Sub-Processors — Flowie's Named Third-Party Data Processors
Flowie engages exactly 9 named sub-processors to deliver our service. All 9 have signed Data Processing Agreements (DPAs) with Flowie, and all non-EU transfers are governed by Standard Contractual Clauses (SCCs). AI processors handle descriptive text only — never financial amounts, never IBANs. Mistral AI is fully French-hosted.
This page is the canonical public reference for the sub-processor annex of the Flowie DPA (version: May 2025). If you are a data controller reviewing our sub-processor disclosure before signing or renewing your DPA, this is the document your team needs. We update this list whenever a sub-processor is added, replaced, or materially changed.
The "Last reviewed" date in the table reflects the most recent per-processor verification. The page-level date above reflects the last time this document was published or revised. Material changes — meaning any addition, replacement, or significant scope expansion — are communicated to data controllers at least 30 days in advance. Minor operational changes (for example, a sub-processor updating a sub-region within an already-disclosed country) do not trigger formal notification. To receive advance notice of material changes automatically, subscribe using the link at the bottom of this page.
The list
Sub-processor list
Nine named third parties. All under signed DPAs. SCCs in force for every non-EU transfer.
| Sub-processor | Category | Purpose | Location | DPA | SCCs | Last reviewed |
|---|---|---|---|---|---|---|
GCP via S3NS Google Cloud Platform via S3NS (Google + Thales) | Infrastructure | Cloud hosting on EU sovereign cloud — Google + Thales partnership | France (primary)Belgium (disaster recovery) | Signed | N/A — EU-hosted | |
Auth0 Okta Inc. | Authentication | Authentication, MFA, and identity token management | Belgium | Signed | Yes (under SCCs) | |
SendGrid Twilio Inc. | Transactional email delivery (notifications, alerts) | United States (EU options available) | Signed | Yes (under SCCs) | ||
Sentry Functional Software Inc. | Monitoring | Application error and performance monitoring (anonymized stack traces)90-day retention | United States (EU options available) | Signed | Yes (under SCCs) | |
Intercom Intercom R&D Unlimited Company | Support | Customer support conversations and user-activity trackingContract duration + 12 months | United States (EU residency available) | Signed | Yes (under SCCs) | |
Fivetran Fivetran Inc. | ETL | ETL pipeline for data-warehouse sync (invoice metadata, supplier data — no financial details)Real-time processing, logs retained 90 days | United States (data in transit only) | Signed | Yes (under SCCs) | |
OpenAI OpenAI OpCo, LLC | AI | AI/NLP for document processing — descriptive text only30-day maximum retention | United States | Signed | Yes (under SCCs) | |
Mistral AI Mistral AI | AI | AI/NLP for document processing — descriptive text only — France-hosted30-day maximum retention | France | Signed | N/A — EU-hosted | |
Anthropic Anthropic PBC | AI | AI/NLP via Claude for document processing — descriptive text only90-day maximum retention | United States | Signed | Yes (under SCCs) |
Last reviewed:
Selection & audit
How we choose and audit sub-processors
Every sub-processor on this list passed a structured evaluation before Flowie engaged them, and each is reviewed at least once per year.
Selection criteria. Before onboarding any sub-processor, Flowie's security and legal teams assess: (1) security certifications — ISO 27001, SOC 2 Type II, and sector-specific frameworks such as SecNumCloud for infrastructure; (2) data location and the jurisdiction in which personal data will be processed or stored at rest; (3) GDPR compliance posture, including the sub-processor's own documentation of technical and organizational measures; and (4) contractual commitments — specifically, the sub-processor's willingness to sign a DPA with appropriate data protection clauses, and, for non-EU processors, to execute Standard Contractual Clauses in accordance with the EU Commission's 2021 decision.
Risk classification. We treat our sub-processors in three tiers. Infrastructure processors (GCP/S3NS) receive the highest scrutiny — they host the environment in which all data lives. Data processors (Auth0, SendGrid, Sentry, Intercom, Fivetran) process specific categories of personal or operational data and are scoped strictly to their stated purpose. AI processors (OpenAI, Mistral AI, Anthropic) warrant a separate evaluation track: we assess input minimization controls, retention caps, and — most critically — whether the vendor has committed contractually to zero retraining using client data. All three AI providers on this list have made that commitment in writing.
Annual review. Each year, Flowie's DPO re-verifies certifications, confirms DPAs remain current, and reviews any changes to sub-processor processing locations or ownership. If a review reveals a material gap, we suspend use of that processor until remediation is confirmed.
No new sub-processor is activated in production until a signed DPA and, where required, SCCs are in place.
30-day advance notice
Notification of changes
Flowie commits to notifying data controllers at least 30 days before any material change to this sub-processor list takes effect. A material change is defined as: adding a new sub-processor, replacing an existing sub-processor, or materially expanding the scope of data an existing sub-processor is permitted to process.
This commitment is reflected in the sub-processor annex of the Flowie DPA. If you have signed a DPA with Flowie, this page is the reference document that annex points to.
Minor changes — such as a sub-processor updating their data center from one facility to another within the same country, or a parent-company name change with no operational effect — do not trigger the 30-day notification requirement, but will be reflected in the "Last reviewed" date on the relevant table row.
Subscribe to change notifications. Data controllers and DPOs can opt in to receive email notification of material sub-processor changes before they take effect. We do not add contacts to this list without explicit opt-in, and you can unsubscribe at any time.
Buyers ask us this
Frequently asked questions
What data controllers and DPOs ask before signing or renewing their DPA.
Why these specific sub-processors?
Is my data sent outside the EU?
Do AI providers see our financial amounts or IBANs?
How are non-EU transfers legally protected?
How will I be told if a sub-processor changes?
Get signed or stay informed
Get your DPA signed or stay informed
Two paths from this page — both go through the same intake. Pick yours.
Request a signed DPA
We turn DPA countersignatures around as quickly as redlines allow.
⚠️ TO VALIDATE: confirm a public turnaround SLA with Legal if a specific commitment is desired.
Subscribe to sub-processor change notifications
Receive 30-day advance notice of any material change to this list.
⚠️ TO VALIDATE: confirm Legal-approved opt-in language for the subscription form.