Current service providers
The
supply chain.
The short list of organizations needed to run hosted Calbraid, plus the calendar providers you choose to connect.
How to read this page
Subprocessors process customer-controlled data to operate Calbraid. Customer-directed providers are Google or Microsoft services you already use and instruct Calbraid to contact; they commonly act under their own agreement with you rather than as Calbraid subprocessors.
Applifyer SH.P.K.
Purpose: product operation, engineering, authorized support, security, and service administration for Applifyer, LLC.
Location: Kosovo.
Data: account, team, calendar, support, security, billing metadata, and operational data when required for authorized duties.
Microsoft Azure
Purpose: virtual compute, storage, networking, and infrastructure security for the primary Calbraid service.
Location: Germany West Central, European Union.
Data: encrypted provider credentials, account and team records, synchronized calendar data, billing metadata, and rotating service logs.
Cloudflare
Purpose: encrypted tunnel and edge transport, DNS, and access-controlled R2 database backup storage.
Location: Cloudflare global infrastructure.
Data: network metadata and encrypted traffic in transit; protected database backup copies under the stated retention schedule.
Resend
Purpose: transactional email delivery for account verification and password recovery.
Location: Resend infrastructure in the United States.
Data: recipient email address plus verification or recovery message content.
Stripe
Purpose: Checkout, subscriptions, invoices, payment methods, tax calculation where enabled, fraud prevention, and refunds.
Location: Stripe global infrastructure.
Data: purchaser and billing contact, plan, price, subscription, invoice, transaction, tax, and payment information. Calbraid does not receive full card numbers.
Customer-directed calendar providers
Purpose: identify a connected Google account and read or route authorized Calendar operations.
Data: account email, calendar list, calendar and event data, OAuth grant and provider revision metadata.
Microsoft
Purpose: identify a connected personal Outlook or Microsoft 365 account and read or route authorized Microsoft Graph calendar operations.
Data: account identity, calendar and event data, OAuth grant and Graph revision metadata.
Internal backup infrastructure
Applifyer also maintains a separately encrypted disaster-recovery repository on private infrastructure it controls. That infrastructure is not a third-party subprocessor. Access is restricted, copies are isolated from normal service use, and the public retention commitment still applies.
Changes and objections
We update this page before a material new subprocessor begins processing where practical. Organization customers may object on reasonable data-protection grounds by emailing info@applifyer.com. We will seek a reasonable alternative; if none is feasible, either party may terminate the affected paid service.
Subprocessor notices:
info@applifyer.com
Applifyer, LLC · 131 Continental Dr, Suite 305 · Newark, DE
19713 · United States