1. Current status — honest placeholder
PayBlah is preparing for launch. Infrastructure and messaging vendors have not yet been finally selected. In particular, our choices for:
- Cloud hosting / infrastructure
- Transactional email delivery
- SMS delivery
- Payment link / payment processing partners
…are not live commitments on this page. We will not invent brand names to fill a table. When providers are contracted and ready for production use, this page will list them with enough detail for customers and counsel to review.
2. What a sub-processor is
For customer (creditor) account data and for personal data about the people and businesses you invoice — where PayBlah acts as a processor under our Data Processing Addendum — a sub-processor is a third party we engage to process that data on our behalf to deliver the Service (for example, to host databases, send reminder email or SMS, or operate payment links).
This page is about those service providers. It is not a list of your own accounting tools (Xero, QuickBooks Online, Sage) that you connect; those integrations are configured by you and governed by your agreements with those providers.
3. Intended categories (vendors TBD)
The following categories describe where we expect to use sub-processors. Until launch publication, provider names, locations, and transfer mechanisms remain to be confirmed.
| Category | Purpose (intended) | Provider | Location / notes |
|---|---|---|---|
| Cloud hosting & infrastructure | Application hosting, databases (including per-tenant isolation), storage, backups, networking | TBD — published before launch | TBD before launch (SP-HOST) |
| Transactional email | Delivery of product email and customer-authorized invoice reminder email | TBD — published before launch | TBD before launch (SP-EMAIL) |
| SMS messaging | Delivery of customer-authorized SMS reminders where the plan and territory support SMS (including STOP / suppression handling with the provider stack) | TBD — published before launch | TBD before launch (SP-SMS) |
| Payment processing / payment links | Payment pages and payment confirmation webhooks; PayBlah is designed not to hold customer funds or card details | Stripe | Subscription card payments via Stripe. PayBlah does not store full PAN/CVC. Debtor payment-link MoR model: Open decision SP-PAY. |
| Error monitoring & application logging | Operational reliability, debugging, security monitoring (minimized personal data where feasible) | TBD — published before launch | TBD before launch |
| Customer support tooling | Ticket handling and support communications (with audited, reason-gated access principles described on our security page) | TBD — published before launch | TBD before launch |
| Analytics (website / product, if enabled) | Optional usage analytics subject to cookie / consent choices on the marketing site and product settings | TBD — published before launch | See also Cookie Policy |
Rows may be added, split, or removed when the architecture is finalized. Empty marketing promises are worse than a short list — we would rather show TBD than a plausible guess.
4. Commitment before launch
Before public production launch of the Service, we commit to:
- Publish a completed sub-processor list on this page (provider name, category/purpose, and material location information as appropriate)
- Give notice to customers in advance of launch (and thereafter for material changes), so there is time to review against your own policies and the DPA
- Keep this page as the canonical public list for marketing-site readers and for customers evaluating the product
5. How we plan to notify changes
After the initial launch list is published, material additions or replacements of sub-processors will be handled in line with the DPA and applicable law. Our intended practice is:
- Update this page with the new or replacement provider and a revised “Last updated” date
- Provide notice to the workspace owner or billing contact by email and/or in-app notice where the DPA requires advance notice
- Allow the objection / exit mechanics described in the signed or posted DPA Draft target: 30 days (SP-NOTICE)
Exact timelines and objection rights will match the counsel-reviewed DPA language — not a shorter informal promise on this page alone.
6. Roles, data types, and security context
In summary (see full documents for detail):
- Controller / processor. PayBlah is typically controller for its own account, billing, and website data, and processor for personal data in your receivables / reminder content that you submit to the Service — as described in the Privacy Policy, GDPR & Data Protection page, and DPA.
- B2B product scope. PayBlah is designed for overdue B2B invoice reminders about invoices you are owed. It is not a consumer debt-collection service.
- Security design. Architectural measures (including database-per-tenant isolation, sealed secrets, and audited support access) are summarized on Security. Sub-processors will be engaged under written terms that require appropriate protection of personal data.
7. Related reading
- Privacy Policy — what we collect and why
- Data Processing Addendum — processor terms, sub-processing, and security measures structure
- Security — isolation, auth, portal tokens, support access
- GDPR & Data Protection — rights and territorial notes
- Cookie Policy — site cookies and preferences
- Acceptable Use — permitted and prohibited use of the Service
8. Contact
Questions about this list or a future vendor entry:
- Privacy / data protection: support@payblah.com hello@payblah.com until a dedicated privacy@ is published
- Security: security@payblah.com
- General: hello@payblah.com
- Contact form
Draft website policies for product readiness — have qualified counsel review before public launch in each territory. This page is an honest placeholder where vendors are not yet selected; it is not a representation that any specific third party is already processing data for PayBlah in production. Confirm final sub-processor terms and transfer mechanisms with counsel before launch in each territory.