Subprocessors
Last updated: April 28, 2026
Tawqee uses the following third-party subprocessors to deliver the Service. We update this page at least 30 days before adding any new subprocessor. To subscribe to changes, email privacy@tawqee.com.
| Vendor | Purpose | Location | Data types | Safeguards |
|---|---|---|---|---|
| Vercel, Inc. | Application hosting, edge / CDN, Next.js runtime | USA, EU (Frankfurt), regional | Application logs, IP, user-agent, request metadata | DPA in place; SOC 2 Type II; EU SCCs |
| Neon, Inc. | Managed PostgreSQL database (primary store) | AWS US East 2 / EU Central 1 | All Customer Content, account records, audit log | DPA in place; SOC 2 Type II; daily PITR backups |
| Anthropic PBC | AI features (auto field detection, contract summary) | USA | Document text excerpts (only when AI features are invoked) | Zero-retention by default; BYOK option for enterprise; DPA + EU SCCs |
| Resend, Inc. | Transactional email delivery | USA | Recipient email address, name, signing link, subject line | DPA in place; SOC 2 Type II; suppression-list management |
| Stripe, Inc. | Subscription billing and payment processing | USA, EU, regional | Customer name, email, billing address, tax ID; never card numbers (Stripe vaulted) | PCI-DSS Level 1; DPA + EU SCCs; ZATCA-compliant invoices for KSA |
| Cloudflare R2 (or AWS S3) | Object storage for original PDFs, signed PDFs, audit certs | Configurable per region; defaults to customer's home region | PDF bytes, signature images, identity-proof artifacts | AES-256 server-side encryption; Object Lock (WORM) on audit/ bucket; SOC 2 |
| Sentry (Functional Software, Inc.) | Error monitoring (production) | USA, EU | Error stack traces, request URL, user ID; PII scrubbed via filters | DPA + EU SCCs; PII scrubbing rules enabled |
| Persona Identities, Inc. (optional) | Global ID-document and selfie verification | USA | ID document images, selfies, verification result | SOC 2 Type II; data deletion configurable; DPA + EU SCCs |
| Saudi Nafath / Yakeen API (optional, KSA) | Saudi national identity verification | Kingdom of Saudi Arabia | National ID, verification result | Data stays in KSA; governed by NDMO and PDPL |
Customer-controlled BYO subprocessors
Enterprise customers can bring their own subprocessor agreements for: AI provider (Anthropic key), object storage bucket (their AWS / GCP / Azure account), email relay (their SES / SendGrid). In these cases the contractual relationship is between the Customer and the named subprocessor, not Tawqee.
Sub-subprocessors
Each subprocessor above may use its own infrastructure providers (e.g., AWS, GCP). We monitor those flow-down obligations through their respective DPAs.