the EEA, we put in place an appropriate transfer mechanism under Chapter V of the GDPR — normally the European Commission's Standard Contractual Clauses — together with an assessment of the transfer, before the transfer takes place.
Morocco, where Jilyss Advisory SARL is established, is not the subject of a European Commission adequacy decision. There is no routine access to production Customer Data from Morocco; exceptional technical access is authorised in advance, limited, attributable and audited.
This list forms part of the Data Processing Agreement.