The providers that process data on Plentia's behalf: what each one does, which data it sees, where and under which safeguard.
Draft pending legal review. It was written by the person who builds Plentia, who is not a lawyer, from each provider’s official legal pages and from what the code actually does. A lawyer will review it before the first customer is charged.
Last updated: 26/09/2026
A subprocessor is a provider that processes personal data on Plentia’s behalf so that the service works. They are all listed here, with what each one does, which data it handles, where it processes it and, if the data leaves the European Economic Area (EEA), the safeguard used.
Every item in the table comes from the provider’s official legal page, consulted on 26/09/2026. Where we could not check something, we say so: it reads “not verified”.
Plentia can read the photo or PDF of an expense invoice and fill in the fields for you. This feature is built and is switched off today. When it is switched on, the file takes this route:
What Anthropic says about that data, on its official pages consulted on 26/09/2026:
We have not been able to verify where Anthropic processes those requests, so we do not state it.
In the public demo, before your invoice is sent, Cloudflare Turnstile checks that you are not a bot. Of your IP address, Plentia keeps only a salted, hashed fingerprint, to limit scans per day, and deletes it after 2 days.
| Provider | What it does for Plentia | Which data | Where | Safeguard if data leaves the EEA | Status |
|---|---|---|---|---|---|
| Supabase (Supabase Pte. Ltd, Singapore) | Database, account sign-in and file storage (receipts and logos). | Everything Plentia stores: account, tax details, invoices, expenses, orders, customers and suppliers, files. | The project data is in the eu-west-1 region, Ireland (EU). The company is in Singapore and uses its own subprocessors, some outside the EU. |
Standard contractual clauses (Decision 2021/914, module two). Supabase is not in the EU-US Data Privacy Framework. | In use. |
| Cloudflare (Cloudflare, Inc., USA) | Serves the website and dashboard and runs the API. Every request passes through it. | Visitors’ IP address and connection data, and the content of requests: sessions, orders arriving from shops and files sent for reading. | Cloudflare’s global network. Whether Plentia’s plan limits the region: not verified. | EU-US Data Privacy Framework (status on 26/09/2026: “Active - Re-certification under Review”) and standard contractual clauses provided for in its agreement. | In use. |
| Cloudflare Turnstile (Cloudflare, Inc.) | Checks that you are not a bot before reading your own invoice in the demo. | IP address, TLS fingerprint, browser (User-Agent) and site key. | Cloudflare’s global network. | As for Cloudflare. | Ready and switched off. |
| Resend (Plus Five Five, Inc., USA) | Sends sign-in emails (account confirmation, codes, password reset) on behalf of Supabase’s sign-in service. | Your email address and the content of the email. | USA. Its agreement says its primary processing takes place there. | EU-US Data Privacy Framework (status on 26/09/2026: “Active - Re-certification under Review”) and standard contractual clauses attached to its agreement. | In use. |
| Identifies you when you choose “Sign in with Google”. | The details of your Google account shared at sign-in (at least your email). | Not verified. | Google LLC is in the EU-US Data Privacy Framework (status “Active” on 26/09/2026). Whether Google acts here as Plentia’s processor or as an independent controller: not verified. | In use, only if you choose to sign in with Google. | |
| Stripe (Stripe Payments Europe, Limited) | Charges the subscription and lets you manage it. | The account’s email, legal name and tax ID. Payment details are collected by Stripe directly; Plentia never sees your card. | Not verified. | Stripe, LLC is in the EU-US Data Privacy Framework (status “Active” on 26/09/2026). Its agreement also provides standard contractual clauses. It distinguishes the purposes for which Stripe acts as a processor from those for which it acts as an independent controller. | Integrated. Billing is switched off: no data is sent to it today. |
| Anthropic (Anthropic Ireland, Limited) | Reads the photo or PDF of an expense invoice and returns its fields. | Whatever is on the invoice: for example, the supplier’s name and tax ID, and your own details. | Not verified. | Standard contractual clauses (Decision 2021/914, modules two and three). Anthropic is not in the EU-US Data Privacy Framework. According to Anthropic, it deletes what it receives through its API within 30 days and does not use it to train its models. | Built and switched off. |
The safeguards are explained in the privacy policy. The EU-US Data Privacy Framework was checked on its official list on 26/09/2026.
Shopify, WooCommerce and advertising platforms are your services. You connect them so that Plentia can read their data, under your own contract with each of them. Today the connections to advertising platforms are switched off.
You connect the Claude connector in your own Claude account. The data it requests goes to Anthropic under your contract with them, not ours.
Sending Verifactu records to the Spanish Tax Agency (Agencia Tributaria) is not active today, and no provider has been engaged for it. If one is engaged, it will appear on this list before it is used.
Under the data processing agreement you give us a general authorisation to use subprocessors. In return:
Legal basis: GDPR, arts. 28.2 and 28.3.d. The Spanish Data Protection Agency’s guidelines on processing contracts (in Spanish) accept a specific or a general authorisation.