Sub-processors and service providers

Last updated: August 24, 2026

Alentra is a brand operated by Komplete10 LTD, a company registered in the United Kingdom and operating from Sweden. This page lists the providers used by Komplete10 LTD to operate the current private-beta architecture. It does not represent that a particular SCC, UK Addendum, transfer assessment, or sector agreement has been executed for a customer. Those documents and exact regions must be completed in the signed production schedule.

Google Cloud / Firebase

Provider terms ↗
Purpose
Authentication, Firestore application data, Cloud Storage documents, Cloud Functions, KMS envelope encryption, and Google Wallet integration.
Data
Account, business, session, wallet, document, evidence, security, and application data as required by the selected service.
Location
Firestore nam5; Storage US-EAST1; Functions us-central1; KMS global; other Google services per their terms.
Status
Active. Customer transfer documents and location acceptance must be completed before covered production processing.
Purpose
Hosting for the web application, API service, and internal admin service; network and runtime logs.
Data
HTTP requests, account and session traffic, service configuration, logs, and data transiently handled by the hosted workloads.
Location
US processing posture; exact service region must be recorded in the signed production schedule.
Status
Active for deployment. Region and transfer schedule require final production confirmation.
Purpose
Embedded Checkout for manual top-ups, tax calculation, refunds, disputes, and payment-event delivery.
Data
Business and billing contact, billing address and tax ID when supplied, Stripe customer and payment references, amounts, tax, payment status, refund/dispute data, and network/device data collected by Stripe.
Location
Stripe global infrastructure, including the United States, under Stripe terms.
Status
Active for billing. Stripe acts according to its services and applicable controller/processor roles.

Google Analytics

Provider terms ↗
Purpose
Optional marketing-site and dashboard usage measurement after analytics consent.
Data
Pseudonymous device/browser data, consented page events, referrer, and coarse location. Hosted session capability paths are excluded.
Location
Google global infrastructure.
Status
Conditional: loaded only after consent and only when a measurement ID is configured.

DigiCert and FreeTSA

Provider terms ↗
Purpose
RFC 3161 timestamp requests and append-only recovery when the primary authority is unavailable.
Data
A SHA-256 audit-record hash plus ordinary connection metadata; no cleartext signer identity or original document.
Location
Provider infrastructure and logs; exact location depends on the selected timestamp authority.
Status
Active when timestamping is enabled. Trust roots, policy, and HTTPS endpoint validation must be finalized for production.

Zoho ZeptoMail

Provider terms ↗
Purpose
Transactional signer verification and receipt links, staff invitations, legal-request replies, billing notices, and internal inquiry notifications; signed delivery/bounce/complaint events.
Data
Recipient address, generic subject, message content in transit, opaque client/provider references, and delivery status. Alentra requires provider content retention to be disabled and does not enable open/click tracking.
Location
The selected ZeptoMail Agent region (.eu or global) and verified log-retention setting must be recorded here before enablement.
Status
Conditional: disabled until the production Agent, EU region, verified transactional sender, retention setting, and signed webhook are configured and accepted.

Conditional providers not yet cleared for production

Alentra's API can use Redis for distributed public-endpoint rate limiting. The final Redis vendor and processing location must be named here before production enablement.

OAuth providers selected by the account user, such as Google or GitHub, also process authentication data under their own terms.

For questions, objections, or a change-notice contact, use the private contact form. The signed DPA must define the notice period and objection procedure.

Government-wallet proof, ready to repeat.

Start with Alentra