Sub-processors

Last updated: May 7, 2026

This is an initial draft. It will be reviewed by a lawyer specialized in GDPR (Europe) and Habeas Data (LATAM) before public launch.

This page lists the sub-processors we use. We publish it for GDPR Art. 28.2 transparency and as a reference for clients who sign a Data Processing Agreement (DPA) with Guerki.

Active sub-processors

Sub-processorServiceData sharedRegionDPA
VercelHosting + edge functionsHTTP requests and visitor IP addressEU+USView DPA
BeehiivNewsletter (waitlist + welcome emails)Subscriber email and UTM parametersUSView DPA
UpstashDistributed rate limitingIP hash (rate limiting)USView DPA
PostHogProduct analyticsPost-consent product events (no PII)EUView DPA

Authorized sub-processors (Guerki HR product — not yet processing)

The following sub-processors are authorized for the Guerki HR product (Annex 2 of our DPA) but do not process personal data at this time. This list reflects planned integration; each effective onboarding moves the provider to the section above.

Sub-processorServiceData sharedRegionDPA
NeonPostgres databaseAll HR product personal data (encrypted)EU+USView DPA
CloudflareCDN + network protectionAll product HTTP requestsEU+USView DPA
ClerkAuthentication and organization managementAdministrator identifiersUSView DPA
AnthropicArtificial intelligence (Claude agents)AI agent inputs and outputsUSView DPA
AWS RekognitionFacial recognition (attendance)Facial images (with explicit consent)USView DPA
StripePayment processingBilling dataUSView DPA
ResendTransactional emailTransactional emails (receipts, alerts)USView DPA

Change notification

We will notify clients under signed contract in writing at least 30 days before adding a new sub-processor or replacing an existing one. The client may object on reasonable grounds within 14 days of notification.

Contact

Questions about sub-processors: dpo@guerki.com

Guerki — AI-powered HR for LATAM and Spain