nvena
TrustHelpFAQContactOpen app

Subprocessor register

Invena Labs Limited (trading as invena)
167-169 Great Portland Street, 5th Floor, London W1W 5PF, United Kingdom
Company number 17237229
Registered in England and Wales

Version: 0.10.4 (beta)
Last updated: 1 August 2026
Last reviewed: 1 August 2026

Invena is in private beta. This register describes third-party providers we use today to operate the service. It includes beta-only tooling where that provider may process personal data on our instructions.

For how we handle personal data generally, see our Privacy Policy.


1. Purpose of this page

This page lists third-party providers that process personal data on our instructions to help us operate the Invena service.

We review this list periodically. Where required by law or contract, we will provide notice before material changes take effect. Material changes will also be reflected on this page.


2. What we mean by “subprocessor”

For the purposes of this page, a subprocessor is a third-party processor we engage to process personal data on our behalf in connection with the Invena service.

Some vendors we use for internal development, domain registration, or other operational support may not be subprocessors in the strict UK GDPR sense. Where that is the case, we list them separately under Other service providers.

We engage subprocessors under appropriate contractual terms, including data processing terms where required. Where personal data is transferred internationally, we use safeguards required by UK data protection law and, where applicable, EEA law.


3. Core subprocessors

These providers may process personal data on our instructions. The data categories align with our Privacy Policy (account data, Space metadata, uploaded documents, audit metadata, error monitoring, and transactional email).

SubprocessorServicePersonal data processedProcessing locationNotes
SupabaseDatabase, authentication, file storageAccount email; Space and entry metadata; uploaded documents; audit metadataWest Europe (London)Core service processor
RailwayAPI application hostingRequest metadata; application logs; configuration secretsUnited StatesBackend hosting; ClamAV malware scan sidecar (SEC-009)
VercelWebsite and product application hostingHTTP request metadata; session cookies on product app; static and dynamic pagesUnited States / global edge networkwww.invena.app (legal) and app.invena.app (Next.js product UI)
CloudflareBot protection on product auth (Turnstile)Challenge tokens; limited client/browser signals used for bot detectionGlobal edge networkLive on app.invena.app login, signup, and related auth forms; Customer DPA on file
ResendTransactional email (invitations, privacy-request acknowledgements, completion notices)Recipient email address; invitation and customer-request metadataUnited StatesTransactional email only
SlackOperator alerts for new privacy requests (Incoming Webhook)Masked reporter email; ticket reference; request type; SLA dateUnited StatesInternal operator channel only; minimised payloads; not the compliance ledger
SentryError monitoring and diagnosticsError stack traces; correlation IDs; scrubbed request metadataEuropean UnionError telemetry; we configure scrubbing to reduce personal data
UptimeRobotUptime and availability monitoringHealth-check metadata; service availability dataUnited StatesMonitors our API health endpoint
Plausible Insights OÜCookieless website analytics (marketing site)Aggregate page views, referrers, and limited technical traffic dataEuropean UnionEnabled only when configured on invena.app / www.invena.app; not loaded on app.invena.app
Google Cloud (Vision API)Optional Photo / document extraction (OCR preview)Document bytes you choose to Extract; returned text previewEuropean Union (eu-vision endpoint for UK/EU beta)User-directed Extract only; see AI Policy.
Google (Gmail API)Optional inbox connect (read-only)Connected Gmail address; encrypted OAuth tokens; selected labels/senders; transient scoped message metadata and attachmentsUnited States / Google global infrastructuregmail.readonly only; no send/delete; no full mailbox replica; tokens removed on Disconnect
Microsoft (Graph API)Optional Outlook / Microsoft 365 inbox connect (read-only)Connected Microsoft email address; encrypted OAuth tokens; selected folders/senders; transient scoped message metadata and attachments when enabledUnited States / Microsoft global infrastructureMail.Read only; inactive until Azure/Railway env is set; no send/delete; no full mailbox replica; tokens removed on Disconnect
Managed map tiles + geocoding provider (planned)Production Place map tiles and geocodingAddress search; tile/view area; place labelsUK/EU preference, to be confirmed on enableInactive until contracted and enabled in the product environment. Listed for advance notice before cutover.

