Legal

Sub-processor List

Last updated 3 August 2026

This document is a draft pending legal review. Values shown in dashed brackets are placeholders that have not been filled in yet.

What counts as a sub-processor here

A sub-processor is a third party Statio contracts that may process customer personal data on Statio's instruction. It is NOT:

  • The customer's own tools. When Statio calls Exact Online, e-Boekhouden, Jortt, Moneybird, Mollie, Shopify, WooCommerce, bol.com, Gmail or Microsoft Graph, it does so with credentials the customer supplied, against the customer's own account, on the customer's instruction. Those providers are the customer's processors, not Statio's. They are listed separately in Annex B2 of the DPA as "customer-directed integrations" for transparency.
  • Public reference lookups. VIES (European Commission) and KVK (Dutch business register) receive a counterparty VAT/KVK number — business-register identifiers, not the customer's own personal data. ECB receives nothing (FX rate pull only).

Annex B1 — Statio's sub-processors

#Sub-processorLegal entity / locationPurposeData it can seeTransfer basis
1UpCloudUpCloud Ltd (Finland); processing region: Netherlands (nl-ams1)All hosting: Managed Kubernetes, PostgreSQL, object storage (backups, desktop release assets, transient attachments)Everything stored by Statio — account data, org data, extracted document fields, database backupsEU/EEA — no transfer
2Mistral AIMistral AI SAS (France)All LLM inference — chat, classification, extraction, translation, draftingWhatever the customer or an automation sends into a prompt: message text, document/email content being extracted, org contextEU/EEA — no transfer
3StripeStripe Payments Europe Ltd (Ireland), with Stripe Inc. (US) as onward processorSubscription billing, payment processing, invoicingBilling contact, company name, VAT ID, payment method, subscription state. Not customer business contentEU entity; SCCs cover the US onward transfer (Stripe's own DPA)
4ResendResend, Inc. (United States)Outbound transactional email — reports, invitations, weekly briefing, notificationsRecipient email address, recipient name, and the report/briefing body (which may contain extracted financial figures)US — Standard Contractual Clauses + a transfer impact assessment
5GitLabGitLab Inc. (United States)Source control and CI/CD onlyNo customer data. Build artefacts and secrets, never production dataUS — no customer personal data flows here, so no transfer mechanism needed

Conditionally active — not currently a sub-processor

Sub-processorStatusTrigger that would activate it
SentryDependency present, currently inert. @sentry/react initialises only if VITE_SENTRY_DSN is set, and no DSN is configured today (apps/statio-desktop/src/main.tsx:8). @sentry/nextjs is in statio-web's dependencies with no init call.The moment a DSN is configured, Sentry becomes a live sub-processor receiving error payloads that can contain user context. Add it to Annex B1 before setting the DSN, not after.

Annex B2 — Customer-directed integrations (for transparency, not sub-processors)

Statio connects to these only when the customer enables the corresponding Statio App and supplies their own credentials. Statio is acting on the customer's documented instruction; the customer's relationship is with the provider.

Accounting: Exact Online, e-Boekhouden, Jortt, Moneybird, Twinfield (unlisted). Mail & calendar: Google (Gmail, Calendar), Microsoft 365 (Graph). Payments: Mollie. E-commerce: Shopify, WooCommerce, bol.com. Business registers (lookup only): VIES / European Commission, KVK. Reference data (no personal data sent): European Central Bank FX rates.

Change log

DateChange
2026-08-03Initial draft compiled from the codebase. Not yet lawyer-reviewed, not yet published.