Box · Trust
Subprocessor register
This register identifies the external services that can process Box personal data, what they do, and when they receive communication content.
Core infrastructure
Supabase, Inc. — authentication, PostgreSQL database, encrypted secrets vault, object storage and serverless functions. The primary Box project is configured in AWS eu-west-1 (Ireland). Data: account, connection, chat, AI, team, file and technical records. Transfer safeguard: Supabase DPA, EU regional storage and Standard Contractual Clauses where required.
Vercel Inc. — delivery and hosting of the public website and web application. Data: IP address, request/response metadata, static application assets and, for the same-origin bridge and waitlist proxy routes, the encrypted request/response stream including authentication headers or submitted content. Connected mail and Supabase data otherwise travel directly between the browser and those services. Vercel states that processing can occur in the United States and other subprocessor locations. Transfer safeguard: Vercel DPA and Standard Contractual Clauses.
Hostinger group entity applicable to Nivora’s account — virtual-server hosting for the Box WhatsApp bridge, waitlist endpoint and API proxy services. Data: linked-device session credentials, connected chat traffic, waitlist submissions and technical logs where those features are enabled. Transfer safeguard: Hostinger DPA and Standard Contractual Clauses where required. The exact contracting entity and server region are reviewed in the supplier record before production use.
AI and speech
OpenAI Ireland Ltd. — AI responses, summaries, classification and drafts requested through Box. Data: prompts and only the message excerpts or attachments needed for that request, plus technical usage metadata. API data is not used for general model training by default. Transfer safeguard: OpenAI DPA and applicable transfer mechanism. Retention is controlled through API settings; limited abuse-monitoring retention can still apply unless an approved zero-retention control covers the endpoint.
Groq, Inc. — speech-to-text only if the voice transcription feature is enabled for the user. Data: the submitted audio segment and technical request metadata. Provider keys stay server-side. This provider must remain disabled until a signed DPA, transfer assessment and production retention setting are recorded.
Google Gemini — not an authorised production subprocessor for Box communication content. Client-side Gemini credentials and direct calls are prohibited. Adding it requires a documented assessment, DPA, register update and in-product notice before use.
Payments and notifications
Stripe Payments Europe, Limited and Stripe affiliates — checkout, subscriptions, invoices, tax/payment operations and fraud prevention. Data: name, email, company, VAT/tax and transaction/device details; Stripe receives payment credentials directly. Stripe acts as processor for some services and independent controller for regulated payments, fraud and compliance. Safeguards are in Stripe’s DPA and Data Transfers Addendum.
Plus Five Five, Inc. (Resend) — delivery of Box waitlist, launch and service emails. Data: recipient and sender address, subject, message content, delivery and bounce events, and technical logs; connected mailbox and chat content is not sent for waitlist delivery. Resend states that account metadata, logs and API records are stored in the United States and standard-plan email/log data is retained for 30 days, with seven-day backups. Transfer safeguards: Resend DPA, 2021 EU Standard Contractual Clauses and its stated EU-US Data Privacy Framework participation.
Apple Inc. and applicable affiliates — Apple Push Notification service and App Store distribution for iOS. Data: device push token and, depending on the user’s notification settings, limited notification content. Lock-screen content is minimised and user-configurable. Apple may act under its own terms for platform operations.
Browser push provider — the browser vendor delivers optional web notifications after permission. Data: push subscription endpoint and encrypted payload. The applicable vendor depends on the browser chosen by the user.
User-directed connected platforms
Google LLC (Gmail and Google identity), Microsoft Corporation (Outlook/Microsoft 365 and identity), and Meta Platforms entities (Instagram, Messenger, Facebook Pages and WhatsApp) receive data when you connect their service or send an instruction through it. They hold the source account and ordinarily act as independent controllers for their platform. Box requests the minimum scopes documented in the Privacy Policy.
Unipile may be supported as an optional connection route in development, but it is not authorised for production customer data unless the connection screen identifies it, a signed DPA and transfer assessment are on file, and this register is updated before activation.
Changes and objections
We review providers for necessity, security, confidentiality, deletion, incident notice and lawful transfers before production access. A provider marked disabled or conditional above may not receive production customer content until its stated gate is complete.
Business customers give general authorisation for the subprocessors listed here. We will provide at least fifteen days’ advance notice of a new subprocessor that will process customer communication, unless an emergency security replacement makes prior notice impossible. Customers can object on reasonable data-protection grounds by emailing box@nivoraworks.com during that period. We will work on a reasonable alternative; if none is available, the affected feature or agreement may be ended.
Back to Box