Skip to content

DPA and sub-processors

For the data Applane holds about your employees (admin and builder email addresses, seat activity), Applane is a processor acting on your instructions: you decide who uses the product. For your billing contact, Applane is a controller.

Applane does not process the contents of your apps, your sheets, your prompts or your documents, because none of it reaches Applane. See Data flow.

Sub-processor Purpose Location
Supabase Database and backend functions: tenant configuration, seats, licences Frankfurt, Germany (EU)
Cloudflare Network edge and static hosting for the website, the console and this site EU data localisation enabled
Stripe Invoicing and payment processing EU entity; Stripe holds the billing contact
Email provider (to be named) Transactional email: licence and admin notices EU

Data stays in the EU. Changes to this list are announced to every admin by email at least 30 days before they take effect.

Applane’s data processing agreement is based on the standard EU processor clauses (GDPR Article 28). Its annex lists the two data categories (admin and builder emails; seat and admin activity), the sub-processors above, EU hosting, breach notification within 72 hours, the deletion timelines on Where things are stored, and audit rights met by this documentation.

Request it from the support address shown in the console, or from the security page on applane.dev. Companies that need their own paper can send it for review; the obligations are the same whatever the template says.

  • Extension: no tokens in extension storage, sandboxed preview, no remote code, a content security policy.
  • Backend: row-level security on every tenant table, writes through audited functions, secrets in a vault, licences signed with ES256, ID token audience and nonce checks, rate limits on the public endpoints.
  • Operations: two-factor authentication on every account that can touch production, pinned dependencies with automated scanning, daily backups.
  • A written incident process: who is told, within what time, by which channel.

SOC 2 is not in place. The interim evidence for a security review is this site, the Data flow page, the Internal-client posture (No Google app verification needed), the sub-processor list, and the DPA.

For AI agents: llms.txt, llms-full.txt, or any page with a .md suffix.