Worthic uses third-party providers to operate, secure, process, store, and support the Service. This page lists material subprocessors that may process personal information or customer content.
Current subprocessors
| Provider | Purpose | Data categories | Notes |
|---|---|---|---|
| Render | Application hosting, deployment/build infrastructure, managed database hosting, background jobs, runtime logging, infrastructure monitoring, and backup/recovery support. | Customer account and workspace data, application database records, uploaded or generated business records where stored in the application database, authentication/session/security event records, billing and subscription records, audit logs, request metadata, IP addresses, device/browser metadata, application runtime logs, deployment/build logs, background job logs, environment/runtime metadata, and secrets/environment variables used to operate the hosted services. | Render hosts Worthic staging and production services and the managed PostgreSQL database infrastructure used by the application. Production database access is restricted through Render/internal service access rather than public direct database exposure. Render is also used as the deployment target for GitHub-based CI/CD and may retain deployment records, service logs, build logs, database metadata, backups, and operational telemetry. Worthic restricts Render account access, stores secrets only as protected environment configuration, and avoids intentionally logging passwords, authentication tokens, payment credentials, full card data, or unnecessary customer document contents. |
| Cloudflare | DNS hosting, domain routing, content delivery/network acceleration, TLS termination, DDoS protection, web application firewall/security filtering, bot/rate-limit controls, caching, and edge/network logging. | DNS records and domain configuration, request metadata, IP addresses, user-agent/device/browser metadata, URL/path and routing metadata, TLS/certificate metadata, security event logs, firewall/WAF events, bot/rate-limit events, cache logs, geolocation/region metadata derived from network traffic, and limited application response metadata where routed through Cloudflare. | Cloudflare is used as an internet-facing infrastructure and security provider in front of Worthic services. It may process network traffic and security logs before requests reach the application hosting environment. Worthic configures Cloudflare to minimise unnecessary logging of customer content, avoid exposing secrets or authentication tokens in URLs, restrict administrative access, and retain Cloudflare logs only for operational, security, incident investigation, legal, and compliance purposes. |
| Cloudflare Analytics | Website and product usage analytics, traffic measurement, performance monitoring, feature usage reporting, and aggregated security/network insights. | Page and route events, feature usage events, request metadata, IP address or approximate location data, device/browser/user-agent metadata, referrer/source metadata, timestamps, aggregated traffic metrics, and limited account/workspace identifiers where analytics is linked to authenticated product usage. | Used to understand service usage, performance, and traffic patterns. Analytics is configured to minimise unnecessary personal information, avoid collecting secrets, payment credentials, authentication tokens, or document contents, and retain analytics data only for operational, product, security, compliance, and reporting purposes. |
| Cloudflare Workers AI | AI-assisted document extraction and analysis, categorization, AI assistant responses, and AI-generated insights within Worthic features. | User prompts, assistant responses, document text/images or extracted document data, accounting and workspace context supplied for the request, categorization inputs/outputs, AI insight inputs/outputs, technical request metadata, model/runtime logs, and AI usage/audit records. | Used through Worthic-controlled AI workflows and request logging. Authenticated AI requests are scoped to the requesting user’s workspace and permissions. Worthic does not send secrets, payment credentials, authentication tokens, or unnecessary personal/financial data, and processes AI inputs only as needed for the relevant feature. |
| OpenAI | AI-assisted document analysis and extraction, document categorization, financial insights, conversational assistants, reasoning, and related generative-AI functionality. | User prompts and instructions; conversation content; financial, account, transaction, reporting-line, and workspace information submitted for analysis; document text, extracted content, document images or page renders where vision processing is used; filenames and limited document metadata; generated outputs; and technical request metadata required to operate, secure, and monitor the service. | Used to provide Worthic’s AI-assisted features, including document understanding, categorization, financial insights, and conversational assistance. Worthic sends only the information required for the requested AI operation. Users and workspace administrators should avoid submitting unnecessary personal or sensitive information. Processing and retention are governed by Worthic’s agreement and applicable service terms with OpenAI. |
| Postmark | Transactional email delivery and inbound email processing for account verification, password resets, operational notifications, support/admin alerts, and user-submitted document ingestion. | Email addresses, recipient/sender names where provided, account/workspace identifiers, email subject and body content, verification/reset links or tokens, inbound email content, attachments and document metadata submitted for ingestion, delivery status, bounce/suppression data, timestamps, IP/device metadata where included in email events, and message logs. | Used for service emails and to receive user-submitted documents for ingestion and analysis. Worthic does not include passwords, full payment credentials, authentication tokens, or unnecessary sensitive information in email content. Inbound attachments may contain customer business, financial, or personal information and is routed only to the intended workspace/document-processing flow. Email logs and delivery records may be retained for account security, support, deliverability, audit, legal, and compliance purposes. |
| Lemon Squeezy | Merchant of Record; checkout hosting, payment processing and authorisation, subscription billing, tax calculation and collection, invoicing, transaction settlement, payment notifications, refunds, fraud prevention, and chargeback/dispute handling. | Customer name, billing email and contact details, billing address and country, tax/VAT identifiers where supplied, payer/customer identifiers, subscription and invoice references, transaction amount/currency/status, payment-method references or tokens, limited card/payment-network metadata such as brand and last four digits where provided, refund/dispute metadata, IP address, device/browser data, and fraud-prevention metadata. | Used to sell Worthic subscriptions, process and reconcile payments, calculate and remit applicable taxes, issue invoices/receipts, prevent fraud, and manage refunds and disputes. Lemon Squeezy acts as Merchant of Record. Worthic does not directly collect or store full card numbers, card security codes, or other sensitive payment credentials when Lemon Squeezy-hosted checkout and provider-side tokenisation are used. Billing records may be retained as required for accounting, tax, fraud prevention, chargebacks, legal obligations, and regulatory compliance. |
| Sentry | Application error monitoring, performance diagnostics, release health, issue triage, and operational alerting. | Technical logs, error events, stack traces, release and environment identifiers, affected routes, request metadata, device and browser metadata, IP address or approximate location data, user/account/workspace identifiers where included in diagnostic context. | Used to detect, investigate, and remediate staging and production application errors. Worthic has configured Sentry to avoid intentional collection of secrets, passwords, payment credentials, authentication tokens, full customer documents, or unnecessary customer financial content. |
| Google Identity Services / Google Workspace | User authentication, Google sign-in, account linking, identity verification, authentication security checks, and staff identity and access lifecycle management, including authoritative staff directory synchronization, role and employment-status changes, account suspension, and access reconciliation. | Google account identifiers; staff and user email addresses; profile names where provided; OAuth tokens or claims; sign-in and account-linking metadata; staff directory profile, role and account-status data; Workspace user identifiers; suspension and lifecycle status; synchronization and reconciliation records; device/browser metadata; IP address or approximate location data; timestamps; and authentication, security, and audit event records. | Google Identity Services is used where users choose Google sign-in or account linking. Google Workspace is also used as Worthic’s authoritative staff identity source for internal identity and access management. Worthic Staff Access uses approved Google Workspace directory data to support staff onboarding, role changes, deactivation and suspension, access reconciliation, and lifecycle audit records. Worthic requests only the OAuth scopes required for these functions, protects OAuth credentials and tokens, and treats authentication and staff-directory records as security and account data. This integration does not grant Google access to customer workspace documents, uploaded or generated business records, or customer financial records unless such information is separately and explicitly sent through another Google service or integration. |
Updates
Worthic may update this page from time to time. Where required by contract or law, affected customers will be notified of material subprocessor changes.