Sub-processors

Last updated: 2026-09-14

These are the third parties that process data on behalf of our customers. For each one: what it does, what it receives, where it processes, and whether anything leaves the European Economic Area.

OVHcloud (OVH SAS)

France

Hosts the application servers, the database and your files.

Data received:
All of your workspace data — users, assets, work orders, inventory, documents, HSE records. Compute and database in Gravelines; file storage replicated to Strasbourg, where backups are kept. ISO 27001, 27017 and 27018 certified.
Transfer outside the EEA:
None.
Their privacy policy

Lemon Squeezy, LLC

United States

Merchant of Record: the legal seller of paid subscriptions, handling collection, tax and invoicing.

Data received:
Name, email address, billing address, invoice lines and subscription history. Card details are held by Lemon Squeezy — we never store any.
Transfer outside the EEA:
Yes — covered by the European Commission's Standard Contractual Clauses (implementing decision 2021/914).

Only for subscriptions paid by card. A free account, or one invoiced by bank transfer, never reaches this provider.

Their privacy policy

Postal

France

Main outbound mail server for transactional email.

Data received:
Email addresses, names, and the content of the messages the service generates.
Transfer outside the EEA:
None.

Self-hosted on our own infrastructure in France — not a separate third party.

Brevo (Sendinblue SAS)

European Union

Critical email (address verification, password reset, invitations) and backup when the main channel is unavailable.

Data received:
Email addresses, names, and the content of transactional messages. ISO 27001 certified.
Transfer outside the EEA:
None.
Their privacy policy

OpenRouter, Inc.

United States

Gateway to the language models behind the AI features: assistant, failure analysis, photo diagnosis, voice transcription.

Data received:
Only what is submitted to the feature — the question asked, the equipment description or photo, the voice recording, and the context needed to answer. Never a bulk extract of your database.
Transfer outside the EEA:
Yes — covered by the European Commission's Standard Contractual Clauses (implementing decision 2021/914).

You can switch the AI features off for your whole company. Switched off, nothing at all reaches this provider.

Their privacy policy

Firebase Cloud Messaging (Google Ireland Limited)

European Union and United States

Delivers push notifications to the mobile app.

Data received:
Device token, plus the title and body of the notification.
Transfer outside the EEA:
Yes — covered by the Standard Contractual Clauses and the EU-US Data Privacy Framework.

Only for people who installed the mobile app.

Their privacy policy

Google Ireland Limited · Apple Distribution International Ltd

European Union and United States

"Continue with Google / Apple" sign-in, at the user's choice.

Data received:
Account identifier, email address, name.
Transfer outside the EEA:
Yes — covered by the Standard Contractual Clauses and the EU-US Data Privacy Framework.

Strictly optional. Signing in with an email and a password involves neither of them.

Their privacy policy

Bugsink

France

Technical error tracking, so we can find and fix faults.

Data received:
Error traces and minimal context (company identifier, role). Passwords, session cookies and tokens are stripped before transmission. Kept 30 days.
Transfer outside the EEA:
None.

Self-hosted on our own infrastructure in France — not a separate third party.

OpenPanel

France

Product usage measurement. Being replaced by PostHog.

Data received:
Usage events, company identifier, pseudonymous user identifier. Cookieless. No business data.
Transfer outside the EEA:
None.

Self-hosted on our own infrastructure in France — not a separate third party.

Ory Polis

France

Enterprise single sign-on (SAML 2.0, OIDC, SCIM 2.0) for customers connecting their own identity provider.

Data received:
Identity-provider configuration, authentication assertions, directory attributes synchronised over SCIM.
Transfer outside the EEA:
None.

Self-hosted on our own infrastructure in France — not a separate third party.

Enterprise plan only, and only for customers who connected an identity provider.

PostHog, Inc. — PostHog Cloud EU

Germany

Product usage measurement: which features are used and where people get stuck. Also used to compare two versions of a screen (A/B testing) and to offer short in-app questionnaires.

Data received:
Action names (never their content), company identifier, pseudonymous user identifier, page visited, approximate location (country, city, postal code). IP addresses are not retained. Never your maintenance content: no work order text, no documents, no photos, no AI questions or answers.
Transfer outside the EEA:
None.

Subject to visitor consent. If analytics cookies are declined, nothing is loaded and nothing is sent. Session recording covers a closed list of public pages on our website only — never a screen of the application.

Their privacy policy

What we do not use

  • No audience measurement and no advertising tag inside the application. Google Analytics loads only on the public pages of our website, never on authenticated screens nor on a customer's public QR forms. No authenticated user's identity is sent to Google.
  • Microsoft Clarity was removed entirely on 14 September 2026. None of its scripts is served on any page.
  • No Facebook Pixel, and no social network pixel of any kind, anywhere.
  • No external CDN handling authenticated data.
  • No sale, rental or sharing of your data with any third party, for any purpose.
  • No AI model is trained on your data. The AI gateway is used for inference only, when a user asks for it.

When this list changes

Adding or removing a sub-processor is notified to every customer in writing, in advance. You then have thirty (30) days to object with reasons. We look for a solution together; failing that, you may terminate without penalty. Publishing this page does not replace that written notice.

Need the Data Processing Agreement and its formal annex for your legal team? Ask us and we will send them.

Privacy · Security & compliance