Sub-processors
Last updated · 18 August 2026
Pointnode Limited uses the following sub-processors to deliver the Pointnode platform. Each is engaged under written data-processing or service terms appropriate to its role and only processes Customer data to provide the service or meet its legal obligations.
We notify org admins by email at least 30 days before adding or replacing a sub-processor. Customers may object before the change takes effect; if a workable alternative cannot be agreed, the Customer may terminate without penalty.
Current sub-processors
| Provider | Purpose | Data processed | Region | Transfer mechanism |
|---|---|---|---|---|
| Supabase Inc. Privacy · DPA | Postgres database, authentication, file storage, edge functions, realtime subscriptions | All Customer data — accounts, audit log, telemetry, configuration, uploads | EU (eu-west-1, Ireland) | EEA hosting; provider DPA safeguards any restricted onward or support access |
| Vercel Inc. Privacy · DPA | Cloud dashboard hosting and CDN | Request metadata and application data transiently processed to render pages and execute server functions; platform logs subject to configured provider retention | Multi-region (edge); EU primary | SCCs / IDTA in Vercel DPA |
| Fly.io Inc. Privacy · DPA | MQTT-to-database ingest service hosting (pointnode-ingest app), with a persistent volume for the disk-spool retry buffer | Asset telemetry in transit; transient retry-buffer contents on disk | London (lhr) | UK hosting; provider DPA safeguards any restricted onward or support access |
| HiveMQ GmbH Privacy · DPA | MQTT broker for asset telemetry transport | Asset telemetry in transit (machine data, no personal data) | EEA-hosted Pointnode cluster | EEA hosting; provider DPA safeguards any restricted onward access |
| The Things Industries B.V. (LoRaWAN Network Server — where Pointnode provides the managed network server) Privacy · DPA | LoRaWAN Network Server for the optional connected-lite / wireless sensor telemetry path: routes uplink sensor readings from customer-fitted LoRaWAN devices to the platform, and (where the optional start-inhibit interlock is enabled) routes outbound relay commands to a device. Only engaged where Pointnode provides the managed network server; where the Customer operates its own LoRaWAN Network Server, or Pointnode self-hosts one on its existing Fly.io infrastructure, that path is covered by the Customer's or Fly.io's entry respectively rather than this row. | Device radio identifiers (DevEUI), decoded sensor readings and raw uplink payloads, and — for the interlock — outbound relay command bytes. These are normally machine data but can become personal data if linked with an identifiable operator or user action. | EEA region selected for the managed service | EEA hosting; provider DPA safeguards any restricted onward access |
| Resend Inc. Privacy · DPA | Transactional email delivery (alerts, password resets, invitations) | Recipient email address, alert subject and body | United States | EU SCCs / UK IDTA in Resend DPA |
| Stripe Payments Europe Ltd Privacy · DPA | Subscription billing, invoice generation and delivery, customer billing portal. Card / bank-account capture happens directly between the Customer and Stripe's hosted checkout pages; Pointnode never sees raw payment instrument data. | Customer organisation name, billing contact email address, invoice line items and amounts, payment metadata | Ireland (EU) with US affiliate processing | EU SCCs / UK IDTA in Stripe DPA |
| Functional Software, Inc. (Sentry) Privacy · DPA · Sub-processors | Application error monitoring and observability. Browser and server-side exception payloads, stack traces, request URL, user-agent, and the authenticated user’s account UUID for correlation. Email addresses are hashed (deterministic SHA-256 prefix) before transmission. Session replay, performance tracing and default PII capture are disabled; a payload scrubber removes email-shaped strings from exceptional error data. | Authenticated account UUID, request metadata (URL, user-agent, HTTP status), exception stack trace, environment fingerprint | EU (Germany) project region; US provider and authorised global operations | EU SCCs / UK Addendum or IDTA in Sentry DPA where required |
| Anthropic PBC Privacy · Trust & sub-processors | Optional AI features — the Asset Briefing (per-asset condition narrative) and the AI Engineer assistant. Asset context is sent to Anthropic's API to generate plain-English analysis. Enabled per asset or organisation according to the licensed Asset Intelligence scope. Anthropic does not train models on commercial API Customer Content by default. | Asset telemetry summaries and trends, condition / health signals, event and defect descriptions, compliance status, and the text of questions a user asks the AI Engineer. No payment data or account credentials. Free text and uploaded evidence can contain personal data if a user includes it. | United States | EU SCCs / UK IDTA in Anthropic DPA |
| Voyage AI (MongoDB, Inc.) Product · Privacy · DPA | Optional document-vault search (RAG). Generates vector embeddings of documents uploaded to an asset's document vault so the AI Engineer can cite the relevant passage. Enabled per asset (with the Asset Intelligence scope). Organisation-wide features operate only when enabled for that organisation. | Text extracted from documents the Customer uploads to an asset (e.g. manuals, drawings, PLC docs, datasheets). No personal data unless the Customer uploads a document containing it. | United States | EU SCCs / UK Addendum or IDTA in MongoDB DPA where required |
| Apple Inc. Privacy · APNs documentation | Apple Push Notification service (APNs) delivery to iOS devices where the user enables push notifications | App-specific device token and notification title/body needed for delivery | Global Apple infrastructure; APNs may temporarily store an undelivered notification | Apple service terms and applicable transfer safeguards |
The AI features (Asset Briefing, AI Engineer, document search) are optional and are being rolled out progressively. Where a per-asset feature is not enabled, that asset is not processed for the per-asset feature. Fleet-level processing runs only where Asset Intelligence is enabled for the organisation.
The connected-lite wireless-sensor telemetry path and the wireless start-inhibit interlock are likewise optional. A LoRaWAN Network Server only processes data for assets on which the Customer has fitted a wireless sensor or interlock device. Where the Customer runs its own network server, that server is the Customer's own infrastructure rather than a Pointnode sub-processor.
Auxiliary services (not sub-processors)
These services are used for our own business operations and do not process Customer personal data:
- GitHub — source code hosting (no Customer data).
- Linear / our internal docs — engineering coordination (no Customer data).
- UptimeRobot — external monitoring of public health endpoints (no Customer data).
Subscribe to sub-processor changes
Org admins are automatically notified of changes by email. To subscribe an additional address (e.g. a Customer's DPO), email privacy@pointnode.io.