Sub-processors
Last Updated: August 14, 2026
Overview of third-party service providers authorized to process data on behalf of ProvenTen.
1. Overview
ProvenTen engages third-party service providers ("Sub-processors") to support the delivery, security, and operation of our marketing website and SaaS platform. All sub-processors undergo rigorous security evaluations and are bound by Data Processing Agreements (DPAs) incorporating strict data protection and confidentiality obligations in accordance with the GDPR.
2. Platform & Application Sub-processors
To safeguard competitive insights, architecture details, and custom enterprise deployments, our comprehensive Platform Sub-processor List (covering application database hosting, AI matching engines, and in-app analytics) is restricted to authenticated users and prospective evaluation teams:
- In-App Access: Active customers can view the live list directly within the ProvenTen application under Settings > Legal & Compliance.
- On Request: Prospective enterprise customers conducting vendor procurement can request the full platform sub-processor dossier by emailing privacy@proventen.com (Response time: 1–3 business days).
3. Website & Infrastructure Sub-processors
The following third-party sub-processors support our public marketing website, core DNS/mail routing, and general corporate IT operations:
| Sub-processor | Legal Entity | Data Location | Purpose / Service Provided |
|---|---|---|---|
| Domainhotelli | Planeetta Internet Oy (part of team.blue) | Helsinki, Finland (EU) | Marketing website web hosting, server access logs, and DNS infrastructure. |
| Google Workspace & Cloud | Google Ireland Limited | Frankfurt / EU Region | Email infrastructure, corporate document collaboration, and cloud storage (Data at rest restricted to EU). |
4. Updates and Notification Rights
In accordance with our Data Processing Agreement (DPA), ProvenTen maintains a mechanism to notify subscribed customers prior to engaging any new platform sub-processor.
Customers will receive at least 14 days' advance notice via email or in-app admin alerts before new sub-processors are granted access to customer data, allowing customers reasonable time to review and object.