These third-party vendors process customer data on Arendel's behalf to deliver the service. Last updated: July 2026.
We notify customers at least 30 days before adding a new sub-processor. To receive notifications, email trust@arendel.io.
| Vendor | Purpose | Data type | Location |
|---|---|---|---|
| Vercel | Application hosting | All Arendel application data in transit | US (with regional failover) |
| Neon | Postgres database | Org data, user accounts, deals, audit log | US East |
| Cloudflare R2 | Document storage | Uploaded files (data room contents) | Auto (configurable per org) |
| Clerk | Authentication | Email, name, password hash, 2FA secrets, session tokens | US |
| Anthropic | AI (Workshop, IC memo, red-flag review, next-action) | Document text, deal metadata, user prompts | US |
| OpenAI | Document embeddings (Smart Search) | Document text, embedding vectors | US |
| Resend (Amazon SES upstream) | Transactional email | Email addresses, subjects, bodies of notifications | US |
| Sentry | Error monitoring | Stack traces, request URLs, user IDs (no payloads) | US (EU available) |
| Stripe | Subscription billing | Billing email, payment method (tokenized), invoices | US, EU, UK |
| AWS KMS | Encryption key management (field-level encryption) | Encrypted-key material only (no plaintext data) | US East |
| DocuSign | E-signature for LOIs | Signer name, email, signature event timestamps | US, EU |
| AssemblyAI | Meeting transcription (opt-in) | Audio uploads, generated transcripts | US |
| Twilio | SMS 2FA + wire-release confirmation | Phone numbers, SMS body | US |
| Plaid | Bank account verification (closing) | Bank account holder name + last-4 (no balances) | US |
| Intuit QuickBooks | Portfolio company accounting sync | QBO OAuth tokens, financial summaries | US |
| Xero | Portfolio company accounting sync | Xero OAuth tokens, financial summaries | US, EU |
| Google Workspace | Drive import, Gmail sync, Calendar sync (opt-in) | Per-user OAuth tokens, mailbox metadata | US (regional) |
| Microsoft Graph | Outlook + Teams sync (opt-in) | Per-user OAuth tokens | US, EU |
| Slack | Deal-channel notifications (opt-in) | OAuth tokens, channel IDs | US |
Customer data is hosted in the United States by default. Enterprise customers can request EU data residency, in which case Neon and Cloudflare R2 storage are pinned to EU regions, and we route customer-facing traffic through EU edge locations. Sub-processors that don't offer EU residency (such as Anthropic and OpenAI) continue to process the relevant inputs in the United States, which the EU residency-tier DPA contemplates.
Arendel does not use any affiliate or subsidiary entity to process customer data. Arendel Inc. is the sole controller of its own employees with access to customer data.