This schedule lists the subprocessors Luxa Energy LTD ("Raysly") uses to process Customer Data on behalf of customers ("partners"), under the Raysly Data Processing Agreement. It is incorporated by reference into that DPA.
Notice of changes
We will give notice of an intended addition or replacement of a subprocessor at least 30 days before the change takes effect, as described in the DPA (§6), so that you have the opportunity to object on reasonable data-protection grounds. We will notify you by email to the account owner and by publishing an updated version of this page with a visible "last updated" date.
Subprocessors used for processor (partner-data) activities
The table below lists the subprocessors that may process Customer Data when you use the related feature. Many features are opt-in: a subprocessor processes your Customer Data only if you use the feature shown in its "Feature scope" column.
| Subprocessor | Purpose | Data categories | Location | Feature scope |
|---|---|---|---|---|
| Vercel | Application hosting, serverless functions, scheduled jobs | All request data processed by the platform, including partner and customer data in transit | Functions: Frankfurt, Germany (EU). Other Vercel infrastructure: see the provider's data processing terms | All |
| Turso (LibSQL) | Primary operational database (leads, orders, partners, sessions, documents metadata) | All data partners and customers submit through the platform | See the provider's data processing terms | All |
| Cloudflare (R2 storage) | File storage for uploaded documents, images and DB backups, unless a partner connects its own storage | Uploaded customer documents (including ID/title-deed uploads), partner branding assets | Region-partitioned buckets (Cyprus, UK, Switzerland, global); see the provider's data processing terms | Document/image uploads, backups |
| Cloudflare (Turnstile, DNS/SaaS) | Bot protection on public forms; DNS/custom-domain management for partner storefronts | Visitor IP address and anti-bot token; domain names | See the provider's data processing terms | Forms, custom domains |
| Resend | Outbound transactional email | Recipient address, subject, body of platform emails (a copy is also retained in Raysly's own email log) | See the provider's data processing terms | Email notifications |
| Postmark | Inbound email processing (e.g. forwarded competitor offers) | Inbound email content and attachments | See the provider's data processing terms | Offer-upload-by-email feature. |
| Twilio | SMS/phone verification and messaging, including partner-connected Twilio numbers | Phone numbers, SMS content | EU region where the account is configured for it; otherwise see the provider's data processing terms | SMS, phone verification |
| Bird (MessageBird) | Alternative SMS/verification provider | Phone numbers | See the provider's data processing terms | SMS, phone verification (where configured) |
| Sinch | Alternative SMS/verification provider | Phone numbers, SMS content | EU API region (default configuration) | SMS, phone verification (where configured) |
| Xero / QuickBooks / Zoho Books | Accounting sync, at the partner's own election | Partner's billing contacts and invoice data pushed at partner's direction | The partner's own account with the provider | Accounting integrations (opt-in) |
| Google (Drive, Calendar, Maps/Geocoding/Solar API, Fonts) | Partner-connected storage and calendar; address autocomplete and roof/solar calculations on storefronts; web fonts | Address text, coordinates, calendar events, files (where connected); visitor IP (fonts, maps) | See the provider's data processing terms | Integrations, storefront calculator, storefront branding |
| Microsoft (365/OneDrive, Graph) | Partner-connected calendar and storage | Calendar events, files (where connected) | See the provider's data processing terms | Integrations (opt-in, beta) |
| Dropbox | Partner-connected storage | Files (where connected) | See the provider's data processing terms | Integrations (opt-in, beta) |
| Amazon S3 (bring-your-own) | Partner's own storage, at partner's election | Files the partner chooses to store there | Partner-controlled | Integrations (opt-in) |
| Shopify | Product/inventory/order sync and checkout links, at partner's election | Product and order data; partner's Shopify access token (stored encrypted) | Partner's own Shopify region | Integrations (opt-in) |
| Meta, LinkedIn, X/TikTok (via OAuth) | Social Media Studio posting/insights, at partner's election | Partner's connected social account data and content posted through the tool | See the provider's data processing terms | Social Media Studio (opt-in, beta) |
| OpenAI / Google Gemini (via Vercel AI Gateway) / Mistral / OpenRouter / Groq | Configurable parsing of uploaded competitor-offer documents; AI-assisted roof segmentation from satellite imagery | Uploaded customer offer documents; property location/imagery | See the provider's data processing terms | Used only if offer-upload parsing or AI roof segmentation is switched on for your account |
