Tevlio
Products Tevlio Mail → Private email built around security and control. Tevlio DNS → Clear, accountable DNS for organizations. Tevlio Git → A code home built around company ownership. Tevlio Drive → Company files with access and ownership attached.
Resources Blog → Notes on engineering, products, and the work behind them. Help and support → Get answers or contact the right team. Service status→ Check the current health of Tevlio services. Policies and commitments → Privacy, security, terms, and subprocessors.
Products
Products Tevlio Mail → Private email built around security and control. Tevlio DNS → Clear, accountable DNS for organizations. Tevlio Git → A code home built around company ownership. Tevlio Drive → Company files with access and ownership attached.
Resources
Resources Blog → Notes on engineering, products, and the work behind them. Help and support → Get answers or contact the right team. Service status→ Check the current health of Tevlio services. Policies and commitments → Privacy, security, terms, and subprocessors.
Log in
Log in
Back to Policies

Vendors and Subprocessors

Third parties that help Tevlio operate its services and process personal data.

Last updated
2026-08-10 21:39:38 UTC
Revision
6aa7729
Version historyReview every change made to this document on GitHub.
On this page
  • 1. How to read this list
  • 2. Customer Data Subprocessors
  • 3. Other providers and tools
  • 4. International and onward transfers
  • 5. Changes and objections
  • 6. Contact
On this page
  • 1. How to read this list
  • 2. Customer Data Subprocessors
  • 3. Other providers and tools
  • 4. International and onward transfers
  • 5. Changes and objections
  • 6. Contact

This list applies to Tevlio’s Services and is maintained by Tevlio Tecnologia da Informação Ltda. (“Tevlio”). It explains which third parties may process personal data to help us provide and operate the Services.

The Portuguese (Brazil) version is the original and controls if this English translation conflicts with it, unless a signed agreement with the Customer says otherwise.

1. How to read this list

  • A Customer Data Subprocessor processes Customer Personal Data for Tevlio when Tevlio acts as the Customer’s Operator or Processor.
  • An other service provider processes account, billing, website, or business data where Tevlio usually acts as Controller, or where the provider has its own legal obligations.

The data categories below describe the maximum information ordinarily needed for the stated purpose. A provider does not receive every category for every Customer or Service. Tevlio limits access and disclosure to what is reasonably necessary.

Tevlio operates infrastructure in Brazil and also uses providers outside Brazil. Our Privacy Policy and DPA explain how we handle international transfers.

2. Customer Data Subprocessors

Before a Subprocessor processes Customer Personal Data, Tevlio requires a written agreement with privacy, confidentiality, security, incident, deletion, assistance, audit, and international-transfer protections appropriate to the service.

ProviderPurposePersonal data that may be processedService scopeProvider / processing location
PlanetScale, Inc.Managed application databasesAccount identifiers, Service records, metadata, and Customer Content stored in application databasesApplicable ServicesUnited States / United States
The Constant Company, LLC (Vultr)Server and network hostingCustomer Content, Account and Service records, and network and security logsApplicable ServicesUnited States / United States
HostHatch LLCServer and network hostingCustomer Content, Account and Service records, and network and security logsApplicable ServicesUnited States / United States
Hetzner Online GmbHServer and network hostingCustomer Content, Account and Service records, and network and security logsApplicable ServicesGermany / Germany
Tigris Data, Inc.Object storageFiles, attachments, object metadata, and related Account identifiersServices using object storageUnited States / United States
Backblaze, Inc.Object storage and recovery copiesFiles, attachments, object metadata, and related Account identifiersServices using object storage or recovery copiesUnited States / United States
Axiom, Inc.Operational and security logsIP addresses, timestamps, pseudonymous Account or device identifiers, and diagnostic or security events; Customer Content is not intentionally loggedApplicable ServicesUnited States / United States
Functional Software, Inc. (Sentry)Error and performance monitoringDevice and browser information, IP address where collected, error context, and pseudonymous Account identifiers; Customer Content is not intentionally submittedApplicable ServicesUnited States / United States
Help Scout PBCCustomer supportBusiness contact details, support messages and attachments, Account context, and support historyAll ServicesUnited States / United States

3. Other providers and tools

These providers and tools help Tevlio communicate with Customers, deliver websites and applications, produce aggregate metrics, process payments, and meet related financial or legal obligations. Depending on the activity and applicable law, a provider may process personal data as Tevlio’s Processor, Service Provider, or independent Controller, or process only anonymous or aggregate data. Its own privacy notice and legal obligations may also apply.