Uses customer personal data? Yes for active rows above, to the extent described. Microsoft Graph does not receive customer data until operator Azure enablement. The managed map provider does not receive customer data until contracted and enabled.

Place maps (Jul 2026): Continuity Place may call public OpenStreetMap / Nominatim endpoints for preview and geocoding during closed beta (see §3a). We will update this register before enabling a managed tiles and geocoding provider for production.

Trust Centre breach check (PIP-1): the in-app card deep-links you to Have I Been Pwned’s free search. You enter your email on their site; Invena does not transmit your email to HIBP for that check. A paid HIBP API integration (if enabled later) would be listed here before it goes live.

Visible in the customer-facing product? Supabase, Railway, Vercel (app.invena.app), Resend, and Cloudflare Turnstile (auth forms) support the product experience. Slack supports internal operator workflows when enabled. Vercel also serves www.invena.app visitors. Sentry and UptimeRobot are not customer-facing products.

Added (1 Aug 2026): Cloudflare Turnstile enabled on Continuity auth forms.
Removed (Jul 2026): A short-lived support-inbox trial ended; email and in-app paths remain available for privacy and support requests. Streamlit Cloud was removed from this register (28 Jul 2026) after the product UI moved fully to app.invena.app.


3a. Closed-beta map preview (community endpoints)

These providers are public / community endpoints, not commercial subprocessors with a negotiated customer DPA. We list them for transparency during closed beta.

ProviderServicePersonal data processedProcessing locationNotes
OpenStreetMap / Nominatim (community endpoints)Beta Place map preview and geocode / reverse geocodeAddress search strings; tile/view coordinates; returned place labelsGlobal public endpointsClosed beta only. No customer DPA. Replace before open signup / GA with the managed provider in §3. Not used for vault document storage.

4. Internal processing components

These tools form part of our technical controls. They are not external subprocessors.

ComponentPurposeData processedLocation
ClamAV sidecarMalware scanning on document and avatar uploadFile bytes during scan only, on an ephemeral basisSame region as our backend/API environment

ClamAV is self-hosted alongside our API on Railway. We do not send uploaded files to a separate ClamAV vendor. Enabled in production since June 2026 (fail-closed on scan failure).


5. Other service providers

These providers support Invena operationally but do not normally process customer content on our behalf in the course of providing the Invena service to you.

ProviderPurposeProcesses customer personal data?Notes
GoDaddyDomain registration and DNS for invena.appNo, subject to ordinary DNS/registration logsDomain and DNS infrastructure only
GitHubSource code hostingNo customer vault dataDevelopment and source control only

6. Data residency summary

Primary customer content — including Spaces, entries, and documents — is stored in Supabase in West Europe (London) (UK), as described in our Privacy Policy. Other service components may process data in the UK, the EEA, or other countries listed in this register.

Some subprocessors process data in other jurisdictions — for example the United States for transactional email, website/product edge hosting, API hosting, and certain monitoring services, and the European Union for error monitoring — where necessary to provide the service. Where we transfer personal data internationally, we use appropriate safeguards required by UK data protection law and, where applicable, EEA law.


7. Changes to this register

We may add, remove, or replace subprocessors as the service develops. Where required by law or contract, we will provide notice before a material change takes effect and before the new processing begins.

Notice approach: Our operational aim is to give reasonable advance notice (typically 14 days where practicable) before adding a subprocessor that materially changes how we process your personal data. This timing is an operational target, not a substitute for any legal or contractual notice requirement. We update this page and our Privacy Policy at the same time.

App Store privacy labels must reflect our actual data practices — separate from subprocessor notice timing.


Contact

Privacy questions: privacy@invena.app

nvena

Product

  • Trust centre
  • Help centre
  • FAQ
  • Security
  • Open app

Company

  • About
  • Contact
  • Beta access

Resources

  • Legal
  • Privacy Policy
  • AI Policy
  • Terms of Service
  • Acceptable Use
  • Content & Use
  • Accessibility
  • Cookies
  • Copyright
  • Subprocessors
  • Open Source

Built in Chichester, England. Privacy-first by design. Designed for life's important moments.

Invena Labs Limited trading as invena. Company number 17237229. Registered office: 167-169 Great Portland Street, 5th Floor, London W1W 5PF, United Kingdom. Registered in England and Wales.

© 2026 Invena Labs Limited