NOCTRA

Provider and role disclosure

Subprocessors used for Workspace processing

This disclosure identifies current providers that can process customer personal data on behalf of NOCTRA for Workspace services. It is scoped to the Workspace processor relationship; public marketing services are not included as Workspace subprocessors.

Version
1.0
Last updated
2026-08-28

Provider entity, region, transfer mechanism, provider DPA date and change date remain unpublished unless verified from the applicable contract or configuration.

Subprocessor change process

Before adding or replacing a Workspace subprocessor, NOCTRA provides notice through the applicable contract or billing contact or a designated Platform notice channel with enough advance time, where practicable, for an objection on objectively justified data-protection grounds. The parties first seek a reasonable solution where practicable. Urgent security, legal or provider circumstances may require shorter notice.

A. Workspace subprocessors

Services used to process customer-controlled Workspace data on NOCTRA’s behalf. Account-specific contract and transfer facts remain subject to the applicable provider account and agreement.

  1. Supabase

    Supabase’s published DPA describes Supabase as processor or subprocessor for covered customer data. Coverage for NOCTRA depends on the applicable provider account and accepted terms.

    Provider reference
    Current classification
    Workspace subprocessor
    Activation
    Platform service
    Processing purpose
    Authentication, relational data storage, guarded database operations and file storage.
    Relevant NOCTRA functionality
    Supabase Auth; Workspace and Event application data; RPC and RLS enforcement; organizer branding and Event-cover storage.
    Potential data categories
    Account, Workspace, organizer, Event, attendee, buyer, ticket, Door, report, tax-document, audit and media data.
    Contracting provider entity
    Supabase, Inc.
    Processing region / location
    Not verified in repository
    Transfer mechanism
    Not verified in repository
    Provider DPA date
    Not verified in repository
    Provider change type
    Current inventory
    Change date
    Not verified in repository
    Effective date
    Not verified in repository
    Notification status
    Current inventory — no change notification recorded
    Customer objection mechanism
    Not verified in repository
  2. Vercel

    Vercel’s published DPA describes Vercel as processor for covered Customer Data on eligible plans. NOCTRA’s account plan and DPA eligibility require external confirmation before paid B2B launch.

    Provider reference
    Current classification
    Workspace subprocessor
    Activation
    Platform service
    Processing purpose
    Application hosting, request delivery and server runtime execution.
    Relevant NOCTRA functionality
    Public website, protected application routes, API routes and server-rendered Workspace functionality.
    Potential data categories
    Request and device metadata and application data processed by invoked server routes.
    Contracting provider entity
    Vercel Inc.
    Processing region / location
    Not verified in repository
    Transfer mechanism
    Not verified in repository
    Provider DPA date
    Not verified in repository
    Provider change type
    Current inventory
    Change date
    Not verified in repository
    Effective date
    Not verified in repository
    Notification status
    Current inventory — no change notification recorded
    Customer objection mechanism
    Not verified in repository
  3. Resend

    Resend’s published DPA identifies Plus Five Five, Inc. as processor for customer email data. Coverage for NOCTRA depends on the applicable provider account and accepted terms.

    Provider reference
    Current classification
    Workspace subprocessor
    Activation
    Only when the relevant feature is used
    Processing purpose
    Server-side delivery of transactional invitations, access messages, tickets and contract confirmations.
    Relevant NOCTRA functionality
    Transactional email delivery and related delivery-attempt handling; no Resend browser script is used.
    Potential data categories
    Buyer name and email, Event and ticket details, protected reservation link, provider message reference and delivery metadata.
    Contracting provider entity
    Plus Five Five, Inc.
    Processing region / location
    Not verified in repository
    Transfer mechanism
    Not verified in repository
    Provider DPA date
    Not verified in repository
    Provider change type
    Current inventory
    Change date
    Not verified in repository
    Effective date
    Not verified in repository
    Notification status
    Current inventory — no change notification recorded
    Customer objection mechanism
    Not verified in repository
  4. Upstash Redis

    Upstash’s published DPA describes Upstash as processor for covered Customer Personal Data. Coverage for NOCTRA depends on the applicable provider account and accepted terms.

    Provider reference
    Current classification
    Workspace subprocessor
    Activation
    Only when the relevant feature is used
    Processing purpose
    Server-side rate limiting for selected reservation and refund operations.
    Relevant NOCTRA functionality
    Abuse and availability protection using route or Event scopes; Upstash limiter analytics is disabled.
    Potential data categories
    HMAC-derived pseudonymized request-origin signal, Event or route scope, counters and reset metadata.
    Contracting provider entity
    Upstash, Inc.
    Processing region / location
    Not verified in repository
    Transfer mechanism
    Not verified in repository
    Provider DPA date
    Not verified in repository
    Provider change type
    Current inventory
    Change date
    Not verified in repository
    Effective date
    Not verified in repository
    Notification status
    Current inventory — no change notification recorded
    Customer objection mechanism
    Not verified in repository

B. Payment providers and mixed or independent roles

Payment services can perform different legal roles across Connect, checkout, payment, refund and compliance activities. No single role is forced across all processing.

  1. Stripe

    Payment and Connect activities may involve processor and independent or separate-controller roles. No single classification is asserted until the actual Stripe contracts and data flows are reviewed.

    Provider reference
    Current classification
    Pending legal classification
    Activation
    Only when the relevant feature is used
    Processing purpose
    SaaS subscription billing, Stripe Connect organizer onboarding, hosted ticket checkout, payment processing and refunds.
    Relevant NOCTRA functionality
    Platform subscription billing, connected organizer payment accounts, hosted buyer payment surfaces, server payment API and verified Connect webhooks.
    Potential data categories
    Organizer payment-account information; buyer contact and billing data; order, checkout, payment and refund references and amounts.
    Contracting provider entity
    Not verified in repository
    Processing region / location
    Not verified in repository
    Transfer mechanism
    Not verified in repository
    Provider DPA date
    Not verified in repository
    Provider change type
    Current inventory
    Change date
    Not verified in repository
    Effective date
    Not verified in repository
    Notification status
    Current inventory — no change notification recorded
    Customer objection mechanism
    Not verified in repository
Back to NOCTRA