Beebole Sub-processor List
Beebole s.r.l. (Brussels, Belgium) uses the third parties below to help deliver its time-tracking and planning service. This page identifies the sub-processors that may process Customer Data on Beebole's behalf (Beebole acting as processor), separately identifies website/visitor-data processors that do not touch Customer Data, and clarifies which internal vendors are not customer-facing sub-processors.
1. Customer Data sub-processors
These sub-processors may process Customer Data (timesheets, absences, project records, and related account data) where Beebole acts as processor on behalf of the customer (controller). EU customers' Customer Data is hosted in the EU. Where a sub-processor is a US company or processes in the United States, the transfer safeguard is set out in the International transfers section below.
Sub-processor | Purpose | Data categories | Hosting region | Applies to |
|---|---|---|---|---|
Google Cloud | Hosting, logs, backups, audit trails, and self-hosted AI inference (regional) | Account and Customer Data; logs; audit trails; transient AI-classification inputs | EU (EU customers) / US (US customers) | V2 (all V2 customers) |
Intercom | In-product support messenger and product notifications | Contact identifiers (name, email), support messages, and account attributes synced from PostHog (subscription plan and status, subscription quantity and end date, Stripe customer id, app server, onboarding survey answers) | EU | All |
SendGrid (Twilio) | Transactional email delivery (reports, digests, invitations, notifications) | Recipient name, email address, message content | EU (EU data residency enabled) | All |
Stripe | Payment processing | Billing identifiers, payment-method metadata | EU | V2 |
PostHog | Product analytics (session replay not enabled; PostHog's AI features not enabled as at September 9, 2026) | Product usage data of signed-in users (in-app product analytics) and consented website analytics | EU — stored in Frankfurt (AWS Germany) | All |
PEPPOL e-invoicing (EN 16931) | Customer billing identities, invoice data | EU | All | |
n8n Cloud | Automated Stripe → Factures.com billing-data sync | Billing identifiers, invoice/payment metadata | EU | V2 |
Anthropic | AI-assisted customer support — the assistant the support team uses when investigating a support request | The content of a support request (the conversation and the details the agent includes) and account data support staff retrieve from the account the request concerns in order to diagnose the issue | United States | All |
Sentry | Application error monitoring and diagnostics | Exception and stack-trace data, with the affected user's internal id, name and email address attached to aid debugging | EU — Sentry's European region | All |
V1 legacy sub-processors (active during coexistence):
Sub-processor | Purpose | Data categories | Hosting region | Applies to |
|---|---|---|---|---|
Linode | Hosting of the V1 service, including Customer Data | Account and Customer Data | EU | V1 |
Adyen | Payment processing | Billing identifiers, payment-method metadata | EU | V1 |
Dual-platform coexistence
Beebole operates two platforms in parallel during a coexistence period expected to last approximately one to two years. This is a parallel operation, not a one-time cutover:
V1 (legacy): Customer Data hosted on Linode (EU); payments via Adyen.
V2 (new): Customer Data hosted on Google Cloud, region-segregated — an EU server for EU companies and a US server for US companies; payments via Stripe (EU-hosted).
EU customers' Customer Data stays in the EU on both platforms and does not transfer to the United States under V2.
AI features in the product — no third-party AI provider
Beebole's AI-assisted product features (for example suggested time entries and natural-language report building) run on self-hosted models on Beebole-operated Google Cloud instances, region-segregated like the rest of the platform: EU customers' data is processed by the EU inference server and US customers' data by the US inference server. No third-party AI provider is involved in these features, and no Customer Data is sent to any external AI API by the product. These features therefore introduce no sub-processor beyond Google Cloud, listed above.
AI-assisted customer support — Anthropic
Separately from the product features above, Beebole's support team uses Anthropic's Claude assistant to help investigate and answer support requests.
As part of providing support, Beebole's support staff may access a customer's account in order to investigate and resolve that customer's request. Where the assistant is used in that investigation, it processes:
The content of the support request — the conversation, and the details the support agent includes while working on it; and
Data from the account the request concerns, where the support agent retrieves it in order to diagnose the issue.
Use is confined to the individual request being handled. There is no automatic, scheduled or bulk transfer of Customer Data to Anthropic, and the assistant is not used to process data across customers.
Beebole engages Anthropic under Anthropic's Commercial Terms of Service and Data Processing Addendum. Under those terms Anthropic does not train its models on Beebole's or its customers' data, and treats that data as confidential. Anthropic processes data in the United States; see International transfers below. This is support tooling used by Beebole's own staff, and is unrelated to the product AI features described above, which remain entirely self-hosted.
International transfers
Customer Data of EU customers is hosted in the EU. Three sub-processors are US-incorporated companies, and are covered as follows:
Anthropic (United States) — processing takes place in the US. Anthropic is not certified under the EU-US Data Privacy Framework, so this transfer relies on the EU Standard Contractual Clauses (Module Three, processor to processor) as provided in Anthropic's Data Processing Addendum.
PostHog and Sentry — Customer Data is stored in the EU (Frankfurt and Sentry's European region respectively). Both companies are US-incorporated and both are certified under the EU-US Data Privacy Framework, which provides the transfer safeguard for any access from the United States in the course of providing or supporting their services. Standard Contractual Clauses apply in addition under each provider's data processing terms.
Customer-configured AI assistants (not sub-processors)
Customers may choose to connect their own AI assistants (for example Claude or ChatGPT) to Beebole through Beebole's API or MCP connector, using credentials the customer controls. Any data such an assistant accesses is transferred to the customer's chosen AI provider at the customer's direction and under the customer's own agreement with that provider. Those providers act on the customer's behalf, not Beebole's, and are not Beebole sub-processors.
2. Website / visitor-data processors
These processors handle website and documentation-visitor data only. They do not process Customer Data.
Processor | Purpose | Data categories | Hosting region | Applies to |
|---|---|---|---|---|
Vercel | Hosting of the marketing website (no Customer Data) | Website visitor request data | — | All (website visitors) |
Mintlify | Documentation-site (beebole.com/help) visitor analytics | Docs visitor analytics data | — | All (docs visitors) |
3. Internal vendors (not customer-facing sub-processors)
The following vendors support Beebole's own operations, with Beebole acting as controller of the relevant data. They are not sub-processors of Customer Data and do not process Customer Data on customers' behalf:
Asana (internal project management)
Storyblok (content management)
GitHub (source code)
Vanta (compliance/security monitoring)
Partena (Belgian payroll)
Google Workspace (internal productivity and email)
Anthropic (AI assistant used for Beebole's own internal work — engineering, documentation, and analysis of Beebole's own data. Its customer-facing support role is listed in §1 above.)
Changes to sub-processors
Beebole will give customers reasonable prior notice of any new or changed sub-processor. A customer may object within thirty (30) calendar days of that notice on reasonable data-protection grounds. If a customer objects, Beebole will not appoint (or will not continue to use) the sub-processor for that customer's Customer Data and will work in good faith to provide an alternative. This mechanism reflects GDPR Article 28(2).