Subprocessors
Placeholder draft · Last updated 21 August 2026
Placeholder draft — this document has not yet completed legal review and is not legal advice. Final text must be reviewed before client contracting.
1. What this page covers
This page lists the third-party vendors that process data on OgmaQ's behalf to deliver the service ("subprocessors"), separates them from providers that are not yet (or not currently) in use, and states OgmaQ's position on AI providers. It is kept up to date as the service evolves.
2. Current subprocessors
| Vendor | Purpose | Data processed | Data location | Status |
|---|---|---|---|---|
| Supabase | Database, authentication, file storage, serverless (edge) functions and API infrastructure | Customer workspace data — including the content of files uploaded as attachments, stored in object storage designed to be private — account/profile data, authentication data, operational records and audit-support records | EU · eu-central-1 (Frankfurt) | Confirmed in use |
| Cloudflare | Web hosting (Pages), DNS, email routing, CDN and caching, TLS, WAF and bot management, and performance/security features | Request metadata, IP addresses, public-site/app delivery metadata and related technical/security logs | Global edge network | Confirmed in use |
| Resend | Transactional email delivery — authentication, account and service-notification emails, and workflow notification emails such as "you were mentioned" alerts (active on the production deployment since 16 August 2026) | Recipient email address and the content of transactional emails. Workflow notification emails are deliberately minimal — a record reference, the mentioning colleague's display name and sign-in links; never message text or workspace record content | EU · eu-west-1 (Ireland) | Confirmed in use |
Web fonts are self-hosted on both the public website and the application — no font request is made to Google or any other third-party font service, so Google Fonts is no longer a subprocessor (see the revision history below).
Separately, a legacy self-contained product demo is published on GitHub Pages (hosted by GitHub). It contains only fictional, browser-local demo data, has no sign-in and no database connection, and processes no customer workspace data — GitHub is therefore not listed as a subprocessor. app.ogmaq.com is the production application.
3. Providers not currently active or still to be confirmed
| Provider category | Purpose | Current status |
|---|---|---|
| Payment provider | Billing and subscription management | Not currently used |
| Customer support / helpdesk provider | Customer support and support-ticket handling | Not currently used |
| Analytics provider | Product or website analytics | Not currently used |
| AI provider | Customer-facing AI functionality or customer tenant-data AI processing | Not currently used |
| Identity provider (Microsoft Entra ID) | Planned enterprise single sign-on — federated sign-in where a customer configures it for their deployment. The capability is built into the product, but the Microsoft sign-in provider is not enabled in production: no federated sign-in and no Microsoft identity processing occurs today. Whether an identity provider is characterised as a subprocessor or as the customer's own provider will be confirmed during legal review. | Built, not enabled |
These categories are listed for transparency about the expected shape of the service. They are not current subprocessors and should not be treated as such until a specific vendor is confirmed and moved into the current table above.
4. AI providers
AI and customer data: OgmaQ's customer-facing product currently has no AI functionality. OgmaQ does not process customer tenant data through AI providers, no AI vendor is currently a subprocessor of customer tenant data, and customer workspace content is not used to train AI models. Any future customer-facing AI-assisted functionality would require separate documentation, configuration, customer-facing disclosure and review before being enabled. Internal company tooling used outside the customer-facing product is separately scoped and controlled, and does not involve customer tenant data.
5. Changes to this list
Before adding a new subprocessor that would process customer tenant data, we will update this page. The notification and objection process for subprocessor changes will be defined during legal review and reflected in the Data Processing Agreement.
6. Revision history
Material changes to this list are recorded here so customers can see how it has evolved. Entries are added over time; older revisions are not removed.
| Date | Change | Notes |
|---|---|---|
| 16 August 2026 | Corrected the Resend entry: workflow notification email is now active on the production deployment, verified end-to-end. It was previously described as pending configuration. Recipient email addresses are therefore transmitted to Resend in normal operation when a colleague @-mentions someone; the emails remain deliberately minimal (a record reference, the mentioning colleague’s display name and sign-in links) and never carry message text or workspace record content. | Placeholder draft pending legal review (accuracy correction — a stated condition had become false). |
| 12 August 2026 | Clarified the Supabase entry to name file storage and serverless (edge) functions, and to state that the content of files uploaded as attachments is stored in object storage designed to be private (real attachment storage shipped with v2.69). Disclosed planned Microsoft Entra ID single sign-on as a not-currently-active provider: the capability is built and its database foundation is deployed, but the Microsoft sign-in provider is not enabled in production and no Microsoft identity data is processed today. Added a transparency note on the data-free legacy GitHub Pages demo. | Placeholder draft pending legal review (v4.7 accuracy refresh). |
| 20 July 2026 | Extended the documented Resend scope from authentication/account emails to also cover workflow notification emails ("you were mentioned" alerts) introduced with the notification mailer (v2.73). These emails carry a record reference, the mentioning colleague's display name and sign-in links only — never message text or workspace record content. The mailer ships fail-closed and sends nothing until it is deployed and configured. | Placeholder draft pending legal review (counsel-track DEC-10). |
| 19 July 2026 | Removed Google Fonts from the current-subprocessor list: web fonts have been self-hosted on both the public website and the application since 16 July 2026 (v2.65), so no font request leaves OgmaQ's own hosting. This entry corrects the list to match that change. | Placeholder draft pending legal review. |
| 7 July 2026 | Confirmed Resend's sending region (EU · eu-west-1, Ireland) and recorded a signed Resend data-processing agreement on file. No analytics provider is active (Cloudflare Web Analytics was disabled). | Placeholder draft pending legal review (v2.46.2). |
| 7 July 2026 | Confirmed the Supabase project region (EU · eu-central-1), added Resend as the transactional email subprocessor, recorded Supabase and Cloudflare data-processing terms, and removed the "being set up" caveat from contact aliases after mailbox routing was configured and tested. | Placeholder draft pending legal review (v2.46.1). |
| 7 July 2026 | Added a dedicated revision-history section and clarified the AI-provider position. | Placeholder draft pending legal review. |
| 6 July 2026 | Introduced the current-vs-not-currently-active provider split and the AI-provider statement. | Placeholder draft pending legal review. |
7. Contact
Questions about this list: legal@ogmaq.com (general contact: hello@ogmaq.com). These role-based aliases route to the OgmaQ team; hello@ogmaq.com is the general contact if you are unsure which to use.