search icon

Complete your due diligence review

Check our compliance briefing notes for your location, find out more about international data transfers, and consult a list of sub-processors which we use to provide our products and services to you. For assurance that your data will be protected, access our security controls.

Due diligence essentials

Complete your third-party due diligence review before sharing your personal data with us.

Compliance briefing notes

Review our privacy compliance briefing notes for your location. 

International data transfer

We may need to transfer or access your personal data outside of your region. Find out about our compliance controls when transferring data.

Security controls

Complete your due diligence by reviewing our security practices at Sage.

List of Sage sub-processors

Review our list of Sage sub-processors for key products and services. If your product or service is not listed, please contact us for assistance. 

Product name Name of sub-processor Sub-processor location Data hosting & processing location Processing activities
Sage Business Cloud Accounting Amazon Web Services, Inc. USA USA Data hosting and cloud infrastructure
Post Mark USA USA Email provider, used for sending: Invoices, Payment Reminders, Customer Statements, Etc
  Pendo.io USA USA Track usage and provide contextual messaging to customers
  Cloudflare Inc USA USA Content delivery network provider
  Stripe USA USA Online Payment Acceptance Service
  Twilio USA USA Messaging Service
Sage Intacct Amazon Web Services, Inc. USA USA Hosting
Box USA USA Storage of customer data during implementation and for customer follow-up
  OSF Global Services Romania Romania Software development services
  Code42 Software USA USA Data backup services
  Basecamp USA USA Customer service
  Salesforce, Inc. USA USA Intacct Collaborate, in-house chat function (Chatter) for customer support requests
  Decision on Demand, Inc. USA USA SaaS rules for the Fixed Assets module
  Sumo Logic, Inc. USA USA Application log storage
  Elasticsearch, Inc. USA USA Kibana allows you to process logs (IP addresses) in order to merge them and create dashboards.
Sage X3 Amazon Web Services, Inc. USA USA Data hosting and cloud infrastructure
SendGrid, Inc. USA USA Email Sender
  Cloudflare Inc USA USA Content delivery network provider
  Pendo.io USA USA Track usage and provide contextual messaging to customers
  NewRelic USA USA Monitoring and observability
  Sumo Logic, Inc. USA USA Monitoring and observability
Sage Pastel Payroll Microsoft (365 integration) USA USA Email hosting, document storage, and collaboration tools
Netcash ZA ZA Banking Third-party
Sage 300 People (Desktop) Microsoft 365 USA USA Email hosting, document storage, and collaboration tools
Netcash ZA ZA Banking Third-party
Sage 300 People MCS (Cloud) Microsoft Azure USA USA Data hosting and cloud infrastructure
Microsoft 365 USA USA Email hosting, document storage, and collaboration tools
  Netcash ZA ZA Banking Third-party
  New Relic USA USA Analytics
Sage HR Amazon Web Services, Inc. USA USA Data hosting and cloud infrastructure
UAB Baltsoft Lithuania Germany Creation of PDF documents with electronic signature
  Google Ireland Ltd. Ireland Ireland Calendar, document viewing and single sign-on integration (SSO only used if using GSuite)
  Pusher Ltd. UK UK Control of all push messages for the mobile application
  Slack Technologies, Inc. USA USA Team chat and collaboration via the Internet (requires prior creation of a Slack account).
  SendGrid, Inc. USA USA Sending emails from the cloud
  Salesforce, Inc. USA USA CRM platform for first-level customer service enquiries
  Intercom, Inc. USA USA CRM platform for second-level customer service enquiries
Sage 50 Express Yodlee (Banking) ZA ZA Various banks for direct feeds
Netcash ZA ZA Banking Third-party
Sage 50 Partner Yodlee (Banking) ZA ZA Various banks for direct feeds
Netcash ZA ZA Banking Third-party
Sage Business Cloud Payroll Professional Amazon Web Services, Inc USA USA Data hosting and cloud infrastructure
Cloudflare Inc USA USA Content delivery network provider
  Google Analytics USA USA User Analytics
  Pendo.io USA USA Track usage and provide contextual messaging to customers

When using our products or services, certain features may rely on centralised or Shared Services provided by specialised teams within the Sage Group. These internal services, known as Core Services, are designed to support the delivery, security, and performance of our software and may involve the processing of personal data by different Sage entities located in various regions.

