Programmable

This document is in force but still under review by counsel; wording may change. Questions: [email protected].

Subprocessors

Programmable · Programmable Watch · last updated October 6, 2026

The third parties that process customer data to run Programmable Watch, what each does, and what it can see. Changes are announced 30 days ahead in the Service and on this page. The shared Programmable sign-in (Logto) is operated by us on our own infrastructure and is not a third party.

ProviderPurposeWhat it sees
OVHcloudHosting of the application and database (Virginia, United States)Everything the Service stores, encrypted at rest where noted in the DPA
CloudflareDNS, TLS termination and request filtering in front of the applicationRequests in transit, including IP addresses; no stored data
StripeSubscription billingAccount email, organisation name, payment details you enter with Stripe directly
ResendTransactional email: digests, invitations, document requests, scheduled exportsRecipient addresses and email content, including supplier names and finding titles
SentryError reports (only when enabled)Stack traces and error messages; no request bodies, cookies, headers or query values
Programmable.infoThe public-record registry the Service queries (operated by us)Supplier names, states and identifiers sent as search terms; no decisions, notes or documents
Backblaze B2 or compatible object storageEncrypted off-site backups (only when configured)Encrypted archives it cannot read