Subprocessors
Who processes your data
Fortoxa uses a small set of third parties to deliver the service. Each entry below covers what they do, what they see and where they operate.
Last updated: 2026-04-19
Inferred list — pending confirmation
This list reflects the services Fortoxa uses today based on our stack. Legal review will confirm each entry (exact entity, current region, hosted-vs-managed boundary) before we treat this page as authoritative. Changes will be announced with at least 30 days' notice to customers on paid plans.
| Subprocessor | Purpose | Data | Region |
|---|---|---|---|
| Stripe | Billing, subscription management, payment processing | Customer email, billing address, payment method (Stripe-hosted) | EU / UK / US |
| Resend | Transactional email delivery (alerts, compliance reports, onboarding) | Customer email, message content | EU |
| Managed PostgreSQL (primary database) | Primary data store for customer, workspace and evidence records | All customer data in scope | UK / EU |
| Managed Redis | Job queues, rate limiting, ephemeral caching | Queue payloads, session metadata (short-lived) | UK / EU |
| Object storage (S3-compatible) | Long-lived evidence artefacts and PDF reports | Compliance reports, exported evidence | UK / EU |
| Application hosting (Next.js + Fastify) | Running the web application and API tier | Request metadata, application logs | UK / EU |
Subscribe to subprocessor changes
Paid customers are notified by email at least 30 days before any new subprocessor begins processing customer data. To subscribe for notifications without a paid plan, contact our team.