Canonical page: https://tellenze.com/legal/subprocessors

# Subprocessors and providers

Document version

Version: 2026-10-10.draft-1

A draft inventory of service-provider paths, customer-connected apps and the contract details that still need owner confirmation.

Tellenze can use other services to deliver parts of the product. Some may process workspace personal information for us. Others act for their own purposes or connect through an account your organisation chooses.

This is an owner-confirmation inventory checked against the application on 10 October 2026. It is incomplete and is not an approved subprocessor schedule. Listing a supported integration does not show that it is active in production or approved for your workspace.

## 1. What each role means

At a glance: The contract and the activity determine the provider's role.

A Tellenze subprocessor is a provider we appoint to process customer personal data on our behalf for the agreed service. Its processing needs the customer's written authorisation under the DPA and a suitable written agreement with us.

A provider may also use information for its own defined purposes, such as payment regulation or its account administration. That activity needs a separate role assessment and privacy information; it is not automatically customer processing under the workspace DPA.

A customer-connected app is a service you select and authorise through your own connection or agreement. It may be your processor, an independent controller or part of another processing chain. Its availability in Tellenze does not automatically make it our subprocessor.

The same company can have more than one role. The completed schedule must identify the relevant activity and who appoints and instructs the provider.

## 2. Service paths to confirm

At a glance: These paths appear in the implementation or deployment design; their operational and contractual details remain under review.

The table describes what a supported path can send. It does not confirm a live account, a specific legal entity, an approved country or a signed agreement. Where a path processes customer data for the service, its provider must be included in the executed subprocessor annex.

| Service or path | Purpose and information involved | Role to assess | Confirmation status |
| --- | --- | --- | --- |
| OpenAI API for built-in AI | Generate chat responses and other enabled AI assistance. Requests can include instructions, authorised work context, history, tool results and selected image or PDF attachments. | Potential Tellenze subprocessor for customer-content processing under the actual API agreement. This is separate from a customer's ChatGPT connection. | Application path verified. Confirm account owner, contracting entity, executed terms, enabled features, access and processing countries, retention controls and transfers. |
| Postmark transactional email | Deliver service messages such as invitations, account messages and requested website communications. Receives the relevant recipient, message content, links and delivery metadata. | Potential Tellenze subprocessor for customer-related service messages; separate controller-purpose processing may apply to public enquiries or business administration. | Direct API path verified. Confirm the contracted entity, agreement, actual message categories, locations, retention and transfer safeguards. |
| Cloudflare network and custom-domain services | Deployment design refers to the network edge, and the application supports custom-domain and certificate management. Domains and technical request information may be involved; content exposure depends on the services and routing enabled. | Role depends on the specific Tellenze-appointed service and data path. Network, domain and account processing must be assessed separately where relevant. | Configuration and deployment path found. Confirm active products, contracting entity, routed hosts, data visibility, access locations, retention and agreement. |
| Stripe billing | Supported billing flow can send billing contacts, customer and subscription information and payment references when billing is enabled. | Stripe's published terms distinguish processor and controller activities. Do not classify every payment function as a workspace subprocessor activity. | Code path exists; billing is disabled by default. Confirm actual availability, account and entity, service-specific roles, data sent, locations and terms before listing it as active. |
| Hosting, databases, private-file storage and backups | Run the service and retain or recover application data and private files. The design includes database and S3-compatible storage components. | Identify the actual hosting operators and any storage or recovery providers with access to customer personal data. Software names alone are not processor identities. | Inventory incomplete. Exact providers, entities, countries, access paths, backup copies and contracts require owner confirmation. |
| Support, monitoring and other operational services | Possible access to support material, technical events or operational records depends on the actual tools and procedures. | Identify any appointed provider that receives customer personal data and distinguish independent-purpose activities. | Inventory incomplete. Confirm whether such services are used, what they receive and the applicable processing arrangements. |

## 3. Apps and providers you connect

At a glance: Your connection choices can add recipients and separate agreements.

Workspace administrators and members can use enabled integrations within their access. For Gmail and SMTP email powerups, the sending account or server is chosen through a customer connection. A reviewed send passes the message and addressing information to that provider. Account type and the actual agreement matter: a personal Gmail account and a Google Workspace account must not be assumed to have identical processing terms.

Other connected work, design, publishing or identity services may receive or return information within the granted scope. Confirm the actual feature, provider, account owner and permission before enabling it. A supported connection can be disabled, limited or unavailable in a particular workspace.

A connected ChatGPT or other agent client receives the information returned by the tools it can access. The customer's provider account, chat history and settings govern that client's separate processing. A customer ChatGPT connection is not the same data path as Tellenze's built-in OpenAI API requests.

