Subprocessors

Cavatim subprocessors for hosting, payments, email, analytics, AI, and integrations

This page lists the processors and integration providers Cavatim relies on to operate the planner, billing, support, analytics, AI, and connected-calendar features.

Last updated: July 13, 2026

On this page

Controller and operator

James Boyce trading as Cavatim operates Cavatim from the United Kingdom. Postal address is supplied on invoices, privacy-rights correspondence, and verified legal requests.

Processor and transfer questions can be sent to support@cavatim.com.

Current processors and providers

  • Hostinger: the production VPS, network infrastructure, server storage, local database backups, and SMTP email transport used for the web app, API, worker, analytics, support, and transactional messages.
  • Stripe: payment processing, subscription administration, invoices, tax support, checkout, billing portal, and refund workflows.
  • OpenAI API: optional AI-assisted planning, reflection, summarisation, voice transcription, goal decomposition, task prediction, and agent workflows when those features are used.
  • Cavatim-operated analytics: self-hosted telemetry endpoints on Cavatim infrastructure for consented public-page analytics, product lifecycle metrics, reliability, and security events.
  • GitHub: source control, CI/CD, security scanning, and deployment automation. Customer planner content is not intended to be stored in the source repository or CI artifacts.
  • Google and Microsoft integrations are supported by the codebase but were not configured in production at the date of this review. This page and the internal processor register must be updated before either provider begins processing production integration data.

Data categories

  • Account identifiers, authentication events, billing identifiers, support messages, technical logs, and product telemetry.
  • Planner, goal, recurring-task, reflection, workflow, settings, import/export, and backup data needed to provide the service.
  • Calendar, mailbox, or identity-provider data only when the user connects the relevant provider.
  • AI prompts, outputs, and planner context only when AI-assisted features are used.

Subprocessor changes

Cavatim reviews subprocessors before use for purpose, data categories, region, DPA or equivalent terms, transfer safeguards, and security fit. Material changes are reflected on this page and in the internal processor register before the provider begins processing production customer data.