Please note that while the sub-processors listed on this page are primarily engaged by Sage to process personal data on behalf of its customers (i.e., as processors), some of these entities may also provide services to Sage in other contexts, including where Sage acts as an independent data controller

  • In such cases, the processing activities may relate to Sage’s own business operations—for example, internal analytics, communication tools, or customer relationship management—and are not performed on behalf of customers or in connection with the services we provide to them
  • For more information about how Sage processes personal data in its role as a controller, including the purposes and legal bases for such processing, please refer to our privacy notice

In particular, if your use of the product or service includes any of the following Core Services, your data may be accessed or processed by dedicated teams within the Sage Group:

 

  • Sage Network services, including interconnectivity features or services that facilitate data exchange between platforms; among them:
  1. Banking Service: Automation of the bank reconciliation process. Hosted in AWS, in two regions: EU (Dublin, Ireland) and US (North Virginia, USA). Data is stored in one of these data centres depending on where the your bank is located.
  2. Compliance: Capabilities to addresses all relevant compliance reporting requirements such as e-invoicing, Regulatory reporting, Tax validation and remitting to local Authorities, ID validation and document signing. Data is hosted by AWS in Frankfurt/Sydney. Only Australia customer data is kept in Sydney, the rest of Compliance Service is in Frankfurt.
  3. Payments Acceptance/Out: Solution to accept and receive payments, adding a ‘Pay Now’ button to sales invoices and customers to make supplier and salary payments within their Sage product. We integrate the most known Payment’s providers, such as GoCardless, Stripe, Paypal, IfThenPay.
    Payments In data is hosted by AWS in EU (Dublin) and US (North Virginia) for US customer data.
    Payments Out Data is hosted by AWS in EU (Dublin) and data goes into Modulr, AWS and Cloudflare.
  4. Sage ID: Service that lets users establish their digital identity and authenticate in our products. Auth0-Okta provides identity and access management services.
  5. Sage Verify: Authenticator app which acts as an additional security layer to let users establish their identity before accessing Sage products and services. Sage Verify uses the following sub-processors: Auth0-Okta for identity and access management services, Crashlytics - for tracking crashes, Google Analytics – for website analytics, and Phrase – for translating content.
  6. AP automation: Capabilities to receive, process, pay, and reconcile a supplier or vendor bill inside the product. If you are a French customer we use Veryfi for OCR capability.

Cloud infrastructure and hosting services, which ensure high availability, scalability, and data resilience;

  • Cyber defence and managed security services, designed to monitor, detect, and respond to cybersecurity threats in real time
  • These teams operate under a Shared Service model to provide consistent quality and security across all Sage platforms globally. While the processing of personal data may occur across multiple jurisdictions as part of these operations, all such processing is governed by the same strict technical, organisational, and contractual safeguards, in accordance with applicable data protection laws including the General Data Protection Regulation (GDPR)

  • Sage engages the Sage Affiliates listed below to perform activities related to our Core products, Cyber Defence and Service Maintenance. These affiliates may operate under the same corporate structure but in different regions, leveraging shared resources, infrastructure, and expert services to process data on behalf of Sage.
  • Sage Group has implemented appropriate intra-group agreements, data transfer mechanisms (such as Standard Contractual Clauses), and access controls to ensure that any cross-border data transfers or internal processing activities are secure, transparent, and legally compliant.

Read the full list of Sage Affiliates.

Sage offers additional services and functionalities created by independent developers (tech partners). If you have contracted any functionality with these third parties, they may act as sub-processors of your data. See the list of Tech Partners available for each region:

France: https://fr-marketplace.sage.com/fr-FR/home
Germany: https://portal.sage.de/Appcenter/Frontend/
Portugal: https://pt-marketplace.sage.com/
Spain: https://marketplacepartners.sage.com/
United Kingdom: https://uk-marketplace.sage.com/en-GB/home
United States: https://us-marketplace.sage.com/en-US/home

For any questions relating to data processing and agreements with sub-processors, please contact the Data Protection Officer.