Sub-processors
Last updated 31 July 2026
These are the third parties that help us run Solstral. For each one we list what it is used for, what it can actually access, and where it operates. This page is the authoritative list and is referenced by our Data Processing Addendum and Privacy Policy.
We give workspace owners at least 14 days’ notice before adding or replacing a sub-processor. To be notified, email [email protected] and ask to be added to the sub-processor notice list.
Infrastructure & hosting
Amazon Web Services, Inc. / AWS Australia
- Purpose
- Application hosting, the PostgreSQL database, file storage, and outbound email delivery (Amazon SES).
- Data it can access
- All Customer Data at rest and in transit — records, activities, attachments, and email content.
- Location
- Sydney, Australia (ap-southeast-2)
Cloudflare
Cloudflare, Inc.
- Purpose
- DNS, TLS termination, network security and DDoS protection, and inbound email routing.
- Data it can access
- Traffic metadata and, in transit, request/response content passing through the edge. Inbound email is parsed and forwarded.
- Location
- Global edge network (United States entity)
AI model providers
Anthropic
Anthropic PBC
- Purpose
- Powers the AI assistant, the AI chatbot, AI automation steps and AI-assisted drafting. Content is sent to the model only when one of those features is used.
- Data it can access
- Whatever the invoked AI feature needs to answer: record fields, contact details, activity and email content in the relevant context window.
- Location
- United States
- How to avoid it
- AI features can be switched off entirely per workspace in Settings → AI, which prevents any data being sent to a model provider.
OpenAI
OpenAI, L.L.C.
- Purpose
- Alternative model provider for the same AI features. Used only where a workspace or deployment is configured to prefer it.
- Data it can access
- As for Anthropic — the record and message content the invoked AI feature requires.
- Location
- United States
- How to avoid it
- Not used unless explicitly configured; AI features can also be switched off entirely.
Payments
Stripe
Stripe, Inc. / Stripe Payments Australia Pty Ltd
- Purpose
- Subscription billing and payment processing. Card details are entered directly into Stripe's hosted fields and never reach Solstral's servers.
- Data it can access
- Account billing contact — legal name, billing email, address and tax identifiers — plus payment instrument data held solely by Stripe. No CRM record data.
- Location
- United States and Australia
Business operations
Hostinger
Hostinger International Ltd
- Purpose
- Hosting for the public marketing website (solstral.com).
- Data it can access
- Marketing site visitors only — contact-form submissions and standard web server logs. No access to the CRM application or Customer Data.
- Location
- European Union
GitHub
GitHub, Inc. (Microsoft)
- Purpose
- Source code hosting and the automated build/deployment pipeline.
- Data it can access
- Application source code and build artefacts. No production Customer Data — production credentials are held in AWS Secrets Manager, not in the repository.
- Location
- United States
Cross-border disclosure
Customer Data is stored in Sydney, Australia. Several providers above operate outside Australia — principally in the United States — so using Solstral involves cross-border disclosure for the purposes of Australian Privacy Principle 8 and Chapter V of the GDPR. We rely on standard contractual clauses and the providers’ own transfer frameworks.
A note on AI
The AI model providers only receive data when someone uses an AI feature. If that isn’t acceptable under your policy, an owner or admin can disable AI for the entire workspace in Settings → AI. That switch is enforced in the application: with AI off, no Customer Data reaches a model provider by any route, including automations.