Subprocessors
Cowliss engages the subprocessors below to provide the service (GDPR Art. 28(2)). This page is the canonical list and is incorporated into the DPA by reference.
Change notification
Section titled “Change notification”When a subprocessor is added or replaced, Cowliss updates this page and emails the organization’s admins at least [14] days before the new subprocessor processes any tenant data. You may object at [email protected]; where an objection stands, you may terminate (Art. 28(2)).
Third-party subprocessors
Section titled “Third-party subprocessors”| Subprocessor | Role | Tenant data it processes | Location |
|---|---|---|---|
| AWS SES | Email delivery | Recipient email addresses, rendered message content, delivery/bounce/complaint events | Region set per deployment |
| Clerk | Authentication and organization membership | The controller’s team members: names, emails, sign-in metadata — never end-user data | Clerk cloud [region per instance] |
| Stripe | Payment processing for wallet top-ups | The billing contact’s payment details — no end-user data | Stripe’s own infrastructure |
End-user data (profiles, events) leaves Cowliss’s own storage for exactly one subprocessor: AWS SES, at send time, carrying the recipient address and the rendered message.
Operator-run infrastructure
Section titled “Operator-run infrastructure”The rest of the stack is software Capital Enesti Inc. runs itself. These are not third-party subprocessors, but they are listed here so hosting locations stay on the record:
| Component | Role | Hosting |
|---|---|---|
| Temporal | Durable journey workflow state | Self-hosted alongside the application |
| Postgres | Profiles, traits, consent, registries, ledgers | Operator’s VPS (production target) |
| ClickHouse | The append-only event stream | Operator’s VPS (production target) |
Production hosting locations are recorded on this page when the deployment target is finalized.