Trueness

Sub-processors

Effective date: 26 September 2026 Applies to: the Trueness service operated by Trueness Corp (CNPJ 63.887.933/0001-62), Avenida Paulista, 1374 - Bela Vista, São Paulo - SP, 01310-100, Brazil

This page is referenced by, and forms part of, our Data Processing Addendum, from trueness.lab@gmail.com. It is the general written authorisation for sub-processors that the DPA relies on.


1. Read this part first

Three of our sub-processors can hold personal data that belongs to you or to your customers. The rest cannot.

Can hold your customers' personal data:

Sub-processor What it holds
Google Cloud The servers and the key-management service the product runs on
Neon The database
Sentry Error reports — internal identifiers only, with personal fields removed before transmission

Cannot hold your customers' personal data: Stripe (our own billing), Google (the mailbox our contact address delivers to), GitHub, and Better Stack. What each of them does hold is set out in section 2.

The product currently sends you no email at all, because no transactional email provider is engaged for this release. When one is, it will appear in section 2 before the first message goes out. A mailbox and a sending service are two different things with two different agreements, and this page keeps them apart rather than collapsing them into one line that would be true of neither.

We keep this list short deliberately. Every vendor in the data path is a paragraph in the DPA, a question in every security review, and an outage somebody else can have on our behalf.


2. The full list

Sub-processor Legal entity Purpose Processing location Customer personal data? EU to US transfer mechanism
Google Cloud Contracting entity Google Cloud EMEA Limited (Ireland); the certified US entity is Google LLC Compute (Cloud Run), key management (Cloud KMS), secret storage, object storage, logging, container registry United States — us-east4 (Northern Virginia) Yes EU-US Data Privacy Framework. Google LLC is an active participant, covering HR and non-HR data, next recertification due 13 September 2027. Google's Cloud Data Processing Addendum applies the Framework as its transfer solution, with Standard Contractual Clauses as the fallback if it ceases to. Checked 23 September 2026.
Neon Neon, LLC, a Databricks company; the contracting parent is Databricks, Inc. The primary PostgreSQL database United States — aws-us-east-1 (Northern Virginia) Yes Standard Contractual Clauses, under the Databricks Data Processing Addendum that Neon's own terms incorporate. Databricks, Inc. also holds an active Data Privacy Framework certification (non-HR data, next due 10 August 2027) and Neon, LLC is named under it — but the addendum's operative clause names the Clauses, so that is what we rely on and state. Checked 23 September 2026.
Sentry Functional Software, Inc., trading as Sentry Error monitoring and performance tracing United States Yes — internal identifiers only. Contact names, email addresses, phone numbers, postal addresses, tax identifiers, request bodies and payment-instrument fields are removed before an event is transmitted EU-US Data Privacy Framework. Active participant, non-HR data, next recertification due 28 May 2027. Sentry's data processing agreement names the Framework, with Standard Contractual Clauses as the fallback if it is invalidated. Checked 23 September 2026.
Stripe Stripe, Inc. / Stripe Payments Europe, Ltd. Processing our own subscription billing — the payment you make to us United States / Ireland No. Your billing contact and your company's billing details only. Not your customers' data Stripe's own data processing agreement
Google (consumer mail account) Google LLC The mailbox our published contact address delivers to. This is where a message you send us is received and stored United States No. Your administrators' email addresses and the contents of correspondence with us Google LLC is an active participant in the EU-US Data Privacy Framework. But see the note below: this is an ordinary consumer account, not a Google Workspace subscription, so no separate data processing agreement is in place for it. Checked 23 September 2026.
(transactional email) None engaged Sending you sync alerts, drift digests, billing notices or report share links — — No provider is engaged for this release, so the product sends no such email. Postmark (AC PM, LLC, under ActiveCampaign, LLC's Data Privacy Framework certification, with Standard Contractual Clauses as the named fallback — checked 23 September 2026) is the chosen provider. It will be listed here, with its mechanism and the date checked, before the first message is sent.
GitHub GitHub, Inc. (Microsoft Corporation) Source control and continuous integration United States No Not applicable — no customer data reaches it
Better Stack Better Stack s.r.o. Uptime monitoring of our public endpoints European Union No Not applicable — no customer data reaches it

2.1 One thing about our mailbox, said out loud

Our published contact address is an ordinary Google consumer mail account, not a Google Workspace subscription. Google LLC is an active participant in the EU-US Data Privacy Framework, so the transfer itself is covered — but a consumer account carries no separate data processing agreement of the kind a business subscription does.

