Subprocessors
Last updated: 2026-07-27
This page lists the third parties appointed by Ingram Technologies SRL to process Customer Personal Data on Ingram's behalf in providing Peppost.
It forms part of the Peppost Product Annex to the Ingram Data Processing Addendum.
Change notifications and objections
For a planned appointment or replacement, Ingram will:
- update this page; and
- send notice to the Customer's account email
at least 30 days before the new Subprocessor begins processing Customer Personal Data.
Where an urgent replacement is reasonably necessary to address a security risk, service failure, legal requirement, or material threat to service continuity, Ingram may make the replacement sooner. Ingram will notify affected Customers as soon as reasonably practicable and explain the reason for the urgent change.
A Customer may object to a new or replacement Subprocessor on reasonable, documented data-protection grounds by emailing privacy@ingram.tech. The process and available remedies are described in section 10 of the DPA.
Current Subprocessors
Vercel Inc.
- Purpose: Application hosting, runtime logging, and page-level analytics.
- Processing location: Paris, France. Vercel is a globally operated provider.
- Data processed: Request metadata, IP addresses, runtime logs, and page-level analytics. Invoice data passes through application memory while Peppost processes a send; it is not stored, and analytics never receives invoice content.
- Transfer safeguard: The European Commission SCCs and any applicable adequacy mechanism identified in Vercel's data-processing terms.
- More information: https://vercel.com/legal/dpa
Amazon Web Services EMEA SARL
- Purpose: Database hosting, backups, and infrastructure for Ingram's error reporting.
- Processing location: Paris, France.
- Data processed: Peppost account, send-history, credit, and agreement-acceptance data, and application error events. Invoices and their attachments are not stored.
- Transfer safeguard: EEA processing for the described production workloads. AWS contractual transfer safeguards apply to any permitted support access or onward processing that constitutes a restricted transfer.
- More information: https://aws.amazon.com/compliance/gdpr-center/
Scrada BV
- Purpose: Peppol access-point services: recipient lookup, invoice routing, document transmission, and delivery evidence.
- Registered office: Windgat 15, 9521 Letterhoutem, Belgium.
- Enterprise/VAT number: BE 0793.904.121.
- Processing location: European Union.
- Data processed: The transmitted e-invoice and its attachments in full, sender and recipient identifiers, routing information, document identifiers, delivery status, and error information.
- Retention: Scrada retains transmitted documents in accordance with its own terms; the applicable period is available from Ingram on request.
- Transfer safeguard: No Chapter V transfer mechanism is required for the EU processing currently described by Scrada.
- More information: https://www.scrada.be/privacy/
Cloudflare, Inc.
- Purpose: DNS, network and edge security, and transactional email delivery and routing.
- Processing location: Global.
- Data processed: IP addresses, DNS and request metadata, security events, email addresses, and the contents and headers of transactional email.
- Transfer safeguard: EU-US Data Privacy Framework where applicable and the European Commission SCCs under Cloudflare's DPA.
- More information: https://www.cloudflare.com/cloudflare-customer-dpa/
Customer-authorized Stripe integration
Stripe is Peppost's source system, authorization provider, app surface, and payment provider. The Customer has a direct relationship with Stripe and instructs Peppost to retrieve selected Stripe data.
Stripe is therefore identified here for transparency, but is not classified as a Peppost Subprocessor merely because Peppost accesses the Customer's Stripe account on the Customer's instruction. Stripe's processing under its direct relationship with the Customer is governed by Stripe's own terms and privacy documentation.
- Relevant entity: Stripe Payments Europe, Ltd., Ireland.
- Data involved: Stripe account and object identifiers, sender details, the customer and invoice data selected for sending, credit-purchase information, and limited payment metadata.
- More information: https://stripe.com/privacy-center/legal