Legal

Sub-processors

Last updated: 19 May 2026

In accordance with Art. 28 GDPR, we inform our customers about all third parties (sub-processors) we engage to deliver our services and to whom we may transfer your users' personal data. We contractually ensure that all sub-processors maintain an equivalent level of data protection.

Infrastructure & Hosting

ProviderPurposeLocationData categoriesLegal basisPrivacy
Amazon Web Services (AWS)Cloud hosting, data storage, computeEU (Frankfurt, eu-central-1)All processed customer dataStandard Contractual Clauses (Art. 46 GDPR)Link
Vercel Inc.Edge hosting & CDN for the web frontendEU / USA (SCCs)IP addresses, page views, performance dataStandard Contractual Clauses (Art. 46 GDPR)Link
Cloudflare Inc.DDoS protection, DNS, TLS terminationEU / USA (SCCs)IP addresses, HTTP metadataStandard Contractual Clauses (Art. 46 GDPR)Link

Database & Storage

ProviderPurposeLocationData categoriesLegal basisPrivacy
Supabase Inc.Managed PostgreSQL database serviceEU (Frankfurt)Product and account data, user profileData Processing Agreement (Art. 28 GDPR)Link

Artificial Intelligence

ProviderPurposeLocationData categoriesLegal basisPrivacy
OpenAI, L.L.C.AI-powered product data enrichment (copy, attributes)USA (SCCs)Product titles, descriptions, attribute valuesStandard Contractual Clauses (Art. 46 GDPR)Link
Google LLC (Vertex AI)Alternative AI models for image analysis & translationEU / USA (SCCs)Product images, product textsStandard Contractual Clauses (Art. 46 GDPR)Link
DeepL SEAutomatic translation of product textsGermany (EU)Product descriptions, attributesData Processing Agreement (Art. 28 GDPR)Link

Payment Processing

ProviderPurposeLocationData categoriesLegal basisPrivacy
Stripe, Inc.Credit card and SEPA payment processingUSA / EU (SCCs)Billing address, payment method metadataStandard Contractual Clauses (Art. 46 GDPR)Link

Email & Communication

ProviderPurposeLocationData categoriesLegal basisPrivacy
Postmark (ActiveCampaign)Transactional emails (confirmations, notifications)USA (SCCs)Email address, name, email contentStandard Contractual Clauses (Art. 46 GDPR)Link
Loops.so Inc.Lifecycle email marketing (onboarding, product updates)USA (SCCs)Email address, name, usage behaviourStandard Contractual Clauses (Art. 46 GDPR)Link

Customer Support

ProviderPurposeLocationData categoriesLegal basisPrivacy
Intercom, Inc.In-app chat, Help Center, support ticketingUSA (SCCs)Email address, name, chat messages, usage dataStandard Contractual Clauses (Art. 46 GDPR)Link

Analytics & Monitoring

ProviderPurposeLocationData categoriesLegal basisPrivacy
PostHog Inc.Product analytics, feature usage analysisEU (Frankfurt, EU Cloud)Pseudonymised user IDs, events, session dataLegitimate interest / consent (Art. 6 GDPR)Link
Sentry (Functional Software, Inc.)Error and performance monitoringUSA (SCCs)Stack traces, user ID (pseudonymised), browser infoLegitimate interest (Art. 6(1)(f) GDPR)Link

Authentication

ProviderPurposeLocationData categoriesLegal basisPrivacy
Google LLC (OAuth)Social login via Google accountUSA (SCCs)Email address, name, Google user IDConsent (Art. 6(1)(a) GDPR)Link

Change notice

We reserve the right to update this list when sub-processors are added or removed. Material changes will be communicated to customers with an active Data Processing Agreement by email at least 30 days before they take effect.

Questions & objections

For questions about our sub-processors or if you wish to object to a change, please contact us at jakob@productbay.ai.