Subprocessors
Last updated September 1, 2026. Back to Vorklee
This list describes third-party vendors that process personal data on behalf of Vorklee when you use our platform. We update this page when we add or replace a subprocessor.
| Vendor | Role | Data | Region | Notes |
|---|---|---|---|---|
| Clerk | Authentication, MFA | Email, name, session | United States | SOC 2; GDPR tooling |
| Neon | PostgreSQL database | All org-scoped application data | United States (project region) | DPA via Neon |
| Vercel | Hosting, edge network | Request logs, build artifacts | Global | DPA via Vercel |
| Upstash | Redis (cache, analytics, SSE) | Scrubbed analytics, cache keys | US/EU per project | DPA via Upstash |
| Sentry | Error monitoring | Scrubbed crash events | United States | DPA via Sentry; sendDefaultPii disabled |
| Google (Gemini) | AI inference | Scrubbed prompts via platform AI gate | United States | API terms; secrets redacted before send |
| Stripe | Billing (when enabled) | Billing contact, payment tokens | United States | PCI; Stripe DPA |
| Cloudflare R2 | File attachments (where used) | Uploaded file blobs | Per bucket | DPA via Cloudflare |
| Firebase / FCM | Push notifications (where enabled) | Device tokens | Firebase terms |
Enterprise customers may request a DPA or formal Transfer Impact Assessment before signature.