Legal Sub-processors Last updated: October 4, 2026 Read or download the October 4, 2026 legal documents [https://timastra.com/legal/releases/2026-10-04/index.html]. The dated archive preserves this release; your order or acceptance record identifies the documents that apply to you. Timastra LLC uses the providers below to run its hosted products: Collect, Inventory, Expenses, HRIS, Bookings, Commerce, Sentinel and Schedule Online. Providers processing workspace data on our instructions are sub-processors under the applicable data processing agreement [https://timastra.com/legal/releases/2026-10-04/documents/dpa.html]. Website traffic, Timastra support correspondence and billing have separately described purposes and roles. The Schedule and Deskrun desktop apps keep their data on your own computers and use none of these providers for it. Sign-in is run by Timastra itself at auth.timastra.com on the same Singapore servers; no third-party identity provider is used. The support portal is separate from product workspaces. Its operators sign in through Cloudflare Access. The netcup server also scans support uploads in memory; private file storage stays in Cloudflare R2. Timastra controls support records under the website and support privacy policy [https://timastra.com/legal/releases/2026-10-04/documents/privacy.html#support-portal]. Provider | Purpose | Location | Data | netcup GmbH | Server hosting for every hosted product: application servers, databases and uploaded files | Singapore | Hosted product data | Cloudflare, Inc. | DNS, TLS, proxy and attack protection in front of every product; the timastra.com website and operations service | Global network; United States | Request metadata (IP address, browser details, URLs) and traffic in transit | Cloudflare, Inc. (R2 storage) | Encrypted daily backups of hosted products; archived Bookings service logs (deleted after 90 days) | Asia-Pacific | Encrypted backups of hosted product data; service logs | Cloudflare, Inc. (support portal) | Support portal, case database and private uploaded files | Global edge network; case database and files in Asia-Pacific | Support contact details, messages, files and limited authorized product context | Google (Gmail) | Owner mailbox copies of incoming support messages, including fallback handling | Google service locations, including the United States | Sender address, message, attachments and email metadata | Resend | Account, notification and operations email | Tokyo, Japan; United States | Recipient address, message content and delivery metadata | OVH SAS / OVHcloud | Hosting for public demos and pre-release testing (sample data only) | Canada | Demo visitor request logs, including IP addresses | Team Cymru | Network-name lookups for aggregate website traffic statistics | United States | IP address, sent as a DNS query; not stored | Payment merchants and configured connections For a Paddle purchase, the Paddle entity named in the checkout and receipt is the merchant of record, processing billing contact, country, transaction, tax, refund and subscription records in the United Kingdom, United States and other service locations under its own privacy notice. Its payment-controller responsibilities are separate from Timastra's processing of customer workspace data. For an eligible purchase whose checkout names Creem or Dodo Payments instead of Paddle, that merchant of record processes purchase contact, payment, tax and subscription information under its own privacy notice. These payment providers do not receive school timetables or customer workspace records. See payment providers and privacy notices [https://timastra.com/legal/releases/2026-10-04/documents/payments.html#payment-providers]. These conditional disclosures do not establish that an alternative provider is enabled or approved. A business can enable additional connections such as courier fulfilment, email/SMS delivery, accounting or mailbox import, and AI-assisted workflows where offered. The chosen service receives the data needed for that connection; its role, processing locations, retention and agreements depend on the business configuration and contract. Confirm the provider shown in the product and the applicable processing information before enabling a connection. A provider supported by source code is not automatically enabled for every workspace. App stores Google Play distributes Timastra's companion apps. It processes store and install information as an independent controller, not as our sub-processor. Changes For customers covered by the data processing agreement, whether accepted at signup, incorporated into an order or signed separately, Timastra will email every affected customer at least 30 days before a new or replacement sub-processor begins processing workspace data. The notice identifies the change and gives an opportunity to object as the agreement describes. We also update this list; visiting or subscribing to this page is not required to receive the contractual notice. Questions Email support@timastra.com [mailto:support@timastra.com?subject=Sub-processor%20question].