Subprocessors
Version: 2026-09-11
*Translation for convenience. The Spanish text prevails.*
Providers that process data on behalf of Mansaria. Any addition or replacement is announced 30 days in advance (clause 5 of the DPA).
Always active
They take part in every use of the service.
| Provider | Role | Location | Transfer basis |
|---|---|---|---|
| Supabase | Database, authentication, document storage | EU (Ireland, eu-west-1) | Not applicable |
| Vercel | Application hosting and execution | EU (Ireland, dub1) — the same region as the database; the delivery network is global, but it neither runs our code nor reads the session | Not applicable for execution |
| Brevo | Sending email: notices to the agency’s clients and invitations to its staff | France (EU) | Not applicable |
| Cloudflare | Storage of the encrypted backups | EU | Standard Contractual Clauses |
| Scaleway | Second encrypted backup; also runs the nightly backup job | France (Paris) | Not applicable |
| Sentry | Application error reporting | EU (Frankfurt) | Not applicable |
| OpenFreeMap | Catalogue maps | EU | No personal data: property coordinates only |
Backups are encrypted before leaving our systems, with a key whose private half is held by neither storage provider: neither Cloudflare nor Scaleway can read their contents.
Activated by the agency itself
They take no part unless the agency connects that integration. Until it does, no data reaches these providers.
| Provider | Role | Location | Transfer basis |
|---|---|---|---|
| Stripe | Collecting the agency’s invoices from its own clients (Stripe Connect) | EU (Ireland) | Not applicable |
| Employee calendar: viewing schedule with the client’s name and phone and the property address. Employee mailbox: sending mail to the client from their record | United States | Standard Contractual Clauses / EU-US Data Privacy Framework | |
| Microsoft | Employee mailbox (Microsoft 365): sending mail to the client from their record and reading the correspondence with that address | United States | Standard Contractual Clauses / EU-US Data Privacy Framework |
| Meta | Lead Ads capture forms and opening WhatsApp with the client’s phone number | United States | Standard Contractual Clauses / EU-US Data Privacy Framework |
| Smoobu, Lodgify | Booking synchronisation: guest name and contact details | EU | Not applicable |
| Property portals | Listing distribution through a feed: property data, no client data | Depends on the portal | No personal data of clients |
The agency’s own subscription to Mansaria is also charged through Stripe. That processing is not carried out on the agency’s behalf: there Mansaria is the controller, and it appears as such in the Article 30 register.
Disclosures required by law
These are not subprocessors: they are disclosures to authorities required by Spanish law. They are listed here because Article 30 requires identifying recipients, and because the agency must know what leaves the platform.
| Recipient | What is disclosed | Rule |
|---|---|---|
| Ministry of the Interior (SES.HOSPEDAJES) | Traveller report: name, document type and number, date of birth, sex, nationality, address and, for minors, relationship | RD 933/2021 |
| Tax Agency (AEAT) | The agency’s invoicing data | Invoicing rules and Verifactu |
Analytics and profiling
No analytics or advertising tools are used, and no behavioural profiles of platform users are built.
The agency’s own use of the product with its clients is a different matter: the CRM records whether the client opened the property selection sent to them and what they replied. That processing belongs to the agency, which decides its purposes, and Mansaria carries it out on its behalf.
What Sentry receives
Technical data about the failure: error message, stack trace, browser, page path and an internal user identifier — never their email or name.
Before an event is sent, query parameters, cookies and authorisation headers are stripped, both from the event itself and from the error text. The screen is not recorded either (Session Replay is disabled).
Even so, the text of an error is free text: it cannot be ruled out entirely that an unexpected message carries some data along. What is foreseeable is stripped; promising otherwise would be promising more than the code guarantees.
Outside the processing agreement: advertising on the public site
Google and Meta are not sub-processors of Mansaria and take no part in processing the agency’s client data. They act only on visitors to the public site (home, sign-up and legal documents), and only if that visitor consents in the cookie notice.
| Provider | Purpose | When it applies |
|---|---|---|
| Google Ads | Measuring which ad brought a sign-up | Only with the visitor’s consent |
| Meta | The same, for Facebook and Instagram ads | Only with the visitor’s consent |
They are listed here for transparency: although they fall outside the DPA, they are third parties that may receive data through this site.
The employee mailbox: what leaves and what does not
When an employee connects their mailbox, Mansaria does not copy their correspondence — neither into the database nor into the backups. When a client record is opened, the mailbox provider is asked for the letters exchanged with that address and they are shown on screen. All that is stored is the link to the mailbox and, for every letter sent from the record, one line with recipient, subject and date, without the text.
What therefore leaves towards the provider is the client's email address at the moment of the query: that is what finds those letters. On Google only the sending permission is requested, so Gmail correspondence is not read at all.