Sub-processors
The list your security review asks for. Six entries are always in play; the rest only exist if you turn on the feature that needs them, and a Fieldbase running local-first reaches none of them at all.
Last updated
On this page
A sub-processor is a third party that processes data on our behalf in order to deliver Fieldbase. This page lists all of them. It is referenced by the Privacy policy and, for customers with a data processing addendum, it is the list that addendum points at.
Two things to hold in mind while reading it.
Local-first changes the question. With cloud sync off, your Customer Data never leaves your devices, and nothing in the tables below receives any of it. The list describes the maximum reach of the service, not what every customer’s deployment actually touches.
Most of this list is conditional. Only the first table applies to every account. Everything after it engages when you enable a feature, and stays inert when you do not.
1. Always in use
These operate for every account that uses Fieldbase Cloud.
| Sub-processor | What it does | What it receives | Where |
|---|---|---|---|
| Google Cloud Platform (Google LLC) | Hosting: application runtime, database, object storage for photographs and attachments, key management, backups. This is where Fieldbase Cloud runs. | All Service Data and all synced Customer Data | United States (us-central1) by default; European or Asia-Pacific regions available for Enterprise deployments |
| Google LLC — Sign in with Google | Authentication, where a user signs in with a Google account | Name, email address, the provider’s stable subject identifier | United States |
| Microsoft Corporation — Sign in with Microsoft / Entra ID | Authentication, where a user signs in with a Microsoft account, and SAML federation for organisations using Entra | Name, email address, the provider’s stable subject identifier | United States / customer’s tenant region |
| Mailgun (Sinch / Pathwire) | Transactional email: invitations, device approvals, security and account notices | Recipient email address, recipient name, message contents | United States or European Union, depending on deployment |
| Google Maps Platform (Google LLC) | Base map tiles. Requests are proxied by our servers, so the provider sees our service rather than your device or your IP address. Nothing is cached or re-hosted by us. | Tile coordinates for the areas viewed | United States |
| Google Analytics (Google LLC) | Page-view counts on the fieldba.se marketing website only. Not present in the Applications or in Fieldbase Cloud, and not loaded at all until a visitor accepts the consent banner. |
Pseudonymous website usage data, IP address | United States |
Your own identity provider, where you configure SAML, is not a sub-processor of ours — it is your system, and we receive an assertion from it.
2. Only when you enable the feature
None of these are contacted unless the corresponding feature is switched on.
| Sub-processor | Feature | What it receives | Where |
|---|---|---|---|
| Copernicus Data Space Ecosystem (ESA / operated by a consortium) | Satellite imagery — Sentinel products | A bounding box around the area of interest, and a date range | European Union |
| NASA Earthdata / Common Metadata Repository | Satellite imagery — HLS product catalogue and granules | A bounding box around the area of interest, and a date range | United States |
| Microsoft Planetary Computer (Microsoft Corporation) | Satellite imagery catalogue | A bounding box around the area of interest, and a date range | United States |
| OpenWeather Ltd | Field weather | A coordinate, and the time range requested | United Kingdom |
| Google Weather API (Google LLC) | Field weather, where configured as the provider | A coordinate, and the time range requested | United States |
| Google — Gemini API (Google LLC) | Photo analysis: estimating what is in a plot photograph | The selected photograph and the question asked of it | United States |
| Google — Gemini API (Google LLC) | Notebook assistant: drafting analysis code | The request, your organisation’s trait keys and design attributes, and the notebook cells already written | United States |
On the two Gemini entries: what comes back is a proposal a person accepts or rejects, never a value written into your record. Both features are metered, configured per organisation, and can be left off permanently. If your review requires that no field data reach a model provider under any circumstances, say so before deployment and we will confirm it at the deployment level rather than leaving it to a setting somebody could change.
Your correction source is not on this list. RTK corrections come from whichever NTRIP caster you point Fieldbase at — a public regional network, a commercial provider, or your own base station. That connection is between your receiver and that caster under their terms, we do not proxy it, and we do not receive its data.
3. Our own people and tooling
b0gy staff can reach production systems only through audited, role-limited access, and can reach a customer machine only through the consent handshake described in clause 5 of the Terms of service. Every member of staff is under written confidentiality obligations.
Our infrastructure is declared in Terraform and changed by review rather than by hand in a console, and deployment pipelines authenticate with short-lived workload identity, so there are no long-lived keys sitting in CI. The Security page has the rest.
4. Changes to this list
We will post an updated version of this page, and change the date at the top, before a new sub-processor begins processing Customer Data.
Customers with a data processing addendum, and any other customer who asks, are notified by email at least 30 days in advance, and may object on reasonable data protection grounds within that period. If we cannot resolve an objection, you may terminate the affected part of your subscription and receive a pro-rata refund of prepaid fees — which is a real remedy rather than a formality, because export is never gated and leaving costs you nothing but the decision.
To join that notification list, write to privacy@fieldba.se with “sub-processor notices” in the subject.
5. Contact
Questions about anything on this page, or a request for the data processing addendum, go to legal@fieldba.se or privacy@fieldba.se.
b0gy LLC, Las Vegas, Nevada, United States.
The other documents
Privacy policy
UpdatedWhat the apps, the cloud service and this website collect, the legal bases for it, how long it is kept, and the rights you can exercise over it.
Terms of service
UpdatedPlans, seats and billing; ownership of your season; the safety terms governing machine control; warranties, liability and how either side ends the agreement.
Acceptable use policy
UpdatedThe limits on how Fieldbase may be used: the service itself, other people's data and land, and the safety rules governing machine control.