Subprocessors
This page lists third-party providers that Accordix uses to process personal data on behalf of Customers. It forms part of the Data Processing Agreement.
Customers provide general authorisation for the subprocessors listed here. Accordix will give Customer administrators at least 30 days' notice, by email or another durable method where reasonably practicable, before a new subprocessor begins materially processing Customer Personal Data. A Customer may object during that period on reasonable data-protection grounds.
Current subprocessors
| Provider | Purpose | Data processed | Location / region | Safeguards and notes | Status |
|---|---|---|---|---|---|
| Render Services, Inc. | Application hosting, managed PostgreSQL, persistent file storage, infrastructure operation and backups | Account data, workspace metadata, Customer Content and uploaded files | Primary Accordix deployment intended for Frankfurt, Germany; provider is US-headquartered | Render data processing terms and applicable transfer safeguards, including Standard Contractual Clauses where required. Provider-managed backup lifecycle depends on the applicable service and plan. | Active |
| CloudMailin | Outbound transactional email and inbound document intake by email | Recipient and sender addresses, message metadata, limited reminder content, message body where supplied, and inbound attachments | Provider-operated infrastructure; exact processing and support locations may vary | Provider contractual terms and applicable transfer safeguards must be reviewed for the account in use. Customers should avoid sending unnecessary sensitive content in email subjects or bodies. | Active |
| Meta Platforms Ireland Limited / WhatsApp Business Platform | Inbound document and message intake through WhatsApp | Sender phone number, platform/profile metadata made available by WhatsApp, message content, timestamps and attachments | EU contracting entity; Meta infrastructure and support may involve processing outside the EU/EEA | Meta data processing terms and applicable transfer safeguards, including Standard Contractual Clauses where required. WhatsApp is used only for Customers assigned to or using an enabled intake channel. | Active where used |
| Google Cloud EMEA Limited / Google Cloud Vertex AI (Gemini) | AI-assisted extraction from invoices; AI-assisted extraction of bank-statement fields and transactions; suggestions of potentially missing linked documents | The complete document file submitted for analysis and the prompt/instruction; documents may include names, addresses, company and tax identifiers, account numbers, IBANs, transaction descriptions, amounts, dates, references and other financial or personal data | Vertex AI requests configured to the Google Cloud eu multi-region |
Google Cloud Data Processing Addendum and applicable transfer safeguards. Google states that Customer Data is not used to train or fine-tune models without permission or instruction. Limited technical retention, caching, abuse-monitoring processing or global support access may apply according to service, model and configuration. Zero retention is not promised unless separately verified. | Active where AI processing is used |
Operational notes
- Invoice recognition, bank-statement recognition and linked-document detection are distinct Vertex AI processing activities. They may send the complete uploaded file to Google Cloud.
- AI output is assistive, may be inaccurate and must be reviewed by an authorised person. It is not used by Accordix to make legal or similarly significant decisions about individuals.
- WhatsApp availability in the deployment does not mean every Customer uses it. Processing occurs when a Customer has and uses an enabled intake channel.
- Reminder emails are designed to avoid document contents and normally contain only workflow information needed to request a document.
- Accordix currently does not use third-party advertising trackers, a payment provider, a separate object-storage provider or a third-party customer-support platform.
Provider verification
Accordix periodically verifies the contracting entity, applicable data processing terms, processing locations, transfer mechanism, retention configuration and security documentation for each active provider. Public statements on this page describe the intended production configuration and do not replace the provider's binding terms.
Questions: privacy@accordix.sk.