Skip to main content

Subprocessors

faktoora uses the following third-party services to provide, support, and secure our platform. All subprocessors have a Data Processing Agreement (DPA) in place, and we regularly review their security posture.

Infrastructure

SubprocessorPurposeLocationCertifications
HetznerCloud hosting and infrastructureGermany (EU)ISO 27001

Payments

SubprocessorPurposeLocationCertifications
StripePayment processing and subscription managementUS (EU SCCs)PCI DSS Level 1, SOC 2
BanksAPIBank transaction matching and reconciliationEUDPA in place

Communication

SubprocessorPurposeLocationCertifications
MailjetTransactional email delivery (invoices, notifications)France (EU)DPA in place

E-Invoicing

SubprocessorPurposeLocation
Peppol networkPan-European e-invoice delivery (AS4 protocol)EU
AEAT (Spanish Tax Authority)VeriFactu mandatory invoice registrationSpain (EU)

AI Services

SubprocessorPurposeLocationData scope
OpenAIOptional AI-assisted product catalogue inputUS (DPA with SCCs)Receives only user-provided input text — never existing product data, invoices, customer data, or personal data

Data Protection

SubprocessorPurposeLocation
PROLIANCE GmbHExternal Data Protection OfficerGermany (Munich)

Customer-Configured Integrations

The following services may process customer data when explicitly configured and authorised by the customer. faktoora does not send data to these services unless the customer enables the integration.

ServiceCategoryPurpose
XeroAccountingInvoice and contact synchronisation
DATEVAccountingGerman tax advisor data exchange
BexioAccountingSwiss accounting synchronisation
WeclappERPBusiness process synchronisation
HubSpotCRMContact and deal synchronisation
PipedriveCRMSales pipeline synchronisation
Monday.comCRMProject and contact management
Custom SMTP/IMAPEmailCustomer-provided email servers for sending and receiving
Custom webhooksIntegrationCustomer-defined HTTP endpoints for event notifications

Customers maintain their own relationships and agreements with these providers. faktoora acts as a processor under the customer's instructions for these integrations.

Evaluation Criteria

When selecting subprocessors, we evaluate:

  • Data residency — EU-based hosting preferred; non-EU requires Standard Contractual Clauses
  • Security certifications — ISO 27001, SOC 2, PCI DSS, or equivalent required for critical services
  • Data Processing Agreements — mandatory for all personal data processors
  • Encryption — TLS 1.2+ in transit and encryption at rest required for critical services
  • Incident notification — timely breach notification obligations

Review Schedule

Supplier classificationReview frequency
CriticalQuarterly
ImportantAnnually
StandardAnnually

Changes to This List

We will notify affected customers before engaging a new subprocessor that processes personal data. If you have questions about our subprocessors, contact compliance@faktoora.com.