Legal
Sub-processors
Last updated: August 21, 2026
Shared sub-processors (NomadWorld platform)
NomadWorld ApS uses the following sub-processors across its products unless a product-specific page states otherwise.
Convex (Convex Inc.)
- Role: Primary database, real-time sync, server-side compute.
- Data categories: account identifiers, application data, audit logs, consent records.
- Processing location: United States (primary deployment).
- Transfer mechanism: Standard Contractual Clauses (EU 2021/914) incorporated via the Convex DPA.
- Certifications: SOC 2 Type II.
- Provider DPA / Privacy: convex.dev/legal/privacy
Vercel (Vercel Inc.)
- Role: Application hosting, edge / serverless compute, Vercel Analytics (only when cookie consent is granted).
- Data categories: request metadata, IP address (anonymised in Analytics), user-agent, page-view metrics.
- Processing location: Global edge with US/EU regions.
- Transfer mechanism: Standard Contractual Clauses incorporated via the Vercel DPA; EU-US Data Privacy Framework certified.
- Certifications: SOC 2 Type II, ISO 27001, EU-US DPF.
- Provider DPA / Privacy: vercel.com/legal/privacy-policy
WorkOS (WorkOS Inc.)
- Role: Authentication (AuthKit), SSO, session management.
- Data categories: user email, user identifier, OAuth tokens, session metadata.
- Processing location: United States.
- Transfer mechanism: Standard Contractual Clauses incorporated via the WorkOS DPA; EU-US Data Privacy Framework certified.
- Certifications: SOC 2 Type II, ISO 27001, EU-US DPF.
- Provider DPA / Privacy: workos.com/legal/privacy
Paddle (Paddle.com Market Limited)
- Role: Merchant of Record for paid transactions, billing, invoicing, EU VAT handling, refunds.
- Data categories: billing name, email, billing address, payment method (handled by PCI-compliant processors), transaction records.
- Processing location: Ireland (primary EU controller-level), United Kingdom, United States.
- Transfer mechanism: Standard Contractual Clauses + UK IDTA where applicable.
- Certifications: PCI DSS Level 1.
- Note: Paddle is the controller for payment data under its Merchant of Record model; NomadWorld receives only records necessary for fulfilment.
- Provider DPA / Privacy: paddle.com/legal/privacy
Overview
Ceero ApS engages the following sub-processors to operate hub.ceero.eu, the unified account portal, and bundle subscription infrastructure for the Ceero ecosystem. Each sub-processor processes personal data only on documented instructions from Ceero and under contractual safeguards no less protective than applicable data protection law.
This page is the authoritative list for the Ceero hub and shared account infrastructure. Individual products may engage additional sub-processors for product-specific features; those are listed in each product's sub-processor page.
We provide at least 30 days' advance notice of any new or replacement sub-processor by updating this page and, where appropriate, notifying registered users.
Last updated: May 2026
Email security@ceero.eu to subscribe to sub-processor change notifications.
Sub-processors
WorkOS (WorkOS Inc.)
- Role: Unified authentication (AuthKit), SSO, session management across Ceero apps.
- Data categories: user email, name, profile image URL, user identifier, OAuth tokens, session metadata, authentication event logs.
- Processing location: United States.
- Transfer mechanism: Standard Contractual Clauses incorporated via the WorkOS DPA; EU-US Data Privacy Framework certified.
- Certifications: SOC 2 Type II, ISO 27001, EU-US DPF.
- Provider DPA / Privacy: workos.com/legal/privacy
Convex (Convex Inc.)
- Role: Primary database, real-time sync, server-side compute for account records, bundle subscription state, consent logs, and cross-app user data.
- Data categories: user identifier, account profile fields, subscription status and plan metadata, Paddle customer/subscription identifiers, consent preference records, audit events.
- Processing location: United States (primary deployment, hosted on AWS).
- Transfer mechanism: Standard Contractual Clauses (EU 2021/914, Module 3) incorporated via the Convex DPA.
- Certifications: SOC 2 Type II.
- Provider DPA / Privacy: convex.dev/legal/privacy
Vercel (Vercel Inc.)
- Role: Application hosting (Next.js), edge / serverless compute, and Vercel Web Analytics (only when cookie consent is granted).
- Data categories: request metadata, IP address (anonymised in Analytics), user-agent, page-view metrics.
- Processing location: Global edge with US/EU regions.
- Transfer mechanism: Standard Contractual Clauses incorporated via the Vercel DPA; EU-US Data Privacy Framework certified.
- Certifications: SOC 2 Type II, ISO 27001, EU-US DPF.
- Provider DPA / Privacy: vercel.com/legal/privacy-policy
Paddle (Paddle.com Market Limited)
- Role: Merchant of Record for Ceero bundle subscriptions, billing, invoicing, EU VAT handling, refunds, and customer billing portal.
- Data categories: billing name, email, billing address, payment method (handled by PCI-compliant processors), transaction and subscription records, tax identifiers where applicable.
- Processing location: Ireland (primary EU controller-level), United Kingdom, United States.
- Transfer mechanism: Standard Contractual Clauses + UK IDTA where applicable.
- Certifications: PCI DSS Level 1.
- Note: Paddle is the controller for payment data under its Merchant of Record model; Ceero receives only the records necessary for subscription fulfilment and support.
- Provider DPA / Privacy: paddle.com/legal/privacy
Change notification
Ceero provides at least 30 days' advance notice of any new sub-processor or replacement of an existing sub-processor by updating this page. To subscribe to change notifications, email security@ceero.eu with the subject line "Subscribe: Ceero sub-processor changes".
Contact
- General data protection: support@ceero.eu
- Security and sub-processor concerns: security@ceero.eu
- Company: Ceero ApS, CVR 45441393, Njalsgade 21F 2. sal, København S, Denmark
- Supervisory authority: Datatilsynet (datatilsynet.dk)