Raysly
FunktionenPreiseNetzwerkAnmeldenJetzt starten
Legal information

Raysly Subprocessor Schedule

Version
1.0.1
Effective date
2026-10-01
Country
GLOBAL
Language
EN

Archived. Current

This schedule lists the subprocessors [COMPANY_NAME] ("Raysly") uses to process Customer Data on behalf of customers ("partners"), under the Raysly Data Processing Agreement. It is incorporated by reference into that DPA.

Notice of changes

We will give notice of an intended addition or replacement of a subprocessor at least [SUBPROCESSOR_NOTICE_DAYS] (currently 30) days before the change takes effect, as described in the DPA (§6), so that you have the opportunity to object on reasonable data-protection grounds. We will notify you by email to the account owner and by publishing an updated version of this page with a visible "last updated" date, consistent with dpa.md §6.

Subprocessors used for processor (partner-data) activities

The table below lists vendors that the fact base shows in code as capable of touching partner/customer data in the course of operating features a partner has enabled. Inclusion in this table does not by itself prove a signed data processing agreement is in place with that vendor, or that the vendor is active in your specific deployment — features are opt-in per partner, and some entries depend on environment configuration not visible in the codebase. Verify each row against the actual vendor contract before publishing this schedule.

Subprocessor Purpose Data categories Location Feature scope
Vercel Application hosting, serverless functions, scheduled jobs All request data processed by the platform, including partner and customer data in transit Functions pinned to Frankfurt (fra1, EU); other Vercel infrastructure region Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism All
Turso (LibSQL) Primary operational database (leads, orders, partners, sessions, documents metadata) All data partners and customers submit through the platform All
Cloudflare (R2 storage) File storage for uploaded documents, images and DB backups, unless a partner connects its own storage Uploaded customer documents (including ID/title-deed uploads), partner branding assets Region-partitioned buckets (Cyprus/UK/Switzerland/global); vendor's own EU-jurisdiction commitment stated in internal docs but not independently confirmed here Document/image uploads, backups
Cloudflare (Turnstile, DNS/SaaS) Bot protection on public forms; DNS/custom-domain management for partner storefronts Visitor IP address and anti-bot token; domain names Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism Forms, custom domains
Resend Outbound transactional email Recipient address, subject, body of platform emails (a copy is also retained in Raysly's own email log) Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism Email notifications
Postmark Inbound email processing (e.g. forwarded competitor offers) Inbound email content and attachments Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism Offer-upload-by-email feature.
Twilio SMS/phone verification and messaging, including partner-connected Twilio numbers Phone numbers, SMS content EU edge only if the partner's deployment is explicitly configured for it; otherwise Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism SMS, phone verification
Bird (MessageBird) Alternative SMS/verification provider Phone numbers Vendor states EU by default; not independently confirmed SMS, phone verification (where configured)
Sinch Alternative SMS/verification provider Phone numbers, SMS content Defaults to EU API region per vendor configuration SMS, phone verification (where configured)
Xero / QuickBooks / Zoho Books Accounting sync, at the partner's own election Partner's billing contacts and invoice data pushed at partner's direction Accounting integrations (opt-in)
Google (Drive, Calendar, Maps/Geocoding/Solar API, Fonts) Partner-connected storage and calendar; address autocomplete and roof/solar calculations on storefronts; web fonts Address text, coordinates, calendar events, files (where connected); visitor IP (fonts, maps) Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism Integrations, storefront calculator, storefront branding
Microsoft (365/OneDrive, Graph) Partner-connected calendar and storage Calendar events, files (where connected) Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism Integrations (opt-in, beta)
Dropbox Partner-connected storage Files (where connected) Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism Integrations (opt-in, beta)
Amazon S3 (bring-your-own) Partner's own storage, at partner's election Files the partner chooses to store there Partner-controlled Integrations (opt-in)
Shopify Product/inventory/order sync and checkout links, at partner's election Product and order data; partner's Shopify access token (stored encrypted) Partner's own Shopify region Integrations (opt-in)
Meta, LinkedIn, X/TikTok (via OAuth) Social Media Studio posting/insights, at partner's election Partner's connected social account data and content posted through the tool Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism Social Media Studio (opt-in, beta)
OpenAI / Google Gemini (via Vercel AI Gateway) / Mistral / OpenRouter / Groq / self-hosted Ollama Configurable parsing of uploaded competitor-offer documents; AI-assisted roof segmentation from satellite imagery Uploaded customer offer documents; property location/imagery Default is off; the active provider (if any) is a per-region/partner configuration Offer-upload parsing (opt-in), roof segmentation
PostHog Product analytics (autocapture, session analytics); gated on the relevant surface's own consent state before it initialises Visitor interaction data. Server-side events use a pseudonymised identifier derived from email, not the raw address Client-side: EU region (ingestion proxied to eu.i.posthog.com). Server-side: Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism Engagement analytics
Sentry Error monitoring and diagnostics across the whole platform, including storefronts Technical error data; a low sample of session replays with all text/inputs masked Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism Platform-wide
GitLab (CI) Runs the scheduled job that dumps the full primary database and uploads it to backup storage Full database dumps, i.e. all Customer Data in the primary database Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism All (backups)
Upstash (Redis) Rate limiting and short-lived caches IP address and identifiers used as rate-limit keys; cached lookups Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism All
Chatwoot Support inbox used by staff Support messages; contact name, email and phone Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism Support.
Mapbox Forward geocoding; satellite image tile for AI roof segmentation Address query; latitude and longitude of the property Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism Portal address search, roof segmentation
swisstopo / geo.admin.ch (Swiss federal geodata service) Swiss address search from the portal lead screens Address search string Switzerland CH leads
Apple (APNs) / Google (Firebase Cloud Messaging) Mobile push notifications to partner staff Device tokens; notification content, which may include a lead's name Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism Mobile app notifications
Remote antivirus scanning service Scans uploaded documents where configured Uploaded documents Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism Document uploads
Vercel Web Analytics / Speed Insights Page analytics and performance sampling, currently also on storefront pages Page URL, device/browser data Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism All, including storefronts

