LEGAL

Every vendor that touches your data. Named.

The full list of sub-processors Baslic relies on. Updated whenever it changes.

Summary

In plain English

Baslic runs on a deliberately small set of sub-processors: eight active, with one more (Backblaze for encrypted off-site backups) joining within the next 7 days. Hosting stays on EU servers in Germany; our analytics are cookieless (Plausible, EU-hosted). We have no chat widget, no advertising trackers, no session recording, and no behavioral profiling.

Change notifications

We notify customers by email at least 30 days before any new sub-processor begins processing customer data, unless an urgent security or compliance need requires faster action (in which case we notify as soon as possible and document the reason in the changelog). To receive these notifications, click the button below — we will add your email address to the sub-processor notification list. The same commitment is written into our Data Processing Agreement.

Infrastructure

Where Baslic's servers, databases, and storage live.

Hetzner

Hetzner Online GmbH

Website

Purpose

Cloud infrastructure (compute, storage, network) for production and beta environments

Data processed

All customer data at rest, including database records and uploaded receipt files

Location

Falkenstein and Nuremberg, Germany (EU)

Transfer mechanism

Within EEA (no transfer mechanism required)

Cloudflare

Cloudflare, Inc. (US) — EU contracting via Cloudflare Ireland Ltd (Dublin)

Website

Purpose

DNS resolution (authoritative nameservers for baslic.com). Proxy is currently OFF — Cloudflare does not intercept HTTPS traffic; only DNS queries pass through.

Data processed

DNS query metadata (resolver IP, query name, response). No HTTPS payload data.

Location

Global edge for DNS; EU contracting via Cloudflare Ireland

Transfer mechanism

Cloudflare standard DPA + EU-US Data Privacy Framework

Backblaze B2

Backblaze, Inc. (California, USA) — EU (Amsterdam) region

Website

Purpose

Off-site encrypted backup of customer receipt files

Data processed

Encrypted backup archives — client-side encrypted with age before upload; encryption keys are held by Baslic only, so Backblaze cannot decrypt them.

Location

Amsterdam, Netherlands (EU)

Transfer mechanism

EU region (Amsterdam) selected — data stays within the EEA; EU Standard Contractual Clauses (SCC) are also in place with the US parent entity.

AI engines

AI models that parse receipts, invoices, and Z-Reports. The OCR step (extracting raw text from receipt images and PDFs) is self-hosted on our own infrastructure — see the In-house components section below. Only the extracted text, plus the document metadata needed for classification, is sent to the AI model for line-item structuring, VAT classification, and Z-Report parsing.

Anthropic

Anthropic Ireland Ltd.

Website

Purpose

AI parsing of receipts, invoices, and Z-Reports — Timo's NLU, per-line VAT classification, and Matkalasku trip parser (Claude models)

Data processed

Extracted text from receipts and invoices, plus the document metadata needed for classification. Receipt images themselves do not leave our infrastructure (the OCR step is self-hosted, see In-house components).

Location

Anthropic Ireland Ltd. (Dublin) acts as the EU data controller for European customers. Inference is processed on Anthropic-operated infrastructure in the United States. EU data residency is available only as an enterprise option and is not currently configured for Baslic. Standard Contractual Clauses (Module 3) cover the EU-to-US transfer.

Transfer mechanism

EU Standard Contractual Clauses (Module 3) plus enterprise zero-retention agreement.

Platform services

Authentication, email delivery, and domain services.

Postmark

ActiveCampaign, LLC

Website

Purpose

Outbound transactional email delivery (ingestion confirmations, sign-in links, billing notifications, sub-processor change notifications)

Data processed

Recipient email address, subject line, and message body for each transactional email sent

Location

EU servers with US fallback

Transfer mechanism

EU Standard Contractual Clauses (Module 3)

Clerk

Clerk Inc. (Delaware, USA)

Website

Purpose

User authentication, session management, multi-factor authentication

Data processed

Email address, password hash (bcrypt), session tokens, last sign-in metadata

Location

United States

Transfer mechanism

EU-US Data Privacy Framework (active)

Simply.com

Simply.com A/S (Denmark)

Website

Purpose

Domain registrar (baslic.com) and apex email mailbox hosting

Data processed

Domain registration metadata (WHOIS), apex mailbox content

Location

Denmark, EU

Transfer mechanism

Within EEA (no transfer mechanism required)

Analytics

We use a single cookieless analytics service to understand traffic patterns at an aggregated level. No individual visitor is identifiable, no cookies are set, and no data is shared with advertising networks.

