Sub-processors

Last updated · 18 August 2026

Pointnode Limited uses the following sub-processors to deliver the Pointnode platform. Each is engaged under written data-processing or service terms appropriate to its role and only processes Customer data to provide the service or meet its legal obligations.

We notify org admins by email at least 30 days before adding or replacing a sub-processor. Customers may object before the change takes effect; if a workable alternative cannot be agreed, the Customer may terminate without penalty.

Current sub-processors

ProviderPurposeData processedRegionTransfer mechanism
Supabase Inc.
Privacy · DPA
Postgres database, authentication, file storage, edge functions, realtime subscriptionsAll Customer data — accounts, audit log, telemetry, configuration, uploadsEU (eu-west-1, Ireland)EEA hosting; provider DPA safeguards any restricted onward or support access
Vercel Inc.
Privacy · DPA
Cloud dashboard hosting and CDNRequest metadata and application data transiently processed to render pages and execute server functions; platform logs subject to configured provider retentionMulti-region (edge); EU primarySCCs / IDTA in Vercel DPA
Fly.io Inc.
Privacy · DPA
MQTT-to-database ingest service hosting (pointnode-ingest app), with a persistent volume for the disk-spool retry bufferAsset telemetry in transit; transient retry-buffer contents on diskLondon (lhr)UK hosting; provider DPA safeguards any restricted onward or support access
HiveMQ GmbH
Privacy · DPA
MQTT broker for asset telemetry transportAsset telemetry in transit (machine data, no personal data)EEA-hosted Pointnode clusterEEA hosting; provider DPA safeguards any restricted onward access
The Things Industries B.V.
(LoRaWAN Network Server — where Pointnode provides the managed network server)
Privacy · DPA
LoRaWAN Network Server for the optional connected-lite / wireless sensor telemetry path: routes uplink sensor readings from customer-fitted LoRaWAN devices to the platform, and (where the optional start-inhibit interlock is enabled) routes outbound relay commands to a device. Only engaged where Pointnode provides the managed network server; where the Customer operates its own LoRaWAN Network Server, or Pointnode self-hosts one on its existing Fly.io infrastructure, that path is covered by the Customer's or Fly.io's entry respectively rather than this row.Device radio identifiers (DevEUI), decoded sensor readings and raw uplink payloads, and — for the interlock — outbound relay command bytes. These are normally machine data but can become personal data if linked with an identifiable operator or user action.EEA region selected for the managed serviceEEA hosting; provider DPA safeguards any restricted onward access
Resend Inc.
Privacy · DPA
Transactional email delivery (alerts, password resets, invitations)Recipient email address, alert subject and bodyUnited StatesEU SCCs / UK IDTA in Resend DPA
Stripe Payments Europe Ltd
Privacy · DPA
Subscription billing, invoice generation and delivery, customer billing portal. Card / bank-account capture happens directly between the Customer and Stripe's hosted checkout pages; Pointnode never sees raw payment instrument data.Customer organisation name, billing contact email address, invoice line items and amounts, payment metadataIreland (EU) with US affiliate processingEU SCCs / UK IDTA in Stripe DPA
Functional Software, Inc. (Sentry)
Privacy · DPA · Sub-processors
Application error monitoring and observability. Browser and server-side exception payloads, stack traces, request URL, user-agent, and the authenticated user’s account UUID for correlation. Email addresses are hashed (deterministic SHA-256 prefix) before transmission. Session replay, performance tracing and default PII capture are disabled; a payload scrubber removes email-shaped strings from exceptional error data.Authenticated account UUID, request metadata (URL, user-agent, HTTP status), exception stack trace, environment fingerprintEU (Germany) project region; US provider and authorised global operationsEU SCCs / UK Addendum or IDTA in Sentry DPA where required
Anthropic PBC
Privacy · Trust & sub-processors
Optional AI features — the Asset Briefing (per-asset condition narrative) and the AI Engineer assistant. Asset context is sent to Anthropic's API to generate plain-English analysis. Enabled per asset or organisation according to the licensed Asset Intelligence scope. Anthropic does not train models on commercial API Customer Content by default.Asset telemetry summaries and trends, condition / health signals, event and defect descriptions, compliance status, and the text of questions a user asks the AI Engineer. No payment data or account credentials. Free text and uploaded evidence can contain personal data if a user includes it.United StatesEU SCCs / UK IDTA in Anthropic DPA
Voyage AI (MongoDB, Inc.)
Product · Privacy · DPA
Optional document-vault search (RAG). Generates vector embeddings of documents uploaded to an asset's document vault so the AI Engineer can cite the relevant passage. Enabled per asset (with the Asset Intelligence scope). Organisation-wide features operate only when enabled for that organisation.Text extracted from documents the Customer uploads to an asset (e.g. manuals, drawings, PLC docs, datasheets). No personal data unless the Customer uploads a document containing it.United StatesEU SCCs / UK Addendum or IDTA in MongoDB DPA where required
Apple Inc.
Privacy · APNs documentation
Apple Push Notification service (APNs) delivery to iOS devices where the user enables push notificationsApp-specific device token and notification title/body needed for deliveryGlobal Apple infrastructure; APNs may temporarily store an undelivered notificationApple service terms and applicable transfer safeguards

The AI features (Asset Briefing, AI Engineer, document search) are optional and are being rolled out progressively. Where a per-asset feature is not enabled, that asset is not processed for the per-asset feature. Fleet-level processing runs only where Asset Intelligence is enabled for the organisation.

The connected-lite wireless-sensor telemetry path and the wireless start-inhibit interlock are likewise optional. A LoRaWAN Network Server only processes data for assets on which the Customer has fitted a wireless sensor or interlock device. Where the Customer runs its own network server, that server is the Customer's own infrastructure rather than a Pointnode sub-processor.

Auxiliary services (not sub-processors)

These services are used for our own business operations and do not process Customer personal data:

Subscribe to sub-processor changes

Org admins are automatically notified of changes by email. To subscribe an additional address (e.g. a Customer's DPO), email privacy@pointnode.io.