Decided (DPA §1): for storefront engagement analytics Raysly runs on a partner's behalf and configuration, the partner is controller and Raysly is processor, so PostHog appears in this table for that activity. Raysly's own platform-level analytics and telemetry (PostHog, Sentry, Vercel) run for Raysly's own purposes and are Raysly's own controller activity, disclosed in the Privacy Notice, not this table. Where a partner connects its own Mollie account (Mollie Connect), Mollie acts under its own contract with the partner and is not a Raysly subprocessor; it is therefore not listed here.

End-customer storefront/marketplace payments are the partner's own responsibility, through the partner's own connected provider (for example Mollie Connect or a Stripe Connect equivalent) or the partner's own bank IBAN. [COMPANY_NAME] is not a party to that payment, so Mollie and Stripe are not listed in the processor table above for storefront/marketplace payment processing. Verified 2026-09-28: the platform-account fallback (getPlatformPaymentProvider()) has been removed from src/lib/marketplace/payments/index.ts, so this reflects the live code.

Not independently confirmed; processed within the EU/EEA or, where outside, under Standard Contractual Clauses or another lawful transfer mechanism appearing above means the fact base could not confirm the processing region in code; each such row must be confirmed against the actual signed vendor agreement before this schedule is published or relied on contractually.

Vendors handling data for Raysly's own controller activities (not partner data)

These vendors process personal data for which Raysly itself is the controller (see the Privacy Notice) — for example, Raysly's own account-holder, billing-contact and marketing data. They are listed separately because they are not subprocessors under the DPA above; they are Raysly's own vendors.

Vendor Purpose
Vercel Hosting of raysly.com, sign-up and the partner portal
Turso (LibSQL) Database holding partner accounts, team members, sessions (IP address, user agent, city/country) and the email log
Cloudflare (R2, Turnstile) File storage and backups; bot check on sign-up
GitLab (CI) Scheduled full-database backups
Upstash (Redis) Rate limiting on sign-up and login (IP address)
Twilio / Bird / Sinch SMS one-time codes for partner login
Google / Apple (and other enabled social login providers) Social sign-in for partner accounts
Google Maps Address autocomplete during onboarding
EU VIES Validation of partners' VAT numbers
Chatwoot Support conversations with partners
Resend Raysly's own transactional account/billing emails
Google Analytics 4 / PostHog Analytics on raysly.com and the partner portal (see the Cookie Policy)
Sentry Error monitoring on raysly.com and the partner portal
Vercel Web Analytics / Speed Insights Performance analytics on raysly.com and the partner portal
Mollie / Stripe / Revolut Processing partners' own subscription payments to Raysly
Revolut Business Read-only bank feed for reconciling Raysly's own account (may show payer names)
Slack Internal staff notification tooling (not customer-facing)

Mollie / Stripe / Revolut, above, is a different relationship from anything in the processor table. Here, these providers process Customer Data belonging to [COMPANY_NAME] itself — Raysly is billing its own partner customer for their Raysly subscription fee, a genuine controller-side activity. This must not be confused with end-customer storefront/marketplace payments (see the note in the processor table above): per the founder's 2026-09-24 decision, those payments are the partner's own responsibility through the partner's own connected provider or bank account, [COMPANY_NAME] is not a party to them, and Mollie/Stripe are accordingly not listed as Raysly subprocessors for that separate purpose.

Version history

  • Version 1.0.2 · 2026-10-01
  • Version 1.0.1 · 2026-10-01
© Raysly — das Betriebssystem für Solarinstallateure.
NutzungsbedingungenDatenschutzhinweiseKontaktCookie-HinweiseRechtliche Informationen