ProviderPurposePersonal data that may be processedService scopeProvider / processing location
Mailgun Technologies, Inc. (Mailgun)Transactional email delivery and delivery trackingSender and recipient addresses, message content, and delivery, bounce, open, and click eventsAccount, billing, support, and Service notificationsUnited States / United States
BunnyWay d.o.o. (bunny.net)DNS, CDN, static application delivery, and network securityIP address, request metadata, and traffic or security logs; Customer Content is not intentionally stored in Tevlio’s static website or application zonesWebsites and web applicationsSlovenia / Germany for origin storage and a worldwide CDN network
Simple Analytics B.V.Aggregate website usage metricsPage and referrer URLs, time zone, and anonymized browser or device information; IP addresses are discarded and no cookies, Account identifiers, or Customer Content are usedWebsitesNetherlands / Netherlands
Stripe Brasil Soluções de Pagamento Ltda. – Instituição de Pagamento and applicable Stripe entitiesPayment processing and fraud preventionName, contact and billing details, tax and transaction data, device and fraud signals, and payment-card data submitted directly to StripePaid ServicesBrazil and applicable Stripe entities / Brazil, United States, and other locations used by the contracted Stripe Services
Woovi Instituição de Pagamento Ltda.Pix payment processing, reconciliation, fraud prevention, and regulatory complianceName or company name, CPF or CNPJ where required, contact and billing details, Pix and transaction identifiers, payment details, and fraud or compliance signalsPaid Services paid through PixBrazil / Brazil

Tevlio does not receive full payment-card numbers or card security codes from Stripe. Woovi may perform identity, fraud-prevention, anti-money-laundering, and other checks required for regulated Pix payment services.

4. International and onward transfers

When a provider located outside Brazil receives personal data governed by the LGPD, Tevlio adopts and maintains a valid mechanism under Article 33 of the LGPD. When contractual clauses are the applicable mechanism, the complete and unmodified ANPD standard clauses form part of the instrument executed with the importer.

A provider may make onward transfers to affiliates or service providers needed for hosting, storage, delivery, security, support, payments, or compliance. Current recipients, purposes, and countries are those published in the official Subprocessor lists or transfer notices maintained on the provider websites linked above. Tevlio reviews this information, requires compatible contractual protection, and maintains a completed record of applicable transfers. Upon a valid request, we will provide the applicable clauses free of charge within the legal period, subject to the protection of commercial and industrial secrets.

5. Changes and objections

Tevlio will notify the Account Owner by email or an agreed Account notification at least 15 days before a new Customer Data Subprocessor begins processing Customer Personal Data. This advance notice does not apply merely because Tevlio changes a provider that does not process Customer Personal Data under the DPA.

If an urgent replacement is necessary to protect security, availability, or legal compliance, Tevlio may provide notice as soon as reasonably practicable and explain the shorter notice. A Customer may object on reasonable data-protection grounds under Section 6 of the DPA .

6. Contact

Questions about a provider, its role, the applicable Service, or a processing location may be submitted through the Tevlio support page .

More policies and commitments

Explore the rest of Tevlio’s policies, terms, and commitments.

Data Processing Addendum Terms that apply when Tevlio processes personal data on behalf of a Customer. → Privacy Policy What personal data Tevlio processes, why and where it is processed, and how to exercise your rights. → Security Overview How Tevlio protects its Services, data, and infrastructure. → Terms of Service Terms that apply to business subscriptions and use of Tevlio Services. →
Back to Policies Back to Top

Useful links

Help and support Service status

Us

Blog

Legal

Privacy Policy Terms of Service All legal policies

Follow us

© 2018–2026 Tevlio. All rights reserved. Tevlio Tecnologia da Informação Ltda. CNPJ 68.407.558/0001-20

English (US) Português (Brasil)