What that means in practice, and what we are doing about it. Today the only personal data in that mailbox is whatever you choose to put in an email to us. We have no customer established in the European Union — the same fact that means no Article 27 representative is designated yet. We will move to a business subscription with a data processing agreement before the first such customer is accepted, on the same trigger, and this page will say so when we have.

We would rather state this plainly than list a business subscription we have not bought.


3. Stripe and HubSpot are not our sub-processors

This surprises people, so we state it plainly.

When Trueness reads your Stripe account and writes to your HubSpot portal, it does so under your own credentials, into your own accounts, under your own contracts with those two companies. We do not send your data to Stripe or to HubSpot; we read from one and write to the other on your instruction. They are your processors, or your independent controllers, under your agreements with them — not ours.

The list in section 2 is the list of parties we engage to deliver the service.


4. Changes to this list

  • We give 30 days' written notice, by email to your registered administrator and by an update to this page, before a new sub-processor begins processing personal data, or before an existing one's role changes materially.
  • During those 30 days you may object, in writing, on reasonable data-protection grounds. We will work with you to find an alternative. If we cannot, you may terminate the affected part of the service and we will refund any unused prepaid term on a pro-rata basis.
  • Where we have to replace a sub-processor urgently because it has failed or has become a security risk, we will notify you as soon as we are able, and the objection right still applies.

To be notified of changes, email trueness.lab@gmail.com with the subject line subprocessor notice.


5. Where processing happens, and what that means for EU and UK customers

There are two separate transfers here, and they are carried by two different mechanisms.

Leg one — from the EEA to us, in Brazil. Trueness Corp is established in Brazil. On 26 January 2026 the European Commission adopted an adequacy decision for Brazil under Article 45 GDPR — Commission Implementing Decision (EU) 2026/179, announced jointly with Brazil on 27 January 2026 — and Brazil's ANPD adopted the reciprocal decision under LGPD Article 33 by Resolution CD/ANPD No. 32 of 26 January 2026. Personal data can therefore reach us from the EEA without Standard Contractual Clauses and without any other Chapter V transfer tool.

Leg two — from us to the United States, where the infrastructure is. Adequacy for Brazil does not cover this leg. Each US sub-processor in section 2 carries its own mechanism, and section 2 names which one and the date we checked it.

All four were verified on 23 September 2026 against the official Data Privacy Framework participant list, not against the vendors' own marketing pages. Two rely on the Framework with the Standard Contractual Clauses as a fallback; one relies on the Clauses directly. We re-verify annually and whenever a vendor's corporate ownership changes, because certifications lapse and contracting entities move — Neon's did, when Databricks acquired it.

One detail we state because it is the kind of thing that gets published wrongly: only US entities can self-certify to the Framework. Google Cloud EMEA Limited, the Irish entity we contract with, is therefore not itself a participant and cannot be. The certification belongs to Google LLC, and the Irish entity relies on the transfer terms in the Cloud addendum.

We say this because the opposite claim — that adequacy solves the whole chain — is wrong, and a buyer who checks will find that it is wrong.

United Kingdom. Not yet determined, and it does not need to be: we have no customer established there. We will confirm the UK position on transfers to Brazil, and whether a separate UK Article 27 representative is required, before accepting a UK customer.

Adequacy is durable, not permanent. The Commission reviews adequacy decisions at least every four years. If the decision for Brazil is suspended or withdrawn, we will implement Standard Contractual Clauses within the period stated in the DPA.


6. The people to contact

Role Contact
Data protection contact / LGPD encarregado trueness.lab@gmail.com
GDPR Article 27 representative in the Union Not yet designated — see the Privacy Policy §2
General support trueness.lab@gmail.com

We have no customer established in the European Union at the date above. A representative under Article 27 GDPR will be designated, with a name and a full postal address published here and in the Privacy Policy, before the first such customer is accepted — or sooner, if our processing otherwise falls within Article 3(2) GDPR. The representative will not be one of the sub-processors listed above, and never will be.