Subprocessors

AmpVerve uses the following subprocessors to deliver our platform. Each one is contractually bound to GDPR-equivalent data-protection terms.

Current subprocessors

Subprocessor Purpose Data categories Region
Microsoft Azure Compute, database, storage, key management Customer account data, device telemetry, encrypted credentials UK South + West Europe
Microsoft Entra ID Identity, single sign-on, MFA Email, name, role, sign-in metadata EU
Stripe Payment processing, payouts Cardholder data, billing address (PCI-DSS Level 1) EU + US
Brevo Transactional email and notifications Email address, name, message content EU
Octopus Energy (Kraken API) Tariff data, smart meter readings API tokens, MPAN, consumption UK
Enode EV / charger / battery aggregation OAuth OAuth tokens, device telemetry EU
Smartcar Vehicle telemetry OAuth OAuth tokens, VIN, location, SoC US + EU
Solarman Solar inverter cloud aggregation API credentials, plant telemetry Global
EPEX SPOT (LocalFlex) UKPN flexibility market platform FSP credentials, asset metadata, baselines EU
Electron (ElectronConnect) SSEN flexibility market platform FSP credentials (VAOU_WA), asset metadata UK
OpenChargeMap Public charging station directory None (read-only public data) UK
Postcodes.io UK postcode geocoding None (postcode lookup only) UK
OSRM Trip routing None (anonymous lat/lon pairs) EU

Notification of changes

We notify customers at least 30 days before any new subprocessor is added or an existing one is replaced. To subscribe to change notifications, email privacy@ampverve.com with the subject Subscribe: subprocessor changes.

Customer right to object

Enterprise customers may object to a new subprocessor in writing within the 30-day notice window. If we cannot accommodate the objection, the customer may terminate the affected service for that subprocessor without penalty.

How we evaluate subprocessors

Last reviewed: April 2026. Contact: privacy@ampverve.com · DPO: dpo@ampverve.com