Service dependencies
Moira Connect Subprocessor List
This list identifies the third parties Moira currently uses or may engage to operate the stated Moira Connect service capabilities. A provider platform connected by a Customer is a Customer-selected recipient under that Customer's authorisation; it is not presented here as a Moira-controlled subprocessor.
1. Current service providers
The following services support the current production architecture. The exact data involved depends on the features Customer enables and whether the relevant service is used for that Customer's workspace.
| Subprocessor | Service purpose | Typical data scope |
|---|---|---|
| Cloudflare | Edge application delivery, traffic protection, DNS/TLS, rate limiting, and Workers-based public and administrative surfaces. | Request, security, routing, configuration, and content data necessary for the relevant edge request. |
| Railway | Application, gateway, worker, and operational infrastructure hosting. | Account, configuration, connection, event, audit, and operational data processed by hosted service workloads. |
| WorkOS | Authentication, organisation membership, identity events, and directory-backed access controls. | User identity, organisation, role, sign-in, and authentication-event data. |
| Stripe | Subscription billing, invoices, checkout, payment status, and tax-related billing workflows. | Billing contact, customer, invoice, subscription, payment-status, and tax information. Payment-card data is handled by Stripe. |
2. Customer-selected provider platforms
When Customer authorises a connection to a messaging, email, social, calendar, or other provider platform, data is transmitted to or from that provider under Customer's authorisation and the provider's own terms. Customer is responsible for determining whether that provider is permitted for its use case and for informing data subjects as required.
The public Provider Catalogue identifies Moira registry state and does not replace the provider's privacy notice, data-processing terms, account policy, programme rules, or regional availability statement.
3. Data locations and transfers
Service providers may process data through global infrastructure or in locations selected under their service terms. Moira does not use this list to promise a single processing region. Where a transfer mechanism is required, the DPA describes the safeguards Moira uses for Customer Personal Data.
4. Change management and objections
Moira will keep this list current and show its version and publication date. Before adding or replacing a material subprocessor, Moira will follow the notice and objection process in the DPA for Customers that have that contractual right.
5. Security, confidentiality, and due diligence
Moira assesses service providers for the role they perform and requires contractual confidentiality and data-protection obligations appropriate to the delegated processing. Moira remains responsible for a subprocessor's processing of Customer Personal Data to the extent required by applicable law and the DPA.
6. Questions and notifications
For a subprocessor question, an executed-DPA notice preference, or a reasonable data-protection objection, contact [email protected] and include the Customer legal entity, workspace identifier, and relevant service capability. We will not disclose another customer's confidential configuration in responding.