Skip to content
Tembrel.Back to the homepage

Subprocessors

Tembrel's evidenced service providers, their processing functions, locations and customer authorization process.

Last updated 25 September 2026

On this page

  1. Scope of this list
  2. Resend
  3. Cloudflare
  4. Neon
  5. Anthropic
  6. Services not included as active subprocessors
  7. Changes and customer authorization

Scope of this list

This list records providers used in Tembrel's documented environment that perform functions involving personal data on behalf of business customers. It supports Schedule C of the Data Processing Agreement. The role depends on the specific service and processing, not simply on being a vendor.

Evidence checked: 25 September 2026. The available operational evidence is staging evidence. It does not establish production activation or an executed customer-specific appointment. The customer agreement records which providers apply to the service being supplied.

Resend

Sends account sign-in, recovery, invitation and security messages, plus demo-request acknowledgements and internal notifications. Processes recipient addresses, message content and delivery metadata. No marketing or subscription mail is sent.

Service
Transactional email delivery and delivery webhooks
Verified use
Configured and verified in staging; controlled transactional delivery accepted. Production is not active.
Location
Resend states that customer data, including message content, delivery logs and webhook payloads, is stored in the United States. The configured EU West sending region does not change the storage location. No EU-only processing claim is made.
Transfers
Resend's DPA incorporates EU Standard Contractual Clauses for restricted transfers and states participation in the EU-U.S. Data Privacy Framework. Resend states its DPA is in force for accounts after signup. Account-specific terms and the applicable transfer assessment remain the operator's responsibility before customer launch.

Resend provider terms

Cloudflare

Hosting the API, Admin and widget, routing database requests, and operational diagnostics. These functions can process customer content, network requests and operational identifiers.

Service
Workers, Pages, Hyperdrive and Worker logs
Verified use
Configured and verified in staging
Location
Network, execution, support and log locations are not established by the repository. No EEA-only processing commitment is made.
Transfers
Cloudflare publishes a DPA and EU standard contractual clauses. The account-specific agreement and transfer assessment must be established before restricted customer transfers; no executed mechanism is asserted here.

Cloudflare provider terms

Neon

Storage and retrieval of customer menu content, guest questions and context, interaction/order evidence and operational records.

Service
Hosted PostgreSQL through Cloudflare Hyperdrive
Verified use
Configured and verified in staging
Location
The documented staging database endpoint is in AWS eu-central-1. This does not establish every backup, support or ancillary processing location.
Transfers
Neon's current public service schedule refers to Databricks contractual terms. The applicable account contracting party, processing terms and any restricted-transfer safeguards must be matched to the customer deployment.

Neon provider terms

Anthropic

Processes question text, recent conversation context and relevant menu/house facts to generate answers. Not required for deterministic pairing wording.

Service
API for enabled menu questions and dish explanations
Verified use
Enabled in staging; a real response and quota enforcement are documented
Location
An account-specific processing region is not established. No EEA-only or on-device processing claim is made.
Transfers
Anthropic publishes processing terms with EU standard contractual clauses. Applicable account terms and safeguards must be verified before restricted customer transfers. No zero-retention or model-training claim is made.

Anthropic provider terms

Services not included as active subprocessors

  • Stripe: Billing implementation exists, but staging credentials and provider acceptance are outstanding. A payment provider's role must be assessed for the enabled service rather than assumed to be a subprocessor.
  • Square and Lightspeed: No accepted staging merchant connection. Customer-selected till integrations are not automatically Tembrel-appointed subprocessors.
  • Customer webhook destinations: Recipients selected by a customer are separate from providers Tembrel appoints. No accepted staging receiver is established.
  • Browser speech-recognition vendors: Selected by the guest's browser, not an audio processor engaged by Tembrel's widget. The browser may send audio to its vendor; submitted transcripts enter Tembrel's text-processing flow.
  • Additional monitoring or marketing analytics vendors: No additional configured recipient is established. Cloudflare Worker logs are already included above; the marketing application has no analytics tracker.
  • Better Auth, Drizzle and other application libraries: Used as software within Tembrel's infrastructure, not evidenced as separate hosted recipients of customer data.
  • Infrastructure providers engaged by a listed provider: Provider-managed supply chains are covered by the applicable provider terms and downstream disclosures. They are not represented as direct Tembrel engagements.

Changes and customer authorization

Under the DPA, proposed additions or replacements require at least 30 days' advance written notice to the customer's designated service contact. The customer may object on reasonable data-protection grounds. An unresolved objection prevents the affected data from moving to the disputed provider; the DPA explains alternatives and ending the affected service.

Location, service-scope and AI configuration changes must be assessed before processing changes. The current list and the customer-specific authorization record must remain aligned. Updating this webpage alone does not replace contractual notice, authorization or a required transfer mechanism.

For your service's appointments and instructions, use the written contact channels recorded in your customer agreement. Zadok Enterprise (eenmanszaak), Netherlands operates Tembrel.

Back to top
Tembrel.
Privacy PolicyTerms of ServiceDPASubprocessors