Sub-processors
Last updated: September 5, 2026
A sub-processor is a third party we engage to process personal data on your behalf while providing the Space Invoices service. This list is part of our Data Processing Agreement. Sub-processors that apply to every customer are listed first. Sub-processors that we engage only when you enable a feature are listed separately.
We give at least 30 days' notice of additions or replacements by updating this page and emailing account owners. To receive change notices at another address, email privacy@spaceinvoices.com with the subject "Sub-processor notifications".
Core sub-processors (all customers)
These providers are part of the Service for every account.
| Entity | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Hosting, application infrastructure, database, object storage, and encrypted database backups | Germany (Nuremberg) | EU processing under Hetzner's data processing agreement |
| Amazon Web Services EMEA SARL | Transactional email through Amazon SES: recipient address, message content, and attachments when you send an email | eu-central-1 (Frankfurt) | EEA processing under AWS data processing terms |
| Cloudflare, Inc. | Application delivery and edge security: request metadata needed to serve the application | Global network; some processing outside the EEA | Cloudflare data processing addendum with EU Standard Contractual Clauses |
| PostHog Inc. (EU cloud) | Product usage analytics: pseudonymous account and user identifiers, event names, and page and click metadata captured automatically; session replay with form inputs masked. On-screen text, which can include names shown on invoices, may be captured in replays until replay is disabled | EU (Frankfurt) | EEA processing under PostHog's data processing agreement |
| Functional Software, Inc. (Sentry) | Error monitoring: technical error data with personal data removed before transmission; pseudonymous identifiers only | United States | Sentry data processing addendum with EU Standard Contractual Clauses |
| Mistral AI | Automated abuse review of outgoing document emails before they are sent, on free and trial accounts only: the email subject and body with the known name and email address of the recipient and recognisable identifiers (email addresses, phone numbers, bank and tax numbers) removed (other personal data written into the free text may remain), and a short summary of the document (document number, issuer, totals, payment terms, and line-item names) | European Union (France) | EEA processing under Mistral AI's data processing agreement |
| Slack Technologies, LLC | Operational alerts on fiscalization and e-invoicing failures containing the entity name, document identifiers, and error text; partner support channels with the account name and invited email addresses | United States | Slack data processing addendum with EU Standard Contractual Clauses |
Feature-dependent sub-processors (only when you enable the feature)
These providers receive personal data only when you use the named feature. Peppol recipient lookups send the recipient identifier you supply; full e-invoice delivery applies only to enrolled entities.
| Entity | Feature | Purpose | Location | Transfer mechanism |
|---|---|---|---|---|
| Recommand | Peppol e-invoicing | Peppol access point: Peppol recipient lookups (the recipient identifier you supply) and, for enrolled entities, full e-invoice delivery (issuer, recipient, line items) | European Union | EEA processing under Recommand's data processing agreement |
| SuperPDP | French e-invoicing | French registered e-invoicing platform (PDP): the full e-invoice content and lifecycle and payment status reports for French entities enrolled for e-invoicing | France (EU) | EEA processing under SuperPDP's data processing agreement |
| Mistral AI | Expense scanning | Document OCR for expense recognition when the feature is enabled and configured for your account: the uploaded supplier invoice or receipt, including supplier name, address, tax number, bank details, and line items | European Union (France) | EEA processing under Mistral AI's data processing agreement |
Tax authorities and other recipients under your instruction
When you enable fiscalization or e-invoicing, or connect an integration, we send data to the recipient you choose. Tax authorities, Peppol recipients, banks, and integrations you connect (for example Stripe or Shopify) act as independent controllers or on your instruction. They are not our sub-processors.
| Recipient | Feature | Data sent |
|---|---|---|
| Financial Administration of the Republic of Slovenia (FURS) | Slovenian fiscalization | Fiscal verification of invoices: invoice identifiers, amounts, taxes, and issuer, customer, and operator tax identifiers for entities with Slovenian fiscalization enabled |
| Croatian Tax Administration (Porezna uprava) via FINA CIS | Croatian fiscalization | Fiscal verification of invoices: invoice identifiers, amounts, taxes, and issuer, customer, and operator tax identifiers for entities with Croatian fiscalization enabled |
| European Commission VIES service | VAT number validation | The VAT identifiers you validate (your own and your customers') |
Account-data service providers
These providers handle your own account data (login, billing, support), for which we are the controller as described in the Privacy Policy. They are listed for transparency.
- Stripe — Subscription billing for your Space Invoices account; card details go directly to Stripe
- Hal — Support chat and in-app messaging; receives your user id, email, name, account name, and plan
- Damper — Roadmap and feedback; receives your user id, email, and plan
- Braintree (PayPal) — White-label subscription activation; receives company name and email
- Google and Apple — Sign-in with Google or Apple, when you choose it; receives your sign-in identity
Changes
- 2026-09-05 — list first published.