Sub-processors

InvoHub engages the following sub-processors to deliver our service. Each sub-processor is contractually bound to data processing standards equivalent to ours, and is assessed for security, compliance, and EU data residency posture.

Current sub-processors

Sub-processorPurposeLocationData accessedSafeguards
AnthropicAI invoice extraction (Claude)USInvoice content (PDFs, text)Zero data retention configured; no model training
AWSObject storage (S3) for invoice filesEU (Frankfurt)Encrypted invoice filesAES-256, EU-only buckets, SCC 2021
NeonManaged PostgreSQL databaseEU (Frankfurt)Account, tenant, invoice metadataRow-level security, encrypted at rest
GoogleGmail OAuth + Pub/Sub for mailbox watchingEU (multi-region)Gmail metadata + message IDsOAuth scopes minimized to gmail.readonly
MicrosoftOutlook OAuth for mailbox accessEUOutlook metadata + message IDsMicrosoft Graph scopes minimized
ReplitApplication hostingEUApplication runtimeEU-region deployment, SCC 2021

Notification of changes

We notify customers at least 30 days before adding or replacing a sub-processor. Notification is sent to the email address associated with the account.

Object to a sub-processor

If you object to a new sub-processor, contact hello@invohub.eu before the 30-day notice period ends. We will work with you in good faith; if no resolution is reached, you may terminate the affected service.

Contact

hello@invohub.eu