Legal

Sub-processors

NP Ledger relies on a small set of vetted service providers ("sub-processors") to run the Service. This page lists the providers that may process personal data to deliver it, what they do, and where. Consent-based website analytics is covered separately in the Cookies section of our Privacy Policy.

Last updated: July 12, 2026

This list supplements our Privacy Policy. We keep it current and will update the "Last updated" date below whenever a sub-processor is added or removed. If you would like advance notice of changes, contact us at support@70ware.com.

Sub-processors that may process customer or donor data

Each provider below processes data only to deliver the function described. Where a provider handles data on our instructions, a data-processing agreement (DPA) is in place. One provider — Plaid, our bank-feed connector — is an independent controller of the bank data you choose to share with it rather than our processor; that relationship is explained in Bank connections below.

Sub-processor Function Data processed Processing location
Google Cloud Platform Cloud hosting, database, file storage (receipts/exports), and task queue All application data, at rest and in transit United States (us-central1)
Stripe Subscription payment processing Billing contact and payment details (card data handled by Stripe, not stored by us) United States
Mailgun (Sinch) Transactional email delivery (receipts, password resets, notifications) Recipient email addresses and message content United States
Google (Gemini API) AI Help, Voice Entry field extraction, and receipt/invoice photo reading Financial context, transcript text, and receipt/invoice images you submit to the AI features United States
Google (OAuth sign-in) Optional "Sign in with Google" authentication Name and email address from your Google account United States
AssemblyAI Voice Entry speech-to-text (batch upload and realtime streaming) Audio you record for Voice Entry (not retained by us after processing) United States
Scalekit OAuth authorization broker for AI-agent connections Sign-in identity and access tokens (no financial records) United States
Plaid Bank-feed connectivity (optional; you connect your bank). Independent controller — see Bank connections Account metadata, balances, and transaction history for the accounts you link United States
Cloudflare (Turnstile) Bot / abuse protection on public forms (e.g., sign-up) Visitor IP address and a challenge token United States / global

Bank connections: Plaid

Connecting a bank feed is optional. If you choose to connect one, you link your bank through Plaid, which signs you in at your bank and sends us the account metadata, balances, and transaction history your bank makes available for the accounts you pick. You enter your bank credentials in Plaid's own secure window, and Plaid collects the consent it needs there. NP Ledger never sees or stores your bank username, password, or one-time codes.

Unlike the other providers on this page, Plaid is not acting on our instructions when it handles that data — it is an independent controller of the bank data you share with it, and it processes that data under Plaid's End User Privacy Policy, not ours. We list Plaid here anyway, because it is a real recipient of your financial data and you should know that before you connect. Please read Plaid's policy before linking an account.

What we do with what Plaid sends us: we import those transactions into your books so you can review, categorize, and record them instead of typing them by hand. Once the data reaches us we hold it under our Privacy Policy, like any other data in your ledger. A bank feed is a convenience, never a requirement — your books are complete and correct with no feed connected at all, and you can disconnect a feed at any time.

Customer-directed data flow: connected AI assistants

NP Ledger offers an optional connector (Model Context Protocol) that lets you link an external AI assistant — such as Claude or ChatGPT — to your account. This is a data flow you initiate and control, not a sub-processor we engage. When you connect an assistant and ask it to read your data, that data is transmitted to the assistant's provider (for example, Anthropic or OpenAI), which processes it under its own privacy policy and terms.

Access is bounded by your role in the organization, scoped to a single organization you choose, re-verified on every request, and revocable at any time from within the assistant. Sign-in is brokered by Scalekit (above), which does not receive your financial records. We disclose this flow here for transparency; review the assistant provider's terms before connecting.

AI processing safeguards

The AI features — AI Help, Voice Entry (speech-to-text and field extraction), and receipt/invoice photo reading — send the data you submit to Google Gemini and AssemblyAI. Under our paid-tier terms with both providers, that data is not used to train their AI models and is retained only transiently for the provider's abuse monitoring. Voice audio is not stored by NP Ledger after processing. These features are optional. This summary reflects our internal AI data-flow assessment.

International data transfers

NP Ledger is hosted in the United States and directed to nonprofits established in the United States and other countries outside the EU/EEA (see the Service Scope section of our Terms). All sub-processors above process data in the United States. Where a provider maintains Standard Contractual Clauses or EU-US Data Privacy Framework certification, that coverage is recorded internally and available on request.

Providers that do not process customer or donor data

We use additional tools (for example, for our own sales and prospect outreach) that process only 70Ware's own business-contact data and never touch your organization's financial records or donor information. These are not sub-processors of the Service and are excluded from the list above.