Legal

Sub-processors

The third-party providers that may process Customer Personal Data on behalf of Native Keeper.

Last updated: 10 June 2026 · Version 1.0

About this page

Native Keeper is a service operated by NeonStack Ltd (company number 16933096, registered in England and Wales). To deliver our service reliably, securely, and at scale, we rely on a small number of carefully selected third-party providers who may Process Customer Personal Data on our behalf. These are our "Sub-processors".

This page gives customers transparency about who those providers are, where they operate, what they do, and how international data transfers are safeguarded. Our use of Sub-processors is governed by our Data Processing Agreement (DPA).

Because Native Keeper is an HR and workforce compliance platform, our customers routinely hold sensitive employee data — including, where lawful, Special Category Personal Data and Criminal-Offence Data. We select and manage Sub-processors with that sensitivity in mind.

For questions about a specific Sub-processor or to subscribe to change notifications, contact legal@nativekeeper.com.

How we choose Sub-processors

Before engaging any Sub-processor that may Process Customer Personal Data, we:

  • Assess their security posture, including certifications, encryption practices, and incident response capabilities.
  • Verify their data-protection commitments, including their DPA, privacy notice, and data-transfer mechanisms.
  • Enter into a binding written agreement imposing data-protection obligations no less protective than those in our DPA.
  • Document the purpose and scope of the data they process on our behalf.
  • Assess suitability for HR-sensitive data, health data, and criminal-offence data where relevant.
  • Periodically review their continued compliance and suitability.

Current Sub-processors

The tables below list all Sub-processors currently engaged by Native Keeper that may Process Customer Personal Data.

Core Infrastructure

Sub-processorPurposeData processedLocation of processingTransfer mechanism
Vercel Inc.Application hosting, edge network, deployment platformAll Customer Personal Data in transit; cached content on the edge for authenticated pages is not persistedUnited States (primary); global edge networkEU Standard Contractual Clauses; EU-US Data Privacy Framework certified
Supabase Inc.Primary database, authentication, encrypted file storage for uploaded documents (including sensitive HR documents such as DBS certificates and Right to Work evidence)All Customer Personal Data at rest, including workforce records, uploaded documents, and account dataEU (Frankfurt) for EU customers; United States for others; UK region available on supported plansEU Standard Contractual Clauses; UK IDTA
Cloudflare, Inc.CDN, DDoS protection, web application firewall (WAF), DNSNetwork metadata, IP addresses, requests in transitGlobal edge network; processing in country of nearest edgeEU Standard Contractual Clauses; UK IDTA; EU-US Data Privacy Framework certified

Payments and Billing

Sub-processorPurposeData processedLocation of processingTransfer mechanism
Stripe Payments Europe, Ltd. / Stripe, Inc.Subscription billing, payment processing, invoicingAccount-holder name, email, billing address, payment card data (handled directly by Stripe; we do not store card details). No workforce records or employee data are shared with Stripe.Ireland (EU); United StatesEU Standard Contractual Clauses; EU-US Data Privacy Framework certified

Communications

Sub-processorPurposeData processedLocation of processingTransfer mechanism
Resend, Inc.Transactional email delivery — including account emails, password resets, and compliance-expiry notifications sent to Admin Users designated by the CustomerRecipient email addresses (Admin Users) and email content (which includes summary information about upcoming expiries but not full workforce records)United States; EU region availableEU Standard Contractual Clauses; EU-US Data Privacy Framework certified

Observability and Support

Sub-processorPurposeData processedLocation of processingTransfer mechanism
Functional Software, Inc. (Sentry)Application error monitoring and performance diagnosticsTechnical telemetry, error stack traces, session metadata. Personally identifiable information is scrubbed before transmission where technically feasible. Workforce record content is not sent to Sentry.United StatesEU Standard Contractual Clauses; EU-US Data Privacy Framework certified
PostHog Inc.Product analytics and feature usage telemetry — collected only from account-holder interactions with the Service (Admin Users), not from Data Subjects whose records are held in the ServiceAccount-holder behaviour: page views, feature usage, session activity. No workforce record content or Data Subject personal data is sent to PostHog.EU (Frankfurt) region available; United StatesEU Standard Contractual Clauses; UK IDTA
Crisp IM SASCustomer support live chat and helpdeskSupport conversations, contact details of Admin Users who initiate support requests. Workforce records are not sent to Crisp.France (EU)Data Processed within the EEA; no third-country transfer

Important clarifications

What we do NOT do with workforce data

  • We do not use employee data for training AI models — neither our own nor any third party's. See DPA Section 9.
  • We do not enrich, profile, or cross-reference Data Subjects across Customer accounts.
  • We do not share workforce data with Sub-processors that are not listed here.
  • We do not sell or license Customer Personal Data to any third party.

Internal tools that are NOT Sub-processors

We use various tools internally, such as accounting, project management, and internal HR tooling, that do not Process Customer Personal Data. These are not Sub-processors under GDPR Art. 28 and are therefore not listed here.

Regional Data Residency

If you require Customer Personal Data to be stored exclusively within the EEA, the UK, or another supported region, contact legal@nativekeeper.com. Regional data residency is available on supported plans.

Notification of changes

We will provide at least 30 days' prior notice before adding or replacing any Sub-processor that Processes Customer Personal Data. Notice will be provided by updating this page with the proposed change and planned effective date, emailing subscribed customers, and updating this page once the change takes effect.

If you object to a new Sub-processor on reasonable data-protection grounds, follow the objection process in Section 6.3 of our DPA within the 30-day notice period.

Subscribe to change notifications

To receive email notifications when this list changes, email legal@nativekeeper.com with the subject "Subscribe — Sub-processor updates" and the email address you would like us to use. Subscribers can unsubscribe at any time by replying to a notification email.

Contact

Email: legal@nativekeeper.com

Postal address: NeonStack Ltd, The North Colchester Business Centre, 340 The Crescent, Colchester, England, CO4 9AD