Provider and role disclosure
Subprocessors used for Workspace processing
This disclosure identifies current providers that can process customer personal data on behalf of NOCTRA for Workspace services. It is scoped to the Workspace processor relationship; public marketing services are not included as Workspace subprocessors.
- Version
- 1.0
- Last updated
- 2026-08-28
Related documents
Provider entity, region, transfer mechanism, provider DPA date and change date remain unpublished unless verified from the applicable contract or configuration.
Subprocessor change process
Before adding or replacing a Workspace subprocessor, NOCTRA provides notice through the applicable contract or billing contact or a designated Platform notice channel with enough advance time, where practicable, for an objection on objectively justified data-protection grounds. The parties first seek a reasonable solution where practicable. Urgent security, legal or provider circumstances may require shorter notice.
A. Workspace subprocessors
Services used to process customer-controlled Workspace data on NOCTRA’s behalf. Account-specific contract and transfer facts remain subject to the applicable provider account and agreement.
Supabase
Supabase’s published DPA describes Supabase as processor or subprocessor for covered customer data. Coverage for NOCTRA depends on the applicable provider account and accepted terms.
Provider reference- Current classification
- Workspace subprocessor
- Activation
- Platform service
- Processing purpose
- Authentication, relational data storage, guarded database operations and file storage.
- Relevant NOCTRA functionality
- Supabase Auth; Workspace and Event application data; RPC and RLS enforcement; organizer branding and Event-cover storage.
- Potential data categories
- Account, Workspace, organizer, Event, attendee, buyer, ticket, Door, report, tax-document, audit and media data.
- Contracting provider entity
- Supabase, Inc.
- Processing region / location
- Not verified in repository
- Transfer mechanism
- Not verified in repository
- Provider DPA date
- Not verified in repository
- Provider change type
- Current inventory
- Change date
- Not verified in repository
- Effective date
- Not verified in repository
- Notification status
- Current inventory — no change notification recorded
- Customer objection mechanism
- Not verified in repository
Vercel
Vercel’s published DPA describes Vercel as processor for covered Customer Data on eligible plans. NOCTRA’s account plan and DPA eligibility require external confirmation before paid B2B launch.
Provider reference- Current classification
- Workspace subprocessor
- Activation
- Platform service
- Processing purpose
- Application hosting, request delivery and server runtime execution.
- Relevant NOCTRA functionality
- Public website, protected application routes, API routes and server-rendered Workspace functionality.
- Potential data categories
- Request and device metadata and application data processed by invoked server routes.
- Contracting provider entity
- Vercel Inc.
- Processing region / location
- Not verified in repository
- Transfer mechanism
- Not verified in repository
- Provider DPA date
- Not verified in repository
- Provider change type
- Current inventory
- Change date
- Not verified in repository
- Effective date
- Not verified in repository
- Notification status
- Current inventory — no change notification recorded
- Customer objection mechanism
- Not verified in repository
Resend
Resend’s published DPA identifies Plus Five Five, Inc. as processor for customer email data. Coverage for NOCTRA depends on the applicable provider account and accepted terms.
Provider reference- Current classification
- Workspace subprocessor
- Activation
- Only when the relevant feature is used
- Processing purpose
- Server-side delivery of transactional invitations, access messages, tickets and contract confirmations.
- Relevant NOCTRA functionality
- Transactional email delivery and related delivery-attempt handling; no Resend browser script is used.
- Potential data categories
- Buyer name and email, Event and ticket details, protected reservation link, provider message reference and delivery metadata.
- Contracting provider entity
- Plus Five Five, Inc.
- Processing region / location
- Not verified in repository
- Transfer mechanism
- Not verified in repository
- Provider DPA date
- Not verified in repository
- Provider change type
- Current inventory
- Change date
- Not verified in repository
- Effective date
- Not verified in repository
- Notification status
- Current inventory — no change notification recorded
- Customer objection mechanism
- Not verified in repository
Upstash Redis
Upstash’s published DPA describes Upstash as processor for covered Customer Personal Data. Coverage for NOCTRA depends on the applicable provider account and accepted terms.
Provider reference- Current classification
- Workspace subprocessor
- Activation
- Only when the relevant feature is used
- Processing purpose
- Server-side rate limiting for selected reservation and refund operations.
- Relevant NOCTRA functionality
- Abuse and availability protection using route or Event scopes; Upstash limiter analytics is disabled.
- Potential data categories
- HMAC-derived pseudonymized request-origin signal, Event or route scope, counters and reset metadata.
- Contracting provider entity
- Upstash, Inc.
- Processing region / location
- Not verified in repository
- Transfer mechanism
- Not verified in repository
- Provider DPA date
- Not verified in repository
- Provider change type
- Current inventory
- Change date
- Not verified in repository
- Effective date
- Not verified in repository
- Notification status
- Current inventory — no change notification recorded
- Customer objection mechanism
- Not verified in repository
B. Payment providers and mixed or independent roles
Payment services can perform different legal roles across Connect, checkout, payment, refund and compliance activities. No single role is forced across all processing.
Stripe
Payment and Connect activities may involve processor and independent or separate-controller roles. No single classification is asserted until the actual Stripe contracts and data flows are reviewed.
Provider reference- Current classification
- Pending legal classification
- Activation
- Only when the relevant feature is used
- Processing purpose
- SaaS subscription billing, Stripe Connect organizer onboarding, hosted ticket checkout, payment processing and refunds.
- Relevant NOCTRA functionality
- Platform subscription billing, connected organizer payment accounts, hosted buyer payment surfaces, server payment API and verified Connect webhooks.
- Potential data categories
- Organizer payment-account information; buyer contact and billing data; order, checkout, payment and refund references and amounts.
- Contracting provider entity
- Not verified in repository
- Processing region / location
- Not verified in repository
- Transfer mechanism
- Not verified in repository
- Provider DPA date
- Not verified in repository
- Provider change type
- Current inventory
- Change date
- Not verified in repository
- Effective date
- Not verified in repository
- Notification status
- Current inventory — no change notification recorded
- Customer objection mechanism
- Not verified in repository
