Skip to content
Vaze
What’s includedCoverageSecurityCompare plansStart free
Menu
HomeWhat’s includedCoverageSecurityCompare plansStart free

Trust documents

Sub-processors

Effective date: 2026-10-01

PrivacyTermsDPASub-processorsSecurity

This page is the canonical, always-current list of the third parties that process personal data on Vaze's behalf. It is referenced by the Data Processing Agreement and the privacy policy, and it governs if those documents fall out of step with it.

How this list was derived. Every outbound call in the application code was enumerated by reading the call sites, and then the parties that host, proxy and monitor the service were added, because application code cannot see them. "Data reached" describes the most a party can see, not what it necessarily does see in a given deployment. Vaze is an independent controller for operator accounts and the audit trail; Vaze is a processor, acting on the Customer’s documented instructions, for the members, seats, key records and per-person usage it reads from a Connected Vendor, for the history it keeps of those reads, and for customer-selected digest and report recipients. The listed service providers are sub-processors for customer estate data they process, and processors of Vaze for its controller data.

Current — in the technical data path today

PartyPurposeData reachedProcessing locationTransfer mechanism
Microsoft Azure (UK West and UK South)Application host and primary live-state managed disk in UK West; encrypted recovery snapshots in separate Azure storage in UK South.Customer and operator data held in live state and encrypted recovery copies: estate registry, vendor credentials, usage and cost history, audit trails, role bindings, report archives.United KingdomMicrosoft Products and Services Data Protection Addendum, including the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum where an international transfer occurs
CloudflareDNS, TLS edge and the outbound tunnel that reaches the host; Cloudflare Access for restricted private review surfaces where enabled.HTTP requests and responses in transit; IP address and standard request logs; operator e-mail and authentication events where Access is used for private reviews; readiness service-token checks.Global edgeUK Extension to the EU–US Data Privacy Framework; EU SCCs with the UK Addendum under Cloudflare’s DPA
Better StackExternal readiness monitoring and incident e-mail.Hostname, readiness result, response and incident timing, and the alert recipient. The readiness response carries no customer payload.Per Better Stack's DPAEU SCCs with the UK Addendum under Better Stack’s DPA
GoogleIdentity provider for operator sign-in.The operator's e-mail, name and verified flag returned at sign-in.Per Google's termsPer Google's terms
MicrosoftIdentity provider for operator sign-in.The operator's e-mail, name and tenant identifier returned at sign-in.Per Microsoft's termsPer Microsoft's terms

Conditional — engaged only if a customer enables the feature

PartyPurposeData reachedStatus
ResendOutbound digest, report and health e-mail.Recipient e-mail addresses and the rendered digest or report content, which can include per-person names and usage figures where the customer's report includes them.Capability built; delivery disabled on the live service as of 2026-10-01. Processing begins only if a customer enables delivery.
Xero and Intuit QuickBooksOptional spend-feed discovery: reading a customer's accounting transactions to find AI vendors paid for outside the connected accounts.Transaction descriptors, amounts and dates from the customer's own accounting organisation; data flows from the provider to Vaze, not the reverse.Connectors built and verified against provider sandboxes only. No production application is registered; nothing is read until a customer connects one.

Deliberately not on this list

  • The AI vendors themselves — OpenAI, Anthropic, GitHub, Microsoft 365, Google Workspace and OpenRouter. Vaze reads their administrative APIs with credentials for accounts the customer already holds, under the customer's own agreement with each vendor. Connector requests send authentication material and the identifiers and query parameters needed for the requested administrative API operation. Scheduled collection does not upload Vaze's stored estate history. The supported direct write sends the target project and rate-limit identifiers and the new rate limit to OpenAI only through the explicitly approved and human-executed action path. They are not Vaze’s sub-processors: Vaze does not engage them, and each processes on the customer’s own agreement with it. Vaze receives that data from them on the customer’s instruction, and the customer is responsible for having the right to give that instruction.
  • Analytics, error reporting and advertising — none. Neither the website nor the console loads a third-party analytics or error-reporting SDK. Availability monitoring (Better Stack) and platform logging (Azure, Cloudflare) exist and are listed above; that distinction is deliberate.
  • A database provider — there is none. Live application state is files on the single application host; encrypted recovery snapshots are held in the separate Azure storage listed above.

How we notify you of changes

For a Customer whose DPA is in force, we publish and e-mail notice of a later provider addition or replacement at least 30 days before it begins processing personal data, by updating this page and e-mailing the Customer’s primary account contact (and any billing contact named in a paid Order). A Customer that objects on reasonable data-protection grounds may terminate the affected service with effect from the change date. A change of region or role for a provider already on this list is published here and does not create a new notice period.

Questions

privacy@vaze.ai

Vaze
HomeCoverageTool directoryCompare plansMethodsSecurityFor MSPsPrivacycontact@vaze.ai

Vaze is operated by CROSSTENANT LTD (company no. 17349672).