| PostHog | Product analytics; runs only after consent on the relevant site | Visitor interaction data. Server-side events use a pseudonymised identifier derived from email, not the raw address | Client-side: EU region. Server-side: see the provider's data processing terms | Engagement analytics |
| Sentry | Error monitoring and diagnostics across the whole platform, including storefronts | Technical error data; a low sample of session replays with all text/inputs masked | See the provider's data processing terms | Platform-wide |
| GitLab (CI) | Runs the scheduled job that dumps the full primary database and uploads it to backup storage | Full database dumps, i.e. all Customer Data in the primary database | See the provider's data processing terms | All (backups) |
| Upstash (Redis) | Rate limiting and short-lived caches | IP address and identifiers used as rate-limit keys; cached lookups | See the provider's data processing terms | All |
| Chatwoot | Support inbox used by staff | Support messages; contact name, email and phone | See the provider's data processing terms | Support. |
| Mapbox | Forward geocoding; satellite image tile for AI roof segmentation | Address query; latitude and longitude of the property | See the provider's data processing terms | Portal address search, roof segmentation |
| swisstopo / geo.admin.ch (Swiss federal geodata service) | Swiss address search from the portal lead screens | Address search string | Switzerland | CH leads |
| Apple (APNs) / Google (Firebase Cloud Messaging) | Mobile push notifications to partner staff | Device tokens; notification content, which may include a lead's name | See the provider's data processing terms | Mobile app notifications |
| Vercel Web Analytics / Speed Insights | Page analytics and performance sampling, currently also on storefront pages | Page URL, device/browser data | See the provider's data processing terms | All, including storefronts |
For storefront engagement analytics Raysly runs on a partner's behalf and configuration, the partner is controller and Raysly is processor, so PostHog appears in this table for that activity. Raysly's own platform-level analytics and telemetry (PostHog, Sentry, Vercel) run for Raysly's own purposes and are Raysly's own controller activity, disclosed in the Privacy Notice, not this table. Where a partner connects its own Mollie account (Mollie Connect), Mollie acts under its own contract with the partner and is not a Raysly subprocessor; it is therefore not listed here.
End-customer storefront/marketplace payments are the partner's own responsibility, through the partner's own connected provider (for example Mollie Connect or a Stripe Connect equivalent) or the partner's own bank IBAN. Luxa Energy LTD is not a party to that payment, so Mollie and Stripe are not listed in the processor table above for storefront/marketplace payment processing.
Vendors handling data for Raysly's own controller activities (not partner data)
These vendors process personal data for which Raysly itself is the controller (see the Privacy Notice) — for example, Raysly's own account-holder, billing-contact and marketing data. They are listed separately because they are not subprocessors under the DPA above; they are Raysly's own vendors.
| Vendor | Purpose |
|---|---|
| Vercel | Hosting of raysly.com, sign-up and the partner portal |
| Turso (LibSQL) | Database holding partner accounts, team members, sessions (IP address, user agent, city/country) and the email log |
| Cloudflare (R2, Turnstile) | File storage and backups; bot check on sign-up |
| GitLab (CI) | Scheduled full-database backups |
| Upstash (Redis) | Rate limiting on sign-up and login (IP address) |
| Twilio / Bird / Sinch | SMS one-time codes for partner login |
| Google / Apple (and other enabled social login providers) | Social sign-in for partner accounts |
| Google Maps | Address autocomplete during onboarding |
| EU VIES | Validation of partners' VAT numbers |
| Chatwoot | Support conversations with partners |
| Resend | Raysly's own transactional account/billing emails |
| Google Analytics 4 / PostHog | Analytics on raysly.com and the partner portal (see the Cookie Policy) |
| Sentry | Error monitoring on raysly.com and the partner portal |
| Vercel Web Analytics / Speed Insights | Performance analytics on raysly.com and the partner portal |
| Mollie / Stripe / Revolut | Processing partners' own subscription payments to Raysly |
| Revolut Business | Read-only bank feed for reconciling Raysly's own account (may show payer names) |
| Slack | Internal staff notification tooling (not customer-facing) |
Mollie, Stripe and Revolut appear in this table only for Raysly's own subscription billing. In that role they process personal data of partners' billing contacts, for which Luxa Energy LTD is the controller. They are not Raysly subprocessors for end-customer storefront or marketplace payments: those payments run through the partner's own connected provider or bank account, and Luxa Energy LTD is not a party to them.