← Home

Sub-processors

Third parties that may process personal information on our behalf when you use Reconciled.

Last updated: DRAFT — review with legal counsel before publishing

Reconciled engages the third parties listed below to deliver the Service. We have written agreements with each that impose confidentiality and security obligations consistent with POPIA. We update this page when we add or remove a sub-processor.

ProviderPurposeLocationData categoriesSafeguard
Anthropic, PBCAI extraction of transactions from uploaded documentsUnited StatesBank statement contents, financial document contentsAnthropic Data Processing Addendum; data not used for model training
Laravel Cloud (Laravel LLC)Application hosting, managed MySQL database, queue worker infrastructureUnited States (primary region)All application data — user records, client data, compliance tasks, time entries, invoices, synced email messagesLaravel Cloud Data Processing Addendum; SOC 2 Type II; data encrypted in transit (TLS 1.2+) and at rest
Cloudflare, Inc. (R2 object storage)Storage of uploaded documents (bank statements, supporting documents) and email attachmentsEuropean Union (EU-only routing configured)Uploaded financial documents, email attachmentsCloudflare Data Processing Addendum; AES-256 server-side encryption; bucket private with signed-URL access
Microsoft Corporation (Microsoft Graph)Mailbox access for users who connect a Microsoft 365 / Outlook mailbox via OAuthRegion of the user's Microsoft 365 tenant (typically EU or US)Mailbox metadata + message bodies + attachments of the connecting userMicrosoft Online Services DPA; OAuth tokens encrypted at rest; access scoped to consented permissions only
Google LLC (Gmail API)Mailbox access for users who connect a Gmail / Google Workspace mailbox via OAuthUnited StatesMailbox metadata + message bodies + attachments of the connecting userGoogle Cloud Data Processing Addendum; subject to Google API Services User Data Policy (Limited Use); OAuth tokens encrypted at rest
User's configured IMAP/SMTP providerMailbox access for users who connect via legacy IMAP+SMTP (e.g. Rackspace, Fastmail, Zoho, on-prem Exchange)Determined by the user's chosen providerMailbox credentials + synced message contentsCredentials encrypted at rest with AES-256; the user's contractual relationship is with their chosen mail provider
Google LLC (Google Tag Manager)Website analytics — landing page only, after explicit consentUnited StatesIP address, browser identifiers, page viewsGoogle Ads Data Processing Terms; loads only after user accepts cookie banner

How we vet sub-processors

  • Written DPA or equivalent contract before any data is shared
  • Review of provider's security posture and POPIA / GDPR compliance posture
  • Assessment of cross-border transfer safeguards (POPIA s.72)
  • Annual review of the sub-processor list

Notification of changes

When we add a sub-processor that handles personal information, we will update this page and notify firm administrators by email at least 30 days before the change takes effect, where reasonably possible.

Contact

Questions about our sub-processors: hello@reconciled.co.za