This list applies to Tevlio’s Services and is maintained by Tevlio Tecnologia da Informação Ltda. (“Tevlio”). It explains which third parties may process personal data to help us provide and operate the Services.
The Portuguese (Brazil) version is the original and controls if this English translation conflicts with it, unless a signed agreement with the Customer says otherwise.
1. How to read this list
- A Customer Data Subprocessor processes Customer Personal Data for Tevlio when Tevlio acts as the Customer’s Operator or Processor.
- An other service provider processes account, billing, website, or business data where Tevlio usually acts as Controller, or where the provider has its own legal obligations.
The data categories below describe the maximum information ordinarily needed for the stated purpose. A provider does not receive every category for every Customer or Service. Tevlio limits access and disclosure to what is reasonably necessary.
Tevlio operates infrastructure in Brazil and also uses providers outside Brazil. Our Privacy Policy and DPA explain how we handle international transfers.
2. Customer Data Subprocessors
Before a Subprocessor processes Customer Personal Data, Tevlio requires a written agreement with privacy, confidentiality, security, incident, deletion, assistance, audit, and international-transfer protections appropriate to the service.
| Provider | Purpose | Personal data that may be processed | Service scope | Provider / processing location |
|---|---|---|---|---|
| PlanetScale, Inc. | Managed application databases | Account identifiers, Service records, metadata, and Customer Content stored in application databases | Applicable Services | United States / United States |
| The Constant Company, LLC (Vultr) | Server and network hosting | Customer Content, Account and Service records, and network and security logs | Applicable Services | United States / United States |
| HostHatch LLC | Server and network hosting | Customer Content, Account and Service records, and network and security logs | Applicable Services | United States / United States |
| Hetzner Online GmbH | Server and network hosting | Customer Content, Account and Service records, and network and security logs | Applicable Services | Germany / Germany |
| Tigris Data, Inc. | Object storage | Files, attachments, object metadata, and related Account identifiers | Services using object storage | United States / United States |
| Backblaze, Inc. | Object storage and recovery copies | Files, attachments, object metadata, and related Account identifiers | Services using object storage or recovery copies | United States / United States |
| Axiom, Inc. | Operational and security logs | IP addresses, timestamps, pseudonymous Account or device identifiers, and diagnostic or security events; Customer Content is not intentionally logged | Applicable Services | United States / United States |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | Device and browser information, IP address where collected, error context, and pseudonymous Account identifiers; Customer Content is not intentionally submitted | Applicable Services | United States / United States |
| Help Scout PBC | Customer support | Business contact details, support messages and attachments, Account context, and support history | All Services | United States / United States |
3. Other providers and tools
These providers and tools help Tevlio communicate with Customers, deliver websites and applications, produce aggregate metrics, process payments, and meet related financial or legal obligations. Depending on the activity and applicable law, a provider may process personal data as Tevlio’s Processor, Service Provider, or independent Controller, or process only anonymous or aggregate data. Its own privacy notice and legal obligations may also apply.
| Provider | Purpose | Personal data that may be processed | Service scope | Provider / processing location |
|---|---|---|---|---|
| Mailgun Technologies, Inc. (Mailgun) | Transactional email delivery and delivery tracking | Sender and recipient addresses, message content, and delivery, bounce, open, and click events | Account, billing, support, and Service notifications | United States / United States |
| BunnyWay d.o.o. (bunny.net) | DNS, CDN, static application delivery, and network security | IP address, request metadata, and traffic or security logs; Customer Content is not intentionally stored in Tevlio’s static website or application zones | Websites and web applications | Slovenia / Germany for origin storage and a worldwide CDN network |
| Simple Analytics B.V. | Aggregate website usage metrics | Page and referrer URLs, time zone, and anonymized browser or device information; IP addresses are discarded and no cookies, Account identifiers, or Customer Content are used | Websites | Netherlands / Netherlands |
| Stripe Brasil Soluções de Pagamento Ltda. – Instituição de Pagamento and applicable Stripe entities | Payment processing and fraud prevention | Name, contact and billing details, tax and transaction data, device and fraud signals, and payment-card data submitted directly to Stripe | Paid Services | Brazil and applicable Stripe entities / Brazil, United States, and other locations used by the contracted Stripe Services |
| Woovi Instituição de Pagamento Ltda. | Pix payment processing, reconciliation, fraud prevention, and regulatory compliance | Name or company name, CPF or CNPJ where required, contact and billing details, Pix and transaction identifiers, payment details, and fraud or compliance signals | Paid Services paid through Pix | Brazil / Brazil |
Tevlio does not receive full payment-card numbers or card security codes from Stripe. Woovi may perform identity, fraud-prevention, anti-money-laundering, and other checks required for regulated Pix payment services.
4. International and onward transfers
When a provider located outside Brazil receives personal data governed by the LGPD, Tevlio adopts and maintains a valid mechanism under Article 33 of the LGPD. When contractual clauses are the applicable mechanism, the complete and unmodified ANPD standard clauses form part of the instrument executed with the importer.
A provider may make onward transfers to affiliates or service providers needed for hosting, storage, delivery, security, support, payments, or compliance. Current recipients, purposes, and countries are those published in the official Subprocessor lists or transfer notices maintained on the provider websites linked above. Tevlio reviews this information, requires compatible contractual protection, and maintains a completed record of applicable transfers. Upon a valid request, we will provide the applicable clauses free of charge within the legal period, subject to the protection of commercial and industrial secrets.
5. Changes and objections
Tevlio will notify the Account Owner by email or an agreed Account notification at least 15 days before a new Customer Data Subprocessor begins processing Customer Personal Data. This advance notice does not apply merely because Tevlio changes a provider that does not process Customer Personal Data under the DPA.
If an urgent replacement is necessary to protect security, availability, or legal compliance, Tevlio may provide notice as soon as reasonably practicable and explain the shorter notice. A Customer may object on reasonable data-protection grounds under Section 6 of the DPA .
6. Contact
Questions about a provider, its role, the applicable Service, or a processing location may be submitted through the Tevlio support page .