Subprocessors
Version 1.0 · Effective August 8, 2026
Peony & Lace — Subprocessors
Version 1.0 · Effective at product launch
What this page is. Peony & Lace (a product of Ellis Intelligence LLC) engages the third parties below ("Subprocessors") to process Customer Data on our behalf in delivering the Service. This is the public disclosure described in our Data Processing Addendum ("DPA") §5.1, kept current as our stack changes.
Ellis Intelligence LLC, a Colorado limited liability company, operates Peony & Lace as a d/b/a; Peony & Lace is not a separate legal entity. This page describes the Subprocessors used specifically by the Peony & Lace Service. Ellis Intelligence LLC has no subsidiaries or affiliated entities, and no entity other than Ellis Intelligence LLC processes Customer Data as part of the Service.
Update cadence & your objection right
We review this list quarterly. Before we engage a new Subprocessor, we specifically inform affected customers in writing — by email to the account's designated contacts, or by in-product notice — with notice deemed given when sent, and we post the change here in addition to (not instead of) that written notice. Customers have 30 days from the date notice is given to object on reasonable data-protection grounds; a timely objection suspends our use of the new Subprocessor for that customer pending resolution, per DPA §5.3.
Current Subprocessors
Peony & Lace — current Subprocessor list
Infrastructure and hosting
| Subprocessor | Purpose | Data accessed | Region | Notes |
|---|---|---|---|---|
| Cloudflare, Inc. | Edge, DNS, DDoS, WAF, Access gating, tunnel; marketing site on Cloudflare Pages | Network metadata; request bodies in transit, not at rest | US (global edge) | Cross-brand. |
| Fly.io, Inc. | Production application hosting + database | Tenant data (Planner, Couple, guest) in transit and at rest | US (iad / Ashburn, VA) | Chosen production host. |
| Cloudflare R2 (via Litestream) | Continuous SQLite backup -> point-in-time restore | Encrypted copies of the tenant database file | US (R2) | Streaming replication of tenant SQLite to R2. |
Artificial intelligence
| Subprocessor | Purpose | Data accessed | Region | Notes |
|---|---|---|---|---|
| Anthropic, PBC | AI-assisted venue research and outreach drafting | Wedding metadata (date, location, vibe, budget), minimized to avoid identifying Couple data where possible | US | Masked before transmission; see Privacy Policy §7(b) and DPA Schedule 2. |
Billing and communications
| Subprocessor | Purpose | Data accessed | Region | Notes |
|---|---|---|---|---|
| Stripe, Inc. | Subscription billing | Billing contact + tokenized payment method | US | — |
| Resend Inc. | Transactional email | Recipient address + message content | US | — |
| Google LLC (Workspace) | Our internal business email | Our internal email only; not customer-product data | US | — |
A category with no entries is omitted from the published page rather than shown empty. A vendor we have not engaged is never listed here — planned or candidate vendors are disclosed, if at all, through the notice mechanics above, at the time we engage them.
Subprocessors NOT used. No brokerage, custodian, or regulator system is a Subprocessor.
Categories of Data Subjects: Planner's team members; Couples; wedding guests (guest records carry no age or minor-status field; minors are not distinguishable from adults in storage)
Data Residency
Data at rest is stored in the United States. Production hosting and backup replication are U.S.-region-pinned. Some of our infrastructure providers operate global edge networks for content delivery; data at rest stays U.S.-only under our configuration.
Customers Outside the United States
We do not currently market to or onboard customers in jurisdictions that prohibit U.S. data processing under their data-protection law. Customers in the EU/EEA, UK, or Switzerland may onboard subject to the Standard Contractual Clauses ("SCCs") incorporated by reference into our DPA (together with the UK Addendum, for UK transfers).
Audit Rights
You may request a summary of our subprocessor-management practices by emailing [email protected]. SOC 2 Type I is planned; an auditor has not yet been engaged; our report will be available under NDA once complete. We do not permit direct audit of our Subprocessors; we share their relevant audit reports under NDA.
For a customer whose personal data is transferred under the SCCs or the UK Addendum incorporated into our DPA, nothing in this section limits that customer's audit and inspection rights under Clause 8.9 of the SCCs. For that customer, an audit request is satisfied first by our security-posture documentation (or SOC 2 report, once one exists) together with the relevant Subprocessors' audit reports under NDA; any further Clause 8.9 inspection is conducted on reasonable notice, during business hours, subject to confidentiality obligations, and at the customer's expense except where the audit reveals material non-compliance.
Contact Us
Ellis Intelligence LLC Attn: Privacy & Security — Peony & Lace Email: [email protected]
Related: Privacy Policy · Terms. This list is referenced by, and generated in accordance with, our Data Processing Addendum. Peony & Lace is not affiliated with, endorsed by, or acting on behalf of any wedding venue, vendor, or government agency.
Related: Privacy Policy · Terms. This list is referenced by, and generated in accordance with, our Data Processing Addendum. Peony & Lace is software, not a wedding-planning service.