Supabase
Privacy policy ↗- Purpose
- Hosted Postgres database, authentication, Realtime, edge functions, cron jobs
- Region
- Frankfurt, Germany (eu-central-1)
- Data accessed
- All Customer Data (audit events, approvals, tools, policies, users)
Legal · Sub-processors
Every company that receives data because of Pliuz, in two groups: the ones that handle your Customer Data, and the one that does not but gets listed anyway. Any addition triggers a 30-day notice to existing customers (via email and updates to this page).
These are the sub-processors our Data Processing Addendum governs under GDPR Art 28.
This one never touches approval payloads, approver identities or audit events, and it does not run inside the authenticated product. Pliuz is the controller of its own marketing-site visitor data, so under Art 28 it is not a sub-processor at all — we list it because leaving it out would look like hiding it. If a security review requires no US processor anywhere in your supply chain: Slack is optional per tenant, and this one is a property of our own website that can be switched off entirely.
Last updated: 2026-09-05. Subscribe to changes by emailing founder@pliuz.com with subject "Subscribe sub-processor updates" — we will email any addition 30 days before it goes live.