This document is in force but still under review by counsel; wording may change. Questions: [email protected].
Subprocessors
Programmable · Programmable Watch · last updated October 6, 2026
The third parties that process customer data to run Programmable Watch, what each does, and what it can see. Changes are announced 30 days ahead in the Service and on this page. The shared Programmable sign-in (Logto) is operated by us on our own infrastructure and is not a third party.
| Provider | Purpose | What it sees |
|---|---|---|
| OVHcloud | Hosting of the application and database (Virginia, United States) | Everything the Service stores, encrypted at rest where noted in the DPA |
| Cloudflare | DNS, TLS termination and request filtering in front of the application | Requests in transit, including IP addresses; no stored data |
| Stripe | Subscription billing | Account email, organisation name, payment details you enter with Stripe directly |
| Resend | Transactional email: digests, invitations, document requests, scheduled exports | Recipient addresses and email content, including supplier names and finding titles |
| Sentry | Error reports (only when enabled) | Stack traces and error messages; no request bodies, cookies, headers or query values |
| Programmable.info | The public-record registry the Service queries (operated by us) | Supplier names, states and identifiers sent as search terms; no decisions, notes or documents |
| Backblaze B2 or compatible object storage | Encrypted off-site backups (only when configured) | Encrypted archives it cannot read |