Trust

Subprocessors

Third parties Sembr uses to operate the platform. Each one is contractually required to meet our privacy and security standards.

Last updated: August 2026.

Current subprocessors

These are the third parties that process customer data on Sembr's behalf.

Subprocessor Purpose Region Data processed
DigitalOcean App hosting, Managed Postgres database, and file storage (Spaces) for member uploads, export bundles and their backup copy Toronto, Canada (TOR1) All structured tenant data, plus files that may hold any category of personal data
Stripe Payment processing via Stripe Connect Global (US/EU) Payment method tokens, transaction metadata
Cloudflare CDN + edge security (WAF, bot protection) Global Cached static assets, request metadata, IP addresses
Resend Transactional email US Recipient email addresses, message content
Anthropic AI content generation (Claude API) US Staff-submitted text, and organization data with member identities replaced by opaque tokens before sending. Member records are not sent from the database. Per-member opt-out.
Sentry Error monitoring US Application errors (no PII in payloads)
Better Stack Uptime + log monitoring EU URL health checks, operational telemetry (no member records)

Data-processing agreements (with Standard Contractual Clauses where applicable) are being formalized with each subprocessor ahead of public launch.

Tools we run on our own infrastructure

These run as software on Sembr's own servers (DigitalOcean, Toronto) rather than as third-party services. Your data does not leave Sembr's infrastructure to reach them, so they are not third-party subprocessors. We list them for full transparency.

Tool Purpose
n8n Internal operations automation
Redis Caching + background job queue
Libredesk Support helpdesk (support conversations)
fail2ban Host intrusion prevention

Our public marketing website (this site) is hosted in Canada by WHC and loads web fonts from Google Fonts; neither processes member data.

Notification policy

Sembr provides 30 days notice before adding or changing a subprocessor. Customers can subscribe to changes using the contact link in the footer with the subject line "subprocessor updates."

What we don't do

  • No data sold or shared with advertising platforms. We have no ads, no tracking pixels, no data brokers.
  • No SaaS analytics that ship PII. No Mixpanel, Amplitude, FullStory, etc.
  • No data warehouses fed from production. Internal analytics use anonymized aggregates only.

The full policy

We are drafting the full subprocessor policy with privacy counsel ahead of public launch. For specifics today, use the contact link in the footer.

← Back to home

Full transparency on data flows.

Every third party, every region, every purpose.