Sub-processors
Last updated: Oct 7, 2026
For business customers, we process report data on their behalf (data processing agreement) using these sub-processors (Art. 28(2) GDPR):
- Cloudflare, Inc. (USA): delivering the website and app, protection from attacks, Turnstile. Worldwide network, usually a data centre close to the user. EU-US Data Privacy Framework, plus standard contractual clauses.
- Supabase Pte. Ltd. (Singapore): database, sign-in, file storage, contact form. Stored encrypted in Frankfurt, Germany; maintenance and support also from Singapore and the USA. Standard contractual clauses.
- Google Cloud EMEA Ltd (Ireland): creating and sealing the PDFs, and database backups, in Frankfurt, Germany. For access from the USA: EU-US Data Privacy Framework (Google LLC).
- OpenAI Ireland Ltd (Ireland): AI features: writing reports from what is said and typed, reading photos, listing what's missing, building forms. Processing also in the USA and other countries. Standard contractual clauses.
- AssemblyAI, Inc. (USA): turning speech into text while someone talks to write a report, telling different voices apart. Processing in the EU; recordings and text are deleted there once converted. Processing in the EU; standard contractual clauses for any access from the USA.
- Resend (Plus Five Five, Inc., USA): sending emails. EU-US Data Privacy Framework, plus standard contractual clauses.
- Functional Software, Inc. (Sentry) (USA): error reports. Servers in Frankfurt, Germany; access from the USA possible. EU-US Data Privacy Framework, plus standard contractual clauses.
Stripe Payments Europe, Limited and PostHog, Inc. only receive our own data (privacy policy).
Changes
We email business customers at least 30 days before adding or replacing a sub-processor. A customer may object for good cause relating to data protection and, if we can't agree, terminate before the change.
Data Act (Art. 28 of Regulation (EU) 2023/2854)
Where processing happens is listed above. Glockner Holding UG (haftungsbeschränkt) is subject to German and EU law; providers based in the USA or Singapore also to theirs. Data is stored and transmitted encrypted. Providers outside the EU are bound by the Data Privacy Framework or standard contractual clauses to review requests from authorities and challenge unlawful ones. We only disclose data where a law or a decision recognised in the EU requires it, only what is necessary, and tell the customer where we're allowed to.