The third-party sub-processors below are engaged in the operation of Sanad. We notify all tenants by email at least 30 days before any addition or material change.
| Sub-processor | Purpose | Region | Data accessed |
|---|---|---|---|
| Supabase | PostgreSQL database hosting (ap-south-1) | India | Tenant data, signed artifacts, hash chains |
| Vercel | Application hosting (functions pinned to bom1, Mumbai) + global edge cache | India (bom1) + global edge | Application requests; tenant data only at request-time |
| Razorpay | Subscription billing | India | Tenant billing email + payment metadata |
| Resend | Transactional email (verification, license delivery, one-time codes, support) | United States | Tenant contact emails, message bodies (including license keys and one-time codes) |
| Sentry | Application error monitoring, only while enabled in production | United States | Application error traces; tenant identifiers are hashed and credentials scrubbed before sending — no compliance records |
For change notifications, ensure your billing contact email is current. Object to any new sub-processor by emailing dpo@cognoshift.in within 30 days of the notification.