Skip to content

CloudBridal — Subprocessor Register

Last updated: 30 September 2026

This register lists the third parties in the CloudBridal data flow. Sections A and B are Sub-processors that process personal data on CloudBridal's instructions under Article 28. By agreeing to CloudBridal's Data Processing Agreement, customers give general written authorisation for these Sub-processors; CloudBridal gives at least 30 days' notice of any change and imposes data protection obligations no less protective than its DPA. Section C lists independent third-party controllers.

For personal data of EU/UK data subjects transferred outside the EEA/UK, the transfer mechanism is the EU Standard Contractual Clauses and/or the relevant party's adequacy certification (e.g. EU-US Data Privacy Framework). Each party below publishes its own DPA or transfer safeguards.

To receive advance notice of changes to this list, email support@cloudbridal.com and we'll add you to our notification list.


A. Core sub-processors (always in the data path)

Sub-processorLegal entityPurposePersonal data categoriesRegion
Microsoft AzureMicrosoft CorporationHosting and infrastructure: SQL Database, Blob Storage (uploaded documents, signatures, photos), Storage Queues, Functions, Application Insights, and self-hosted Container Apps (PDF generation, GeoIP lookup)All application personal data, uploaded documents, IP/geolocation, telemetryUS (East US 2)
PostmarkActiveCampaign, LLC (Postmark)Transactional email (receipts, invites, password resets, reminders)Email address, name, order/appointment/payment details, one-time codesUS
TwilioTwilio Inc.SMS notifications, one-time codes, remindersPhone number, name, message contentUS
SentryFunctional Software, Inc. (dba Sentry)Error and performance monitoring (backend, Functions, frontend)Diagnostic data (user ID, request metadata); PII scrubbing enabled to minimise personal dataUS

B. Optional / tenant-activated sub-processors

These process personal data only in the circumstances shown under Trigger: typically where a tenant enables the integration or service, or contacts support.

Sub-processorLegal entityPurposePersonal data categoriesTrigger
Vonage (Nexmo)Vonage Holdings Corp.Alternative SMS providerPhone number, name, message contentTenant selects Vonage as SMS provider
MailchimpThe Rocket Science Group LLC (Intuit)Email marketing and audience sync, on the tenant's instructionEmail, name, phone, contact listsTenant connects Mailchimp
AnthropicAnthropic, PBCAI-assisted features (drafting and summarising), on the tenant's instruction; AI-assisted support and engineering tooling used by CloudBridal staffName, message content, and the customer, appointment and order details relevant to the request; support correspondence and diagnostic dataTenant enables AI features, or CloudBridal staff handle the tenant's support request or diagnostic data
OpenAIOpenAI OpCo, LLCAI-assisted features (drafting and summarising), on the tenant's instruction; AI-assisted support and engineering tooling used by CloudBridal staffName, message content, and the customer, appointment and order details relevant to the request; support correspondence and diagnostic dataTenant enables AI features, or CloudBridal staff handle the tenant's support request or diagnostic data
VercelVercel Inc.Hosting of tenant websites built and run by CloudBridalWebsite visitor IP address and request metadata; contact-form submissions in transitTenant uses the CloudBridal website service
ResendPlus Five Five, Inc. (Resend)Delivery of website contact-form submissions to the tenant by emailName, email address, phone number, event date, message contentTenant uses the CloudBridal website service
CloudflareCloudflare, Inc.Spam protection (Turnstile) on website contact formsIP address and browser signalsTenant's website has spam protection enabled
CrispCrisp IM SASCustomer support: live chat, help centre and contact form (data stored in the EU)Name, email address, and support conversation content, including any customer details a tenant shares in a requestTenant contacts CloudBridal support

C. Independent controllers / third-party recipients (not sub-processors)

These parties determine the purposes and means of their own processing under their own terms and are not engaged by CloudBridal as Article 28 Sub-processors. They are listed for transparency of the data flow. Each maintains its own transfer safeguards.

RecipientLegal entityPurposePersonal data categoriesRegion
StripeStripe, Inc.Payment processing, subscription billing, payoutsCardholder name, payment card data, billing address, transaction history, emailUS / EU
GoogleGoogle LLCreCAPTCHA, OAuth sign-in, Places address autocompleteIP address and risk signals; (OAuth) email and profile; (Places) typed address fragmentsUS
QuickBooks (Intuit)Intuit Inc.Accounting integration (tenant-activated)Customer/vendor names, transaction line itemsUS