Current subprocessors
- Hetzner Online GmbH
- PurposeProduction hosting, network, compute, local storage, PostgreSQL, Redis, and backups for the Kanvly application.
- DataAccount data, workspace content, logs, uploaded avatars, operational metadata, and backups.
- Location / notesGermany / European Union. Kanvly currently runs on self-managed infrastructure hosted with Hetzner.
- Stripe, Inc.
- PurposePayment processing, checkout, subscription management, invoices, tax calculation, and customer billing portal.
- DataBilling contact details, payment metadata, plan, seat count, transaction status, and payment identifiers.
- Location / notesUnited States and other Stripe processing locations. Kanvly does not store full card numbers. Stripe handles payment details.
- Apple Inc.
- PurposeApp Store distribution, in-app purchase processing, subscription management, receipts, refunds, and App Store account controls for iOS subscriptions.
- DataApp Store account and transaction metadata, subscription product identifiers, renewal status, refund status, and purchase verification details.
- Location / notesUnited States and other Apple processing locations. Apple processes App Store payments and manages App Store refunds and subscription settings.
- Amazon Web Services, Inc. / Amazon SES
- PurposeTransactional email delivery for password reset, account, billing, contact, and workspace invite messages.
- DataEmail address, message subject, message body, delivery metadata, and related operational metadata.
- Location / notesUnited States and other AWS processing locations. Used for email delivery, not for workspace storage.
- OpenAI, L.L.C.
- PurposeOptional Kanvly AI features and workspace copilot responses.
- DataUser prompts, selected chat history, and workspace context needed to answer an AI request.
- Location / notesUnited States and other OpenAI processing locations. Kanvly does not permit model training on customer data through Kanvly-controlled AI requests.
- Cloudflare, Inc.
- PurposeDNS, CDN, TLS termination, and edge protection in front of the Kanvly origin.
- DataRequest metadata for every request to the service — IP address, user agent, requested URL — and the request and response bodies passing through it.
- Location / notesGlobal edge network, including the European Union and the United States. Every request to Kanvly transits Cloudflare before it reaches the hosting provider.
- Google LLC
- PurposeGoogle Analytics on marketing pages where allowed by jurisdiction or after consent; Google OAuth when configured and selected by a user; two-way Google Calendar synchronisation and free/busy lookup for members who connect their Google account; Google Fonts for editor typefaces; and Google Play billing for Android subscriptions.
- DataAnalytics events and device/browser metadata; OAuth profile data for Google sign-in; calendar event titles, descriptions, times, attendees, and availability for connected calendars; the reader's IP address and browser metadata when the editor loads a font; and Play purchase and subscription metadata.
- Location / notesUnited States and other Google processing locations. Google Analytics is blocked until consent in consent-required jurisdictions, and the footer preference control remains available for opt-out. Calendar synchronisation happens only for a member who connects it and stops when they disconnect. Editor fonts are requested by the reader's browser directly from Google.
- Telegram FZ-LLC
- PurposeDelivery of contact-form and bug-report messages to the Kanvly team, and operational alerting.
- DataName, email address, message text, and any screenshot attached to a bug report; plus operational alert text.
- Location / notesOutside the European Union. Used as an internal delivery channel for messages people send to Kanvly, not for workspace storage.
- Slack Technologies, LLC
- PurposeThe Slack integration: notifications, digests, and the @Kanvly assistant, for workspaces that connect it.
- DataCard and page titles, notification and digest text, assistant questions and answers, and Slack workspace and user identifiers.
- Location / notesUnited States and other Slack processing locations. Applies only to a workspace that has connected Slack, and stops when the connection is removed.
- Have I Been Pwned (Superlative Enterprises Pty Ltd)
- PurposeChecking a chosen password against known breach corpora during sign-up and password change.
- DataThe first five hexadecimal characters of the SHA-1 hash of the password, and nothing else.
- Location / notesCloudflare edge network. A k-anonymity range query: the password never leaves Kanvly, the full hash never leaves Kanvly, and the service cannot tell which of the returned hashes was being checked.
- AppSumo (Sumo Group Inc.)
- PurposeValidation and status of a redeemed AppSumo lifetime licence.
- DataLicence key, redemption status, and the associated account email.
- Location / notesUnited States. Contacted only when someone redeems an AppSumo code. Not enabled on the current deployment.
- GitHub, Inc.
- PurposeGitHub OAuth sign-in when configured and selected by a user.
- DataGitHub account identifier, verified email, display name, and OAuth authentication metadata.
- Location / notesUnited States and other GitHub processing locations. Only used when the GitHub sign-in option is enabled and selected.
- OIDC identity provider (single sign-on)
- PurposeSingle sign-on through the OIDC issuer configured for this deployment.
- DataOIDC identifier, verified email, display name, and authentication metadata.
