Skip to content

Subprocessors

Cowliss engages the subprocessors below to provide the service (GDPR Art. 28(2)). This page is the canonical list and is incorporated into the DPA by reference.

When a subprocessor is added or replaced, Cowliss updates this page and emails the organization’s admins at least [14] days before the new subprocessor processes any tenant data. You may object at [email protected]; where an objection stands, you may terminate (Art. 28(2)).

Subprocessor Role Tenant data it processes Location
AWS SES Email delivery Recipient email addresses, rendered message content, delivery/bounce/complaint events Region set per deployment
Clerk Authentication and organization membership The controller’s team members: names, emails, sign-in metadata — never end-user data Clerk cloud [region per instance]
Stripe Payment processing for wallet top-ups The billing contact’s payment details — no end-user data Stripe’s own infrastructure

End-user data (profiles, events) leaves Cowliss’s own storage for exactly one subprocessor: AWS SES, at send time, carrying the recipient address and the rendered message.

The rest of the stack is software Capital Enesti Inc. runs itself. These are not third-party subprocessors, but they are listed here so hosting locations stay on the record:

Component Role Hosting
Temporal Durable journey workflow state Self-hosted alongside the application
Postgres Profiles, traits, consent, registries, ledgers Operator’s VPS (production target)
ClickHouse The append-only event stream Operator’s VPS (production target)

Production hosting locations are recorded on this page when the deployment target is finalized.