Your organisation should record these recipients in its own processing assessment and notices. If we appoint or control a provider for your service instead of connecting a customer-appointed account, that arrangement must also be assessed for the Tellenze subprocessor schedule.

## 4. Business administration and Xolo Go

At a glance: The invoicing framework does not establish a workspace-processing role.

João Pedro Marques Morais operates Tellenze. The owner-provided business display is Xolo Go OÜ - João Pedro Marques Morais, Estonia Partnership. Xolo's published framework describes administrative and representation support within a contractual partnership, which has no separate legal personality.

Business or invoicing information handled through that framework needs its own role and information-flow assessment. It does not show that Xolo hosts the product, accesses workspace content or acts as a Tellenze processor or subprocessor. Confirm the actual business agreements and recipients before assigning a role.

The parties to a customer service contract and to any DPA must be checked separately. This inventory neither appoints Xolo as a data-processing party nor treats the partnership display as a separate Tellenze legal entity.

## 5. What the confirmed schedule must contain

At a glance: A brand name and a provider policy link are not enough.

For each actual subprocessor, the service owner must complete the following record and retain the supporting evidence. A provider's public DPA is useful research, but it does not prove that the appropriate agreement is in force for Tellenze's account.

| Required record | What to confirm |
| --- | --- |
| Identity and agreement | Exact legal entity, account owner, service or products, applicable agreement and DPA version, and execution or incorporation evidence. |
| Purpose and data | Which service task is performed, information sent or accessible, people concerned and any sensitive data. |
| Role and appointment | Who appoints the provider and gives instructions; which activities are processor work and which use data for separate purposes. |
| Locations and access | Countries for storage, processing, support access, recovery copies and relevant onward processing. A billing address or default region setting is insufficient. |
| Protection and retention | Relevant security commitments, account settings, retention and deletion routes, incident support and assistance with rights requests. |
| International transfers | Valid basis for each relevant transfer, correct clauses and completed annexes where used, transfer assessment and any additional measures. |
| Authorisation and changes | Customer's written approval, contact and notice method, objection process and the current schedule version. |

## 6. Locations and international transfers

At a glance: Storage, support access and onward processing all need review.

This draft does not claim EU-only hosting or processing. A configured storage region is not evidence of the physical location of a self-hosted S3-compatible service, and a provider's European contracting entity does not establish all its access locations.

Where international-transfer rules apply, the actual recipients and safeguards must be recorded. Relevant standard contractual clauses need the correct roles, module and completed annexes; a link to a provider's clauses does not complete that assessment for Tellenze.

The DPA describes the proposed transfer duties. The Article 28 controller–processor clauses in Decision 2021/915 and transfer clauses in Decision 2021/914 have different purposes. Neither is assumed to be executed by this inventory.

## 7. Approval and provider changes

At a glance: The agreed DPA sets the approval method and the opportunity to object.

The proposed DPA requires specific or general written authorisation before a subprocessor is appointed. Under general authorisation, additions or replacements need advance information and a useful opportunity to object on data-protection grounds. The agreed annex must set the practical notice method and procedure.

The owner-confirmation status on this page is not a customer approval status. Reading it, selecting an integration or keeping an account open does not sign the draft DPA or approve all possible future providers.

When the schedule is verified and agreed, material provider changes should be recorded with the relevant purpose, data, locations and safeguards. Unresolved objections or missing transfer protection must be addressed before the affected new processing proceeds.

## 8. Disconnecting and stored copies

At a glance: Stopping future access and deleting existing information are separate actions.

Disabling a feature, removing a grant or disconnecting an account can limit future Tellenze access. It does not by itself erase emails already sent, external chat history, provider logs or other information a provider has already received.

Deletion for our subprocessors must follow the executed DPA and the confirmed retention arrangements. For customer-appointed accounts or independent recipients, your organisation may also need to use the provider's account controls or make a separate request. Contact general@tellenze.com for help identifying the relevant Tellenze processing path.

## Sources used for this document

- [GDPR Article 28: subprocessor authorisation and responsibilities](https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng)
- [OpenAI: data processing addendum](https://openai.com/policies/data-processing-addendum/)
- [Official OpenAI documentation: API data controls](https://developers.openai.com/api/docs/guides/your-data)
- [Postmark: data processing addendum](https://postmarkapp.com/dpa)
- [Cloudflare: customer data processing addendum](https://www.cloudflare.com/cloudflare-customer-dpa/)
- [Stripe: processor and controller roles in its data processing agreement](https://stripe.com/legal/dpa)
- [Google: cloud and Workspace data processing terms, subject to the actual account agreement](https://cloud.google.com/terms/data-processing-addendum/)
- [Xolo: administrative role and service-contract framework](https://www.xolo.io/nl-en/faq/xolo-go/category/get-started/article/general-terms-for-the-service-contract-template)

Contact: general@tellenze.com
