Sub-processors
Last Updated: March 2026
This page lists the third-party service providers (sub-processors) that process personal data on behalf of Tatoma B.V. in connection with our platform.
What Are Sub-processors?
Sub-processors are third-party companies that we engage to help us provide our services. They may process personal data on our behalf under strict contractual obligations to protect your data.
Current Sub-processors
Infrastructure & Platform
| Sub-processor | Purpose | Data Processed | Location |
|---|---|---|---|
| WorkOS | Authentication & SSO | User identity, email, organization membership | USA |
| Supabase | Database & file storage | Application data, uploaded files | EU (Frankfurt) |
| Vercel | Hosting & deployment | Request logs, IP addresses | Global (EU primary) |
| Resend | Email delivery | Email addresses, notification content | USA |
AI & Machine Learning
| Sub-processor | Purpose | Data Processed | Location |
|---|---|---|---|
| OpenAI | AI language processing | Prompts and content submitted to AI features (no retention) | USA |
| Anthropic | AI language processing | Prompts and content submitted to AI features (no retention) | USA |
| Groq | AI language processing | Prompts and content submitted to AI features (no retention) | USA |
| Mistral | AI language processing & embeddings | Prompts and content submitted to AI features (no retention) | EU (France) |
| Google (Gemini) | AI language processing | Prompts and content submitted to AI features (no retention) | USA |
| Perplexity | AI-powered research & search | Queries and context submitted to research features (no retention) | USA |
| Tavily | AI-powered web search | Search queries for tool and brand discovery (no retention) | USA |
Data Processing Locations
We prioritize EU-based data processing where possible:
- Primary database: EU (Frankfurt, Germany)
- File storage: EU (Frankfurt, Germany)
- Application hosting: EU region preferred, with global CDN
Sub-processor Changes
We may update our sub-processors from time to time. Material changes to this list will be reflected in the "Last Updated" date above.
If you have a Data Processing Agreement (DPA) with us that includes sub-processor notification requirements, we will notify you of changes according to those terms.
Safeguards for International Transfers
For sub-processors located outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with each sub-processor
- EU-US Data Privacy Framework certification where applicable
Sub-processor Privacy Policies
- WorkOS Privacy Policy
- Supabase Privacy Policy
- Vercel Privacy Policy
- Resend Privacy Policy
- OpenAI Privacy Policy
- Anthropic Privacy Policy
- Groq Privacy Policy
- Mistral Privacy Policy
- Google Privacy Policy
- Perplexity Privacy Policy
- Tavily Privacy Policy
Questions
If you have questions about our sub-processors or data processing practices, please contact us:
Email: gdpr@tatoma.eu
Postal Address: Tatoma B.V. Willemstraat 1 5611 HA, Eindhoven The Netherlands