Plausible Analytics

Plausible Insights OÜ (Estonia)

Website

Purpose

Cookieless website analytics — aggregated page views and traffic sources only

Data processed

Anonymized page paths, user agent category, referrer. No IP storage, no fingerprinting, no individual tracking.

Location

Germany (EU)

Transfer mechanism

Within EEA (no transfer mechanism required)

Business operations

The single sub-processor that supports billing.

Stripe

Stripe Payments Europe Ltd.

Website

Purpose

Payment processing, subscription billing, and tax handling for paid plans

Data processed

Payment method tokens, transaction metadata, billing address, VAT identifiers

Location

Dublin, Ireland (EU) with US as data importer for global payment infrastructure

Transfer mechanism

EU Standard Contractual Clauses (Module 3) plus Stripe's safeguards programme

Maps

MapTiler

MapTiler AG (Zug, Switzerland) — map-tile data centres in France (EU)

Website

Purpose

Map-tile provider — renders the background map for the route maps shown in travel-expense (matkalasku) PDFs. The PDF, including the route line and stop markers, is composed on Baslic's server; MapTiler supplies only the background map tiles.

Data processed

None of the Controller's Customer Personal Data. MapTiler receives only standard map-tile requests (tile x/y/z coordinates for the trip's geographic region) plus our API key, sent from Baslic's server. It does not receive the route line, exact start or end points, identities, names, amounts, trip purpose, or any end-user IP address. At most, the tiles requested indicate the rough geographic region of a trip, not linked to any individual.

Location

MapTiler AG, Zug, Switzerland (headquarters); map-tile data centres in France (EU).

Transfer mechanism

Switzerland benefits from a European Commission adequacy decision (Article 45 GDPR), so requests to MapTiler's Swiss entity are lawful without Standard Contractual Clauses. The map-tile data centres are in France (EU/EEA — no transfer mechanism required).

Pending additions

We currently have no sub-processors pending activation.

In-house components

Not every part of Baslic runs on a third-party service. These components are operated by us directly:

  • OCR engine — we self-host the open-source Tesseract OCR engine on our Hetzner infrastructure to convert receipt photos, PDFs, and HEIC files into raw text before the line-item extraction step. Receipt images stay within our infrastructure throughout this step.
  • Application servers, databases, queues, caches — all operated by Baslic on the infrastructure listed above; no third-party SaaS layer sits between you and your data.
  • Customer chat widgets, session recording, and behavioral profiling — none of these are in use. Product analytics is limited to aggregated, cookieless page-view counts via Plausible (listed above). Error monitoring is computed from our own server logs.

How to object

If you object to a specific sub-processor for legitimate reasons, contact us at privacy@baslic.com within 30 days of the notification. We will respond within 14 business days, and we will work with you to find an acceptable arrangement (e.g. opting out of the affected feature). If no resolution is possible, you may terminate the affected service with a pro-rata refund of any prepaid period, in line with our Data Processing Agreement.

Why this short list

Adding a sub-processor adds risk. We resist adding any service that doesn't earn its place. Most product needs are met by either Hetzner, Anthropic, or our own code.

Changelog

  • 24 June 2026Added MapTiler (MapTiler AG, Switzerland) as a map-tile provider (new Maps section) — renders the background map for route maps in travel-expense (matkalasku) PDFs. Region tiles only, fetched server-side from Baslic's server; no Customer Personal Data is sent. Transfer basis: Switzerland adequacy decision (Article 45 GDPR); tile data centres in France (EU).
  • 11 June 2026Backblaze B2 activated as our off-site encrypted backup sub-processor (Infrastructure), moved from pending to active. Customer receipt backups are client-side encrypted with age before upload to Backblaze B2’s EU (Amsterdam) region and retained under 30-day Object Lock immutability.
  • 24 May 2026(Bonus) Companion pages added: /legal/cookies (full cookie disclosure), /legal/security (security practices and incident response).
  • 24 May 2026Expanded disclosure: added Cloudflare (DNS, Infrastructure), Clerk (authentication, Platform), Simply.com (domain + apex mail, Platform), and Plausible (cookieless analytics, new Analytics section). Backblaze B2 listed as pending (LS3 off-site backup). Summary and in-house statements reconciled with the new stack.
  • 17 May 2026Initial publication of the sub-processor list, covering the launch stack: Hetzner (infrastructure), Anthropic (AI), Postmark (email), and Stripe (billing).

Related documents: