FTE Tracker

LegalDocument 04 of 04

Subprocessor List

The complete list of third parties that receive personal data in connection with FTE Tracker: what each one does, what it receives, and where it operates. It is written to be used by a procurement or compliance reviewer, so it also states what is deliberately not on the list, and why.

Last updated: 10 September 2026 Processes Customer Data: one provider Receives connection data only: three providers Contact: privacy@ftetracker.com
Contents

1What this list is

1.1

FTE Tracker engages a small number of third parties to help deliver the Service. This page is the list referred to in the Privacy Policy and in the Data Processing Agreement, and it is the list a Customer's authorisation of subprocessors attaches to.

1.2

It covers two kinds of recipient, and distinguishes them. One receives Customer Data, because the Service's records live there. The others receive no Customer Data at all, but do receive the visitor's IP address, browser user-agent string and referring page, because a browser cannot request a file from a third party without disclosing those things. Both kinds are listed, because both are a transfer of personal data and a reviewer is entitled to see them.

1.3

Last updated: 10 September 2026. This page is the authoritative version of the list. Where an older copy has been sent to a Customer in a questionnaire or a proposal, this page governs.

2Defined terms

2.1

These terms carry the same meaning here as in the Privacy Policy, the Terms of Service and the Data Processing Agreement.

FTE Tracker, we, us, our
Kevin Alvarado, a natural person doing business under the business name FTE Tracker. FTE Tracker is a sole proprietorship. It is not a corporation, a limited liability company or a partnership, and it has no parent, subsidiary or affiliated entity.
Service
The hosted FTE Tracker application supplied to a Customer under the Terms of Service.
Site
The public FTE Tracker marketing website.
Demo
The public demonstration published on the Site, which runs entirely inside the visitor's own web browser and stores nothing on our servers.
Customer
An organization that has agreed with FTE Tracker to use the Service. Customers are organizations, not individuals.
Customer Data
All data that a Customer or its Authorized Users enter into, upload to, or generate within the Service, including all Personal Data contained in it.
Subprocessor
A third party engaged by FTE Tracker to process Personal Data contained in Customer Data, or to which personal data is disclosed by the delivery of a page or file we publish.
PHI
Protected health information as defined at 45 CFR 160.103 under the Health Insurance Portability and Accountability Act.

3The current list

Scroll the table sideways on a narrow screen

FTE Tracker subprocessors, their function, the data they process and where they operate
Subprocessor Function Categories of data processed Location of processing
Supabase Managed PostgreSQL database, authentication by email and password, storage of multi-factor authentication factors, and the server-side function that creates new user accounts. This is where the Service's records live.

Used by: the Service. Not used by the Site or the Demo.
All Customer Data held by the Service: account records (first and last name, email address, role, supervisor's email address, contracted weekly hours, active status, optional photograph of the person); effort allocations and their dated history; time entries, including the free-text note, the grant fund charged, and leave records such as a sick day; approvals, including the reviewer's identity, decision, timestamp and note; quarterly certification package records and attestation text; and the event log.

Authentication material: email address, password (stored and verified by Supabase, never by FTE Tracker's own code) and the authenticator secret behind the six-digit code.
Cloud infrastructure operated by Supabase. See section 4.
jsDelivr Public content delivery network. Each load of the signed-in application fetches the authentication client library from it.

Used by: the Service. Not used by the Site or the Demo.
No Customer Data. Only what a browser discloses by making the request: the user's IP address, browser user-agent string, and the address of the page making the request. Global content delivery network. Files are served from an edge location near the person making the request, so this processing is not confined to one country.
Google Fonts Delivery of the Inter typeface, and on the Site also Instrument Serif, from fonts.googleapis.com and fonts.gstatic.com.

Used by: the Site, the Demo and the Service.
No Customer Data. Only what a browser discloses by making the request: the visitor's IP address, browser user-agent string, and the address of the page making the request. This applies to a visitor who merely opens the Site or the Demo, as well as to a signed-in user. Global network operated by Google. Files are served from an edge location near the visitor, so this processing is not confined to one country.
Static hosting provider
named on request
Delivery of the files that make up the Site, the Demo and the Service's interface. It runs no application logic and holds none of the Service's records.

Used by: the Site, the Demo and the Service.
No Customer Data. The visitor's IP address and request details, which every web host necessarily processes in order to serve a file. Named in writing on request; see clause 3.1. Static files are served from an edge location near the visitor, so this processing is not confined to one country.
3.1

Static hosting. The files that make up the Site, the Demo and the Service's interface are delivered by a static hosting provider, which necessarily processes a visitor's IP address and request details in order to deliver them, as every web host must. It holds no Customer Data: the Service's records are held by the database subprocessor named above, not by the host. We name that provider in writing to any Customer or prospective Customer that asks at privacy@ftetracker.com, and it will be added to the table above.

3.2

The Demo makes no use of the first two. The Demo loads no database client and contacts no server of ours. The only outbound request it makes is for the typeface. Everything a visitor does in the Demo stays in that visitor's browser.

4Location of processing

4.1

We publish only claims we can evidence, and location is a claim reviewers rely on, so it is worth stating carefully.

4.2

The database. The Service's records are held on infrastructure operated by Supabase in a single hosting region. That region is confirmed in writing to any Customer or prospective Customer that asks at privacy@ftetracker.com, and it is stated in the Data Processing Agreement signed with a Customer that requires it there. We do not change the region of a live project without notifying Customers under section 8.

4.3

Delivery is not confined to one country. A content delivery network and a font service serve files from an edge location close to the person requesting them. Any statement that the Service is delivered from one country would be untrue of those requests, whatever is true of the database. We therefore do not make one.

4.4

A Customer with a contractual or grant-condition requirement about where records are stored should raise it before signing, so that it can be answered specifically rather than by reference to this page.

5What our subprocessors never receive

5.1

Signed certifications. When an Authorized User uploads a signed Time & Effort certification, the file is written to the storage of the browser it was uploaded from and stays there. It is not uploaded to our database subprocessor, nor to any file-storage service, nor to us. No subprocessor on this list ever receives a signed certification file.

5.2

Anything from the Demo. Nothing a visitor types into the Demo reaches any subprocessor, because the Demo transmits nothing but the request for the typeface.

5.3

Customer Data, in the case of the two delivery networks. jsDelivr and Google Fonts receive only the technical information described in the table. They receive no name, no email address, no time entry and no certification record. The same is true of the static host: it serves files and never receives a record held by the Service.

6Not on this list, and why

6.1

A short list is usually more informative for what is absent than for what is present. The following are absent deliberately.

  • No analytics or measurement provider. There is no analytics service, tracking pixel, session recording or heat-mapping tool on the Site, in the Demo or in the Service.
  • No advertising technology and no data broker. Nothing we publish carries an advertising tag, and we sell no personal information and share none for advertising.
  • No email delivery provider. The Service sends no email to Authorized Users. Accounts are created already confirmed, so no confirmation message goes out; there is no self-service password reset by email; and the second factor comes from the user's own authenticator application, not from an emailed code. Correspondence with privacy@ftetracker.com travels through ordinary email systems, and is correspondence with us rather than processing of Customer Data.
  • No customer relationship or support platform. Support is by email; there is no ticketing system holding Customer Data.
  • No artificial-intelligence or machine-learning provider. No Customer Data is sent to any model provider, and none is used to train a model.
  • No file storage service. See clause 5.1.
6.2

If any of these ever changes, it changes by being added to the table in section 3, with the notice described in section 8. There is no category of recipient that we consider too minor to list.

7How a subprocessor is vetted

7.1

FTE Tracker is operated by one person. The vetting described here is proportionate to that, and is described honestly rather than as if it were carried out by a security team.

7.2

Before a third party is engaged, we consider each of the following and record the conclusion.

  • Necessity. Whether the function can be performed without a third party at all. Where an asset can be served from our own files instead of a third party's, we prefer to remove the third party rather than to disclose to it.
  • Scope. The narrowest set of data the provider needs, and whether Customer Data can be kept away from it entirely.
  • Written terms. For a provider that will hold Customer Data, whether it publishes or will sign data processing terms committing it to process data only on instruction, to keep it confidential, to maintain appropriate security, to support deletion, and to restrict its own subprocessors. We do not engage a provider to hold Customer Data on any lesser footing. This test does not apply to a public delivery network that receives no Customer Data: we have no agreement with jsDelivr or with Google Fonts, they take no instruction from us, and each is a controller in its own right for the connection data it receives. That is the reason those two are candidates for removal rather than for negotiation.
  • Security posture. The provider's published security documentation, its handling of encryption in transit and at rest, its access controls, and its history of disclosed incidents.
  • Retention. Whether the provider can support the three-year post-termination retention described in the Privacy Policy, and deletion on request.
  • Advertising use. That the provider does not use data it receives from us for advertising, profiling or its own product development.
  • Exit. Whether we could move away from the provider, and what would be involved.
7.3

We review the list at least once a year, and again whenever a provider materially changes its terms or a Customer raises a question about one. A provider that no longer meets the criteria above is replaced or removed.

7.4

We remain responsible to the Customer for the acts and omissions of the subprocessor that processes Customer Data, to the same extent as if we performed the function ourselves, on the terms of the Data Processing Agreement. We do not extend that undertaking to the public delivery networks, for the reason given in clause 7.2: they receive no Customer Data, take no instruction from us, and are not engaged under terms we have negotiated. Clause 8.3 of the Data Processing Agreement states the same division.

8How a Customer is notified of a change

Thirty days' notice before a new subprocessor begins

Before engaging a new subprocessor, or replacing one on this list, we will email each Customer's designated administrator at least thirty (30) days before that subprocessor begins processing Customer Data, and update this page with a new "Last updated" date.

8.1

The notice will name the provider, the function it will perform, the categories of data it will receive, and the date it is due to begin. It will be sent from privacy@ftetracker.com.

8.2

Urgent replacement. If a subprocessor has to be replaced at short notice to preserve the security or the continued operation of the Service — for example because a provider suffers an incident or ceases to trade — we may make the change first. In that case we will notify each Customer's designated administrator as soon as reasonably practicable, and in any event within five (5) business days of the change, explaining what happened, and a Customer's right to object under section 9 applies from the date of that notice.

8.3

Where notice is sent. Notice goes to the administrator address each Customer designates. A Customer may add or change the addresses that receive these notices — for example a compliance or grants-office address alongside the administrator — by writing to privacy@ftetracker.com. Keeping that address current is the Customer's responsibility.

8.4

A change in a subprocessor's own corporate name, or a change in this page's wording that does not add a recipient or a category of data, is not a change requiring notice under this section. We will still update the page and its date.

9Objecting to a change

9.1

A Customer may object to a new subprocessor on reasonable grounds relating to data protection, by writing to privacy@ftetracker.com within thirty (30) days of the notice. The objection should say what the concern is, so that it can be answered.

9.2

We will work in good faith to address the objection, which may include making the change in a way that keeps that Customer's data away from the new provider, choosing a different provider, or explaining why the concern does not arise.

9.3

If the objection cannot be resolved within a reasonable time, the Customer may terminate the affected part of the Service, or the agreement, on written notice, and we will refund any fees the Customer has prepaid for the period after termination. That is the Customer's sole remedy for an unresolved objection, and the retention and deletion terms of the Privacy Policy apply to the data on termination.

10Sub-subprocessors

10.1

Each provider on this list engages its own infrastructure providers — a cloud platform beneath a managed database, or a network beneath a content delivery service. Those relationships are governed by that provider's own agreements and are described in its own public documentation, which we review under clause 7.2.

10.2

A Customer that needs the identity of the infrastructure provider beneath our database subprocessor, for a grant condition or a security questionnaire, should ask at privacy@ftetracker.com and we will answer specifically rather than by reference to this page.

11Certifications, and health information

11.1

FTE Tracker holds no SOC 2 attestation and no HIPAA certification. We have not undergone an independent security audit. Nothing on this page, on the Site, or in any answer we give to a questionnaire should be read as a claim to either. Where a provider on this list holds its own certifications, those are that provider's and are not ours; we do not present them as ours.

No PHI. No business associate role. No BAA.

The Service is not designed to receive protected health information. Customers and Authorized Users must not enter PHI into any field of the Service, including free-text description and note fields.

FTE Tracker does not act as a HIPAA business associate and does not execute Business Associate Agreements. No subprocessor on this list is engaged to receive PHI, and none should be assumed to be covered by a business associate agreement through us.

12Contact

12.1

Questions about this list, requests for the hosting region or the name of the static host, and objections under section 9 all go to privacy@ftetracker.com.

12.2

Kevin Alvarado, doing business as FTE Tracker, Commonwealth of Puerto Rico. This is the only contact address we publish for questions about this list.