Skip to main content

Sub-processors

Updated 2026-04-21 · Operator: AcctTen (acctten.com)

The following third-party service providers process personal data on our behalf as sub-processors under our Data Processing Addendum. Each provider operates under a Data Processing Agreement (DPA) with Standard Contractual Clauses (SCCs) or is certified under comparable frameworks (APEC CBPR, APEC PRP) recognised by the Singapore Personal Data Protection Commission (PDPC) for cross-border transfer under PDPA §26.

ProcessorPurposeRegionCertificationDPA
Supabase (Postgres, Auth, Storage)Primary data store — tenants, employees, payroll records, audit logs, authenticationap-southeast-1 (Singapore)SOC 2 Type II · ISO 27001DPA ↗
VercelApplication compute, static hosting, edge functionsGlobal edge networkSOC 2 Type II · ISO 27001 · GDPR SCCsDPA ↗
StripeSubscription billing + card payment processing (card data stays on Stripe — we never receive PAN)United StatesPCI-DSS Level 1 · SOC 2 Type II · SCCsDPA ↗
Google Vertex AIAgentic payroll assistance (zero-retention inference, APEC-CBPR certified transfer)Global EndpointAPEC CBPR · APEC PRP · ISO 27001 · ISO 27701DPA ↗
Anthropic (via Vertex router)Backup LLM route for high-tier agent calls (zero-retention for API calls)United StatesSOC 2 Type II · SCCsDPA ↗
Sentry (Functional Software, Inc.)Error telemetry only — PII-scrubbing hook redacts NRIC, bank, salary, email before ingestionConfigurable (default United States)SOC 2 Type II · ISO 27001 · SCCsDPA ↗
OneMap (SG Land Authority)Postal-code → address lookup at signup (non-PII query)SingaporeGovernment-operated serviceDPA ↗
ACRA Open DataUEN → entity lookup at signup (SG Open Data Licence, attribution displayed)SingaporeGovernment open data — SG Open Data Licence 1.0DPA ↗
Google OAuthOptional social sign-in (for users who choose Google SSO)United StatesAPEC CBPR · APEC PRP · ISO 27001DPA ↗

Material changes: We will notify registered OWNER / ADMIN contacts at least 30 days in advance of any new sub-processor engagement that will materially alter the cross-border transfer pattern or the categories of personal data processed.

Questions or objections regarding sub-processors: dpo@acctten.com