---
title: Subprocessors
slug: subprocessors
version: 1.0
effective: 2026-09-07
---

# Bucketize Subprocessors

**Last updated September 7, 2026**

This page lists the third parties that process Customer Data on our behalf (**subprocessors**) under our [Data Processing Addendum](/dpa), what each one does, and where it is. It is split into infrastructure that is always in use, and services that are engaged only when your organization enables a feature. A third group — systems *you* connect — is listed for completeness even though those are not subprocessors: they are your own vendors, acting under your agreements with them, and data flows *from* them into Bucketize at your direction.

**How you'll hear about changes.** We give organization administrators at least **30 days' notice** by email before a new or replacement subprocessor processes Customer Data, and we update this page and its change log at the same time. To add another contact to the notification list, email legal@bucketize.org.

## A. Infrastructure — always in use

| Subprocessor | What it does for Bucketize | Data it processes | Location |
|---|---|---|---|
| **Cloudflare, Inc.** | Edge network, TLS termination, application runtime (Workers), static hosting, scheduled jobs | All requests to the Service, in transit | United States (global edge; requests are processed at the location nearest the user) |
| **Supabase, Inc.** | Managed PostgreSQL database, authentication, SAML single sign-on | All Customer Data and account data, at rest | United States — AWS us-east-1 (Virginia) |
| **Resend, Inc.** | Transactional email delivery (invitations, approval requests, reminders, digests, authentication emails) | Recipient email addresses and message contents | United States |
| **Envoi (envoi.work)** | Fallback email delivery, used only if the primary provider is unavailable | Recipient email addresses and message contents | United States |
| **Functional Software, Inc. (Sentry)** | Error monitoring, performance tracing, sampled session replay (text, inputs and media masked client-side) | Error and diagnostic data; user identifiers where present in an error; masked replays | United States |

## B. Optional — engaged only when a feature is enabled

| Subprocessor | Feature | Data it processes | Training | Retention | Location |
|---|---|---|---|---|---|
| **Anthropic, PBC** | AI assistant (default model provider) | Budget structures and amounts, change history including the names or emails of users who made changes, the questions users ask, and the organization's display name | Prohibited by contract | Requests deleted within 30 days; zero-retention offered where available to us | United States |
| **OpenAI, L.L.C.** | AI analysis, AI-assisted import of spreadsheets and contracts, AI invoice matching, vendor summaries | Budget digests including line owners' names, uploaded spreadsheet headers and sample rows, text extracted from uploaded contracts, invoice vendor names and GL codes | Prohibited by contract (API terms) | Requests deleted within 30 days; zero-retention offered where available to us | United States |
| **Calendly LLC** | Demo scheduling on our marketing site only | Contact details of people who book a demo (not Customer Data) | n/a | Per Calendly's policy | United States |

If your organization turns AI features off, no data is sent to Anthropic or OpenAI. If your organization configures its own model-provider key (bring-your-own-key), requests from your organization are made under your own agreement with that provider rather than ours.

## C. Connected Services — your systems, at your direction (not subprocessors)

| Service | Direction | What flows | Governed by |
|---|---|---|---|
| **BILL (Bill.com)** | Into Bucketize | Invoices, vendors, GL accounts, approver names and emails | Your agreement with BILL |
| **NetSuite (Oracle)** | Into Bucketize | Vendor bills, expense lines, chart of accounts, approver names and emails | Your agreement with Oracle |
| **Greenhouse** | Into Bucketize | Open job requisitions and their planned compensation bands (no candidate data) | Your agreement with Greenhouse |
| **Finch** | Into Bucketize | Employee roster, titles, departments, start/end dates, annualized salary, and monthly gross pay and employer cost from payroll | Your agreement with Finch |
| **Ironclad** | Into Bucketize | Contract records, counterparties, values, dates and attachments | Your agreement with Ironclad |
| **Okta or another SAML identity provider** | Into Bucketize | User identity at sign-in; deprovisioning events (the deprovisioned user's email) | Your agreement with your identity provider |

Bucketize reads from these systems; it does not write to them. Disconnecting a service in your settings revokes our access.

## D. Other third parties your browser may contact

- **open.er-api.com** — a public exchange-rate service your browser queries directly when you view amounts in a currency other than U.S. dollars. It receives no data other than the request itself (including your IP address, as with any web request).

Tooling that does not process Customer Data — source control, continuous integration and secrets management — is not listed here.

---

## Change log

- **2026-09-07** — First published list.
