Home/Legal and Privacy Policy/Subprocessors

Subprocessors

Last reviewed: July 8, 2026

These are the companies we use to run Toolbar. Each one handles some of your data on our behalf, for things like storing accounts, hosting the app, catching errors, or running AI features. We have signed agreements with all of them that require them to protect your data and use it only for the purposes we specify. Where data is transferred outside the EEA, we rely on applicable transfer safeguards, such as Standard Contractual Clauses.

We keep this list up to date. If our providers change, we will update it and bump the "Last reviewed" date above. Customers will receive notice of new or replacement subprocessors where required by their agreement or DPA. Questions? Email us at notices@toolbar.no.

Supabase

Supabase, Inc.

Sweden (EU)

Service & Purpose

Managed database, authentication, and file storage backend. Supabase stores all application data including user accounts, organisation records, software inventory, seat assignments, usage metrics, and billing information. It also manages authentication sessions and access tokens.

Categories of Data Processed

  • Account identifiers (name, work email)
  • Organisation and membership data
  • Role and permission records
  • Software, seat, and usage records
  • Billing and spend metadata
  • Identity provider integration references
  • Authentication session tokens
  • Encrypted connector credentials and access tokens where applicable

Processing Location & Transfer Safeguards

Data is stored in Sweden, an EU member state. No cross-border transfer mechanism is required for EEA-resident data subjects. Supabase processes data under a Data Processing Agreement (DPA).

References

  • Supabase Privacy Policy
  • Supabase DPA

Vercel

Vercel, Inc.

Sweden (EU)

Service & Purpose

Web application hosting, content delivery network (CDN), and server-side runtime. Vercel serves the Toolbar web application and handles all HTTP requests, including edge routing, server-side rendering, and static asset delivery.

Categories of Data Processed

  • IP addresses and device/browser metadata
  • HTTP request headers and query parameters
  • Server-side request logs and performance traces
  • Cookies and session identifiers set at request time
  • Edge function execution metadata

Processing Location & Transfer Safeguards

The Toolbar application runtime is configured for primary processing in Sweden, an EU member state. Vercel may process, cache, route, or log request metadata through its global network and operational systems. Where processing involves transfers outside the EEA, Toolbar relies on Vercel's Data Processing Agreement (DPA), including applicable transfer safeguards.

References

  • Vercel Privacy Policy
  • Vercel DPA

Microsoft Azure AI Foundry

Microsoft Corporation

Region determined by Toolbar's configured Azure AI Foundry resource and Microsoft's service routing for the selected AI capability.

Service & Purpose

AI model API used to power automated features within Toolbar, including software import mapping, billing email parsing, and catalog enrichment. Requests are made server-side through Toolbar's Azure AI Foundry OpenAI-compatible endpoint. Toolbar does not use customer content to train AI models.

Categories of Data Processed

  • Customer-submitted software import data used for AI-assisted mapping, including uploaded rows, columns, software names, vendor names, plan labels, URLs, pricing, cost figures, and other business context included by the customer
  • Billing email metadata, attachment text, invoice images, and invoice PDFs used to extract software billing facts
  • Software vendor and product metadata submitted for catalog enrichment, such as vendor names, product names, and URLs
  • Publicly available vendor website and pricing content retrieved during grounded enrichment workflows

Processing Location & Transfer Safeguards

Where data is transferred outside the EEA, Toolbar relies on Microsoft data protection terms and applicable transfer safeguards. Toolbar uses Azure AI Foundry only to provide import mapping, billing email parsing, catalog enrichment, and related product features, not to train AI models.

References

  • Microsoft Privacy Statement
  • Microsoft Product Terms
  • Azure OpenAI Data, Privacy, and Security

Google Gemini

Google LLC

Region determined by Google's API infrastructure. Toolbar does not configure an explicit regional endpoint; processing may occur in any Google data centre, including locations outside the EEA.

Service & Purpose

Temporary fallback AI model API used during Toolbar's migration to Azure AI Foundry. When enabled, Gemini may process software import mapping, billing email parsing, and catalog enrichment requests if the primary Foundry path is unavailable. Toolbar does not use customer content to train AI models.

Categories of Data Processed

  • Customer-submitted software import data used for AI-assisted mapping, including uploaded rows, columns, software names, vendor names, plan labels, URLs, pricing, cost figures, and other business context included by the customer
  • Billing email metadata, attachment text, invoice images, and invoice PDFs used to extract software billing facts
  • Software vendor and product metadata submitted for catalog enrichment, such as vendor names, product names, and URLs
  • Publicly available vendor website and pricing content retrieved during enrichment workflows

Processing Location & Transfer Safeguards

Where data is transferred outside the EEA, Toolbar relies on Standard Contractual Clauses (SCCs) adopted by the European Commission, as incorporated in Google's Data Processing Amendment. Toolbar uses Gemini only as an environment-controlled fallback for import mapping, billing email parsing, catalog enrichment, and related product features, not to train AI models. Customers should review their own data classification policies before using AI-assisted features.

References

  • Google Privacy Policy
  • Google Gemini API Terms of Service
  • Google Cloud Data Processing Amendment

Sentry

Functional Software, Inc. d/b/a Sentry

European Union (Germany)

Service & Purpose

Sentry is used for error monitoring, performance tracing, sampled session replay, and voluntary feedback submissions. Replay uses Sentry’s default privacy protections, which mask text and input values and block media before data is sent. We may also send technical request metadata and limited user identifiers, such as email address and display name, for debugging and support.

Categories of Data Processed

  • Error events including JavaScript stack traces and server-side exception details
  • Performance spans and server request traces
  • Browser and device metadata (user agent, viewport, OS, browser version)
  • User identifiers (email address and display name) attached to error and feedback events
  • Sampled session replays including DOM snapshots and user interaction sequences
  • Voluntary feedback submissions (text description and optional screenshot)

Processing Location & Transfer Safeguards

Toolbar's Sentry organisation is configured to ingest data exclusively through the EU data centre, located in Germany. Data does not leave the EEA for primary storage or processing. Sentry processes data under a Data Processing Agreement (DPA) that incorporates Standard Contractual Clauses for any incidental transfers.

References

  • Sentry Privacy Policy
  • Sentry DPA
  • Sentry Security & Compliance

Resend

Resend, Inc.

United States

Service & Purpose

Transactional email delivery for Toolbar notifications, including access-review emails, owner-transfer emails, and related operational messages.

Categories of Data Processed

  • Recipient email address and name
  • Organization name
  • Email subject and body content
  • Review, transfer, and product links included in emails
  • Email delivery and diagnostic metadata

Processing Location & Transfer Safeguards

Where data is transferred outside the EEA, Toolbar relies on applicable legal transfer mechanisms, such as Standard Contractual Clauses (SCCs), and written data protection commitments from the provider.

References

  • Resend Privacy Policy
  • Resend Data Processing Addendum

Tally

Tally BV

European Union (Belgium)

Service & Purpose

Demo request and contact form intake. Toolbar uses Tally forms to collect demo requests submitted from the public website.

Categories of Data Processed

  • Name
  • Work email
  • Company name
  • Form responses and free-text context submitted by the requester
  • Submission metadata generated by the form service

Processing Location & Transfer Safeguards

Tally is based in the European Union. Where processing or support access involves transfers outside the EEA, Toolbar relies on applicable legal transfer mechanisms and written data protection commitments from the provider.

References

  • Tally Privacy Policy
  • Tally Data Processing Agreement
← Back to Privacy Policy