Privacy
Subprocessors
Spot Cloud B.V. processes your data on your behalf. These are the outside companies that handle part of it, what each one receives, for which product, and where.
Checked against our code and live configuration on .
Current list
| Vendor | What it does | What it receives | Products | Where |
|---|---|---|---|---|
| Cloudflare | Hosts every product and this website: compute, D1 databases, R2 file storage, key-value storage, live chat, logs, the bot check at signup, and Workers AI as the backup chat model. | Everything stored in the products, and every request your browser sends. | All products and spot-suite.com | Databases and files in Western Europe. Compute, live chat and logs run on Cloudflare’s global network, close to each visitor. |
| Supabase | Postgres databases. Supabase runs them on Amazon Web Services. | The users and records you keep in these products. | xEvolve, Cloud Horizons, Automate Certificates, Guardrail Ledger, ClearScreen | Paris or Frankfurt. A Guardrail Ledger workspace outside the EU uses the region picked at signup. |
| Microsoft 365 | Sends our email through Microsoft Graph: sign-in codes, invitations and product notifications. | Recipient name and email address, and the message. | Spot Suite accounts, xEvolve, Automate Certificates | Not pinned by us |
| Microsoft Azure | Hosts your workspace when you buy through Azure Marketplace: database, file storage, app and key vault. | Everything stored in that workspace, and the Marketplace purchase details. | Any product bought through Azure Marketplace | North Europe (Ireland), unless the buyer picks West Europe or a US region at purchase. |
| Stripe | Card payments, subscriptions and invoices. | Email address, billing address, VAT number, the plan you buy, and your card details, which you type on Stripe’s own checkout page. | Card purchases on spot-suite.com, for every product | Not pinned by us |
| xAI | Writes the replies in our help chat with its Grok model, through a relay we run. If it does not answer in time, Workers AI on Cloudflare replies instead. | The conversation, the site and page you are on, and your email address if you gave it. | Help chat | Not pinned by us |
| Linear | Our issue tracker. When a chat question turns out to be a bug, the chat files a ticket here. | The last ten chat messages, the page address, and your email address if you gave it. | Help chat | Not pinned by us |
| Telegram | Tells our team when a new trial or paid workspace starts. | Company name (or email address when no company is given), product, plan, price and workspace address. | New signups for every product | Not pinned by us |
| abuse.ch (MalwareBazaar) | Checks each file uploaded to xEvolve against its database of known malware. | The file’s SHA-256 fingerprint. The file itself stays in xEvolve. | xEvolve | Not pinned by us |
| MailChannels | Fallback sender for xEvolve notification emails when a workspace has no mail server of its own. | Recipient email address and the message. | xEvolve | Not pinned by us |
| crt.sh, Cert Spotter | Certificate Transparency search, used to find and watch the certificates issued for your domains. | The domain names you ask Automate Certificates to discover or monitor. | Automate Certificates | Not pinned by us |
| Google Fonts | Serves the typefaces on our sign-in and account pages, in the xEvolve, Cloud Horizons and Automate Certificates apps, and in our emails. | Your IP address and browser details, when your browser or mail app loads a font. | Spot Suite accounts, xEvolve, Cloud Horizons, Automate Certificates | Not pinned by us |
“Not pinned by us” means we have not fixed a region with that vendor. The vendor decides where it processes the data, and that can be outside the EU.
Services you connect
Some products work with services you bring yourself: your Microsoft 365, Entra or Intune tenant, your cloud accounts at Azure, AWS or Google Cloud, your DNS provider, your own mail server, and the certificate authority you pick in Automate Certificates, such as Let’s Encrypt. Our products call them on your instructions. You hold your own agreement with each, so they are not on this list.
Products not open yet
Spot IPAM, OpsDesk and InsureGuard are closed for signup and hold no customer data. They run on Cloudflare. We will check this list again before they open.
Changes to this list
We update this page when we add or replace a vendor. Customers hear about a new subprocessor before it starts and can object, as the DPA sets out. Read the DPA
Questions about this list: hello@spot-suite.com