Legal

Sub-processors

Last updated: September 5, 2026

A sub-processor is a third party we engage to process personal data on your behalf while providing the Space Invoices service. This list is part of our Data Processing Agreement. Sub-processors that apply to every customer are listed first. Sub-processors that we engage only when you enable a feature are listed separately.

We give at least 30 days' notice of additions or replacements by updating this page and emailing account owners. To receive change notices at another address, email privacy@spaceinvoices.com with the subject "Sub-processor notifications".

Core sub-processors (all customers)

These providers are part of the Service for every account.

EntityPurposeLocationTransfer mechanism
Hetzner Online GmbHHosting, application infrastructure, database, object storage, and encrypted database backupsGermany (Nuremberg)EU processing under Hetzner's data processing agreement
Amazon Web Services EMEA SARLTransactional email through Amazon SES: recipient address, message content, and attachments when you send an emaileu-central-1 (Frankfurt)EEA processing under AWS data processing terms
Cloudflare, Inc.Application delivery and edge security: request metadata needed to serve the applicationGlobal network; some processing outside the EEACloudflare data processing addendum with EU Standard Contractual Clauses
PostHog Inc. (EU cloud)Product usage analytics: pseudonymous account and user identifiers, event names, and page and click metadata captured automatically; session replay with form inputs masked. On-screen text, which can include names shown on invoices, may be captured in replays until replay is disabledEU (Frankfurt)EEA processing under PostHog's data processing agreement
Functional Software, Inc. (Sentry)Error monitoring: technical error data with personal data removed before transmission; pseudonymous identifiers onlyUnited StatesSentry data processing addendum with EU Standard Contractual Clauses
Mistral AIAutomated abuse review of outgoing document emails before they are sent, on free and trial accounts only: the email subject and body with the known name and email address of the recipient and recognisable identifiers (email addresses, phone numbers, bank and tax numbers) removed (other personal data written into the free text may remain), and a short summary of the document (document number, issuer, totals, payment terms, and line-item names)European Union (France)EEA processing under Mistral AI's data processing agreement
Slack Technologies, LLCOperational alerts on fiscalization and e-invoicing failures containing the entity name, document identifiers, and error text; partner support channels with the account name and invited email addressesUnited StatesSlack data processing addendum with EU Standard Contractual Clauses

Feature-dependent sub-processors (only when you enable the feature)

These providers receive personal data only when you use the named feature. Peppol recipient lookups send the recipient identifier you supply; full e-invoice delivery applies only to enrolled entities.

EntityFeaturePurposeLocationTransfer mechanism
RecommandPeppol e-invoicingPeppol access point: Peppol recipient lookups (the recipient identifier you supply) and, for enrolled entities, full e-invoice delivery (issuer, recipient, line items)European UnionEEA processing under Recommand's data processing agreement
SuperPDPFrench e-invoicingFrench registered e-invoicing platform (PDP): the full e-invoice content and lifecycle and payment status reports for French entities enrolled for e-invoicingFrance (EU)EEA processing under SuperPDP's data processing agreement
Mistral AIExpense scanningDocument OCR for expense recognition when the feature is enabled and configured for your account: the uploaded supplier invoice or receipt, including supplier name, address, tax number, bank details, and line itemsEuropean Union (France)EEA processing under Mistral AI's data processing agreement

Tax authorities and other recipients under your instruction

When you enable fiscalization or e-invoicing, or connect an integration, we send data to the recipient you choose. Tax authorities, Peppol recipients, banks, and integrations you connect (for example Stripe or Shopify) act as independent controllers or on your instruction. They are not our sub-processors.

RecipientFeatureData sent
Financial Administration of the Republic of Slovenia (FURS)Slovenian fiscalizationFiscal verification of invoices: invoice identifiers, amounts, taxes, and issuer, customer, and operator tax identifiers for entities with Slovenian fiscalization enabled
Croatian Tax Administration (Porezna uprava) via FINA CISCroatian fiscalizationFiscal verification of invoices: invoice identifiers, amounts, taxes, and issuer, customer, and operator tax identifiers for entities with Croatian fiscalization enabled
European Commission VIES serviceVAT number validationThe VAT identifiers you validate (your own and your customers')

Account-data service providers

These providers handle your own account data (login, billing, support), for which we are the controller as described in the Privacy Policy. They are listed for transparency.

  • Stripe — Subscription billing for your Space Invoices account; card details go directly to Stripe
  • Hal — Support chat and in-app messaging; receives your user id, email, name, account name, and plan
  • Damper — Roadmap and feedback; receives your user id, email, and plan
  • Braintree (PayPal) — White-label subscription activation; receives company name and email
  • Google and Apple — Sign-in with Google or Apple, when you choose it; receives your sign-in identity

Changes

  • 2026-09-05 — list first published.