Subprocessors

Last updated: October 8, 2026

Entities we engage to process Contact (Lead) data on behalf of Users, under section 5 of the Data Processing Agreement (DPA). The full list of recipients of Users' data is in the Privacy Policy.

  • Supabase — database, authentication, file storage — EU/EEA, Frankfurt (Germany); possible remote access from the USA (SCC/DPF).
  • Railway — hosting of the API, background workers and queues (Redis) — EU/EEA, EU West, Amsterdam (Netherlands); possible remote access from the USA (SCC/DPF).
  • Vercel — hosting of the web application and public campaign pages — EU + USA (SCC/DPF).
  • Meta Platforms — Instagram API integration (receiving comments and messages, sending replies) for operations performed on the Controller's instructions; Meta also pursues its own purposes as a platform, under its own terms — EU + USA.
  • Google — Gemini API (AI suggestions; comment intent assessment is currently disabled) — EU + USA (Google's terms for the Gemini API as a processor). Export to the Controller's Google Sheets spreadsheet happens on its instructions and does not make Google a sub-processor in that respect (section 1).
  • OpenAI — fallback provider for AI features (as above) — USA (SCC/DPF).
  • Brevo — transactional and notification emails (may contain a Contact's name) — EU/EEA.
  • Expo (650 Industries) — mobile push notifications (may contain a Contact's name), onwards via Apple Push Notification service and Firebase Cloud Messaging — USA (SCC/DPF).
  • Sentry — error and performance monitoring (diagnostics) — EU (Germany) + USA (SCC/DPF).

Stripe, inFakt and RevenueCat process only the Controller's own billing data (not Contact data) and are not sub-processors under this DPA. The Processor informs the Controller by email of an intended addition or replacement of a sub-processor and updates the Subprocessors page at least 14 days before entrusting it with data, stating the entity, scope, location and transfer basis. Within that time the Controller may raise a reasoned objection; before any data is transferred the Processor considers the objection and agrees a solution (e.g. disabling the feature or an alternative way of providing it), and if that is not possible the Controller may end the affected service at no extra cost, with a refund for the unused period. The Processor imposes on sub-processors the obligations required by Art. 28(4) GDPR and remains liable to the Controller for their performance.