Skip to main content
Alleex Cloud

Alleex Cloud · Legal

Subprocessors

⚠ PENDING LAWYER REVIEW — not legal advice

This page is a structural scaffold. It has not been reviewed by qualified EU/GDPR counsel and is notlaunch-ready. No paying customer may onboard until a lawyer has reviewed and approved this document (binding pre-launch gate).

Provenance: Auto-generated from the Alleex Cloud platform provider inventory (ADR-0001 stack). Single source of truth; updated whenever a provider is added.

GDPR Art. 28(2). This is the Alleex Cloud platformlist. A customer app's subprocessors vary by installed modules and are published per-app in that app's generated privacy policy.

SubprocessorRoleJurisdictionPersonal dataTransfer
NeonDatabase (control-plane + per-tenant app DB, EU-Frankfurt)US entity · EU data regionYesSCCs
CloudflareCustomer-app edge hosting + R2 storage (EU)US entity · EU WorkersYesSCCs + EU Workers
VercelBuilder/control-plane hostingUSYesSCCs
ClerkBuilder dashboard auth (NOT customer-app users)USYesSCCs
Polar.shMerchant of record — Alleex Cloud subscription billing + EU VATEU-established MoRYesNo SCC required
AnthropicLLM inference (build-time only; BYO-key removes this)USNoSCCs
ResendTransactional email (EU region)US entity · EU regionYesSCCs
PostHogProduct analytics (EU Cloud, consent-gated)EUYesEU-hosted — no transfer
SentryError monitoringUSYesSCCs
Better StackUptime monitoring / logsEU/USYesSCCs where applicable
Trigger.devBackground job orchestrationUS/EUYesSCCs
InfisicalSecrets managementUS (self-hostable)NoSCCs; self-host removes transfer
GitHubSource code, CIUS (Microsoft)NoSCCs
Sigstore / RekorAudit-chain transparency witness (SHA-256 hashes only)Public log (Linux Foundation)NoN/A — hashes only

This document is information about Alleex Cloud's technical and organisational measures, not legal advice. Consult your DPO or legal counsel for your specific obligations.