Who touches your data, and where
Every company that processes Customer Data on our behalf, what it does, which data it sees and where. This list is Annex III of our Data Processing Addendum.
Version 1.0 · Effective 6 October 2026
- Your workspace is stored and run in the EU: Supabase in Frankfurt and Railway in the Netherlands.
- AI providers in the US see only the request in progress, and only when AI features are enabled for your workspace.
- We tell workspace owners 30 days before adding or replacing a subprocessor, and you can object.
- Services you connect yourself, such as Slack, are not on this list: they work under your own agreement with them.
This summary helps you read the document. It is not part of it: where they differ, the sections below apply.
1.Subprocessors for the Falrow service
| Company | What for | Data | Where | Transfer safeguard |
|---|---|---|---|---|
| Supabase, Inc. | Primary PostgreSQL database, user authentication and password-recovery email delivery | All Customer Data stored in the workspace; account email addresses and password hashes | EU: Frankfurt, Germany (AWS eu-central-1) | Stored in the EU. Support access from the US under the EU SCCs. |
| Railway Corporation | Application hosting: runs the Falrow web app, REST API, MCP server and background workers | All Customer Data in transit through the application; server logs | EU: Railway EU West region (Netherlands) | Processed in the EU. Support and operations access from the US under the EU SCCs. |
| Resend, Inc. | Transactional email: workspace invitations and account notices | Recipient email address, inviter name, workspace name | United States | EU SCCs |
| OpenRouter, Inc. | AI gateway that routes requests from Falrow's AI features to the model provider below. Used only when AI features are enabled for the workspace and only for the request in progress. | The text of the request, such as ticket content, meeting notes or a Slack message being classified. Prompts and outputs are not stored by Falrow. | United States | EU SCCs. Falrow requests routing only to model endpoints that do not retain or train on inputs; OpenRouter does not log prompt content by default. |
| Anthropic, PBC | Large language models (Claude) that power AI features, reached through OpenRouter | The text of the AI request in progress | United States | EU SCCs. Commercial API terms: no training on inputs or outputs. |
| TypeSafe | Classification model (Jev) that decides whether a Slack message is a to-do, reached through OpenRouter. Used only when Slack to-do capture is enabled. | The text of the Slack message being classified and its channel context | United States | EU SCCs. Message text is sent only to return a classification. |
2.Processors for the website
These process data about visitors to falrow.com and people who request access, for which we are the controller. They do not process workspace data.
| Company | What for | Data | Where | Transfer safeguard |
|---|---|---|---|---|
| Vercel, Inc. | Hosting of the falrow.com website and the access request form | Website request logs (IP address, user agent); access request form contents | United States, with a global edge network | EU SCCs |
3.Services you choose to connect
When you connect one of these, data flows between Falrow and that service on your instruction. The provider processes it under your agreement with it, not ours, so it is not our subprocessor.
| Service | What flows |
|---|---|
| Slack | Messages and user identities in channels you connect; Falrow posts replies and updates there. |
| Sentry | Error events you route to Falrow; Falrow writes links back to your Sentry organisation. |
| Granola, Fathom, Fireflies, tl;dv | Meeting notes and transcripts imported with an API key you provide. |
| Notion and your own webhook endpoints | Operations events sent to destinations you configure. |
| Your own Postgres or Supabase database | Read-only queries you configure as a data source. |
| Your AI provider key | If you bring your own model key, AI requests go to that provider under your agreement with it. |
| Coding agents (Claude Code, Codex, Cursor and others) | Ticket and plan data your agent reads or writes over the MCP server, under the scope you grant. |
4.How we announce changes
At least 30 days before a new or replacement subprocessor starts processing Customer Data, we email workspace owners and update this page. To get these notices at another address, write to bas@falrow.com. You may object on reasonable data protection grounds within the notice period, as the Data Processing Addendum describes.
Wilmington, DE 19802
United StatesEIN 35-2886201bas@falrow.com