- Location / notesDepends on the configured issuer. One issuer is configured per deployment, not per customer or per workspace. No issuer is configured on the current deployment, so this route is inactive.
| Provider | Purpose | Data | Location / notes |
|---|---|---|---|
| Hetzner Online GmbH | Production hosting, network, compute, local storage, PostgreSQL, Redis, and backups for the Kanvly application. | Account data, workspace content, logs, uploaded avatars, operational metadata, and backups. | Germany / European Union. Kanvly currently runs on self-managed infrastructure hosted with Hetzner. |
| Stripe, Inc. | Payment processing, checkout, subscription management, invoices, tax calculation, and customer billing portal. | Billing contact details, payment metadata, plan, seat count, transaction status, and payment identifiers. | United States and other Stripe processing locations. Kanvly does not store full card numbers. Stripe handles payment details. |
| Apple Inc. | App Store distribution, in-app purchase processing, subscription management, receipts, refunds, and App Store account controls for iOS subscriptions. | App Store account and transaction metadata, subscription product identifiers, renewal status, refund status, and purchase verification details. | United States and other Apple processing locations. Apple processes App Store payments and manages App Store refunds and subscription settings. |
| Amazon Web Services, Inc. / Amazon SES | Transactional email delivery for password reset, account, billing, contact, and workspace invite messages. | Email address, message subject, message body, delivery metadata, and related operational metadata. | United States and other AWS processing locations. Used for email delivery, not for workspace storage. |
| OpenAI, L.L.C. | Optional Kanvly AI features and workspace copilot responses. | User prompts, selected chat history, and workspace context needed to answer an AI request. | United States and other OpenAI processing locations. Kanvly does not permit model training on customer data through Kanvly-controlled AI requests. |
| Cloudflare, Inc. | DNS, CDN, TLS termination, and edge protection in front of the Kanvly origin. | Request metadata for every request to the service — IP address, user agent, requested URL — and the request and response bodies passing through it. | Global edge network, including the European Union and the United States. Every request to Kanvly transits Cloudflare before it reaches the hosting provider. |
| Google LLC | Google Analytics on marketing pages where allowed by jurisdiction or after consent; Google OAuth when configured and selected by a user; two-way Google Calendar synchronisation and free/busy lookup for members who connect their Google account; Google Fonts for editor typefaces; and Google Play billing for Android subscriptions. | Analytics events and device/browser metadata; OAuth profile data for Google sign-in; calendar event titles, descriptions, times, attendees, and availability for connected calendars; the reader's IP address and browser metadata when the editor loads a font; and Play purchase and subscription metadata. | United States and other Google processing locations. Google Analytics is blocked until consent in consent-required jurisdictions, and the footer preference control remains available for opt-out. Calendar synchronisation happens only for a member who connects it and stops when they disconnect. Editor fonts are requested by the reader's browser directly from Google. |
| Telegram FZ-LLC | Delivery of contact-form and bug-report messages to the Kanvly team, and operational alerting. | Name, email address, message text, and any screenshot attached to a bug report; plus operational alert text. | Outside the European Union. Used as an internal delivery channel for messages people send to Kanvly, not for workspace storage. |
| Slack Technologies, LLC | The Slack integration: notifications, digests, and the @Kanvly assistant, for workspaces that connect it. | Card and page titles, notification and digest text, assistant questions and answers, and Slack workspace and user identifiers. | United States and other Slack processing locations. Applies only to a workspace that has connected Slack, and stops when the connection is removed. |
| Have I Been Pwned (Superlative Enterprises Pty Ltd) | Checking a chosen password against known breach corpora during sign-up and password change. | The first five hexadecimal characters of the SHA-1 hash of the password, and nothing else. | Cloudflare edge network. A k-anonymity range query: the password never leaves Kanvly, the full hash never leaves Kanvly, and the service cannot tell which of the returned hashes was being checked. |
| AppSumo (Sumo Group Inc.) | Validation and status of a redeemed AppSumo lifetime licence. | Licence key, redemption status, and the associated account email. | United States. Contacted only when someone redeems an AppSumo code. Not enabled on the current deployment. |
| GitHub, Inc. | GitHub OAuth sign-in when configured and selected by a user. | GitHub account identifier, verified email, display name, and OAuth authentication metadata. | United States and other GitHub processing locations. Only used when the GitHub sign-in option is enabled and selected. |
| OIDC identity provider (single sign-on) | Single sign-on through the OIDC issuer configured for this deployment. | OIDC identifier, verified email, display name, and authentication metadata. | Depends on the configured issuer. One issuer is configured per deployment, not per customer or per workspace. No issuer is configured on the current deployment, so this route is inactive. |
Self-hosted services
PostgreSQL, Redis, application runtime, local upload storage, and operational backups currently run on Kanvly-controlled infrastructure hosted with Hetzner Online GmbH in Germany. Those self-hosted components are not separate subprocessors beyond the hosting provider.
Changes and objections
Kanvly may update subprocessors as the product changes. If a new subprocessor materially changes how customer personal data is processed, Kanvly will update this page and take reasonable steps to notify affected customers where required. Customers may object through Kanvly supportwith a reasonable data protection basis.