{"lastUpdated":"2026-08-27","subprocessors":[{"id":"hetzner","name":"Hetzner Online GmbH / Hetzner Finland Oy","service":"Cloud infrastructure, primary database & object storage","purpose":"Hosts the Service's compute, primary database (including customer-scoped embedding/search storage), and primary object storage","dataCategories":"Customer Data submitted to or generated by the Service, including content, logs, metadata, backups, configuration data, and embeddings","location":"Helsinki, Finland (EU)","transferMechanism":"None (EU-only)","status":"active"},{"id":"azure-openai","name":"Microsoft (Azure OpenAI / Azure AI Foundry)","service":"AI / model provider","purpose":"LLM inference, document processing, and workflow assistance underlying the Service's AI agent capabilities","dataCategories":"Prompts, inputs, outputs, and context submitted to AI agents, including documents or extracted text where enabled","location":"Global processing; the current model deployment uses Azure's Global Standard deployment type","transferMechanism":"Microsoft Products and Services Data Protection Addendum, including the 2021 Standard Contractual Clauses for transfers requiring safeguards","status":"active"},{"id":"azure-backup","name":"Microsoft (Azure Blob Storage)","service":"Encrypted off-site database backup","purpose":"Stores encrypted base backups and write-ahead logs of the Service's primary database for disaster recovery","dataCategories":"Full encrypted copies of Customer Data held in the primary database","location":"Sweden Central (EU) storage region","transferMechanism":"Microsoft Products and Services Data Protection Addendum, including the 2021 Standard Contractual Clauses for transfers requiring safeguards","status":"active"},{"id":"google-gemini","name":"Google (Gemini API)","service":"Embedding model provider","purpose":"Generates customer-scoped embeddings used for search and retrieval within the Service","dataCategories":"Text chunks or conversation content used to generate embeddings","location":"Global processing through the Gemini API; no EU-only endpoint is configured","transferMechanism":"Google Data Processing Addendum, including the 2021 Standard Contractual Clauses for transfers requiring safeguards","status":"active"},{"id":"cloudflare-r2","name":"Cloudflare, Inc. (R2 object storage)","service":"Object storage for uploads and short-lived scratch data","purpose":"Stores file/attachment uploads submitted via the Service, and short-lived extracted web page content generated by agent tooling","dataCategories":"Uploaded files and attachments; short-lived extracted web page content","location":"Global; configured with an Eastern Europe best-effort location hint (not an EU jurisdiction restriction)","transferMechanism":"EU-U.S. Data Privacy Framework and, where required, Standard Contractual Clauses","status":"active"},{"id":"cloudflare-network","name":"Cloudflare, Inc. (network, CDN & tunnel)","service":"CDN, DNS, and outbound tunnel connectivity","purpose":"Terminates TLS at Cloudflare's edge and routes and proxies inbound traffic to the Service's origin infrastructure","dataCategories":"Connection metadata and request/response content transmitted through the Service","location":"Global network","transferMechanism":"EU-U.S. Data Privacy Framework and, where required, Standard Contractual Clauses","status":"active"},{"id":"posthog","name":"PostHog EU","service":"Platform analytics & session tracking","purpose":"Product analytics, usage diagnostics, and aggregate usage reporting for the Service","dataCategories":"User/session identifiers, device/browser metadata, feature interaction events, and timestamps; not used for application-log storage or model training","location":"Germany (EU data center); supporting processing may occur in other locations identified by PostHog","transferMechanism":"PostHog Data Processing Agreement, including the 2021 Standard Contractual Clauses for transfers requiring safeguards","status":"active"},{"id":"resend","name":"Plus Five Five, Inc. (Resend)","service":"Transactional & inbound email delivery","purpose":"Delivers account, security, and product email notifications, and receives inbound email sent to Botyard-hosted bot addresses","dataCategories":"Notification content, sender/recipient email addresses, delivery logs, webhook payloads, and inbound email content and attachments where applicable","location":"United States","transferMechanism":"EU-U.S. Data Privacy Framework and, where required, Standard Contractual Clauses","status":"active"},{"id":"openrouter","name":"OpenRouter","service":"Model routing (managed credits)","purpose":"Not currently active — feature-gated off pending launch. When enabled, would route certain customer AI requests to third-party model providers via OpenRouter.","dataCategories":"Not applicable — not yet processing Customer Data","location":"Not applicable","transferMechanism":"Not applicable","status":"not-yet-active","notes":"Before activation, this entry will be moved to the active list and notice will be given in accordance with the DPA's sub-processor notice provision."}],"changelog":[{"id":"2026-08-27-initial-publication","effectiveDate":"2026-08-27","description":"Initial publication of the sub-processor list, cross-checked against production infrastructure and vendor documentation."}]}