Legal · archive
Sub-processors — 2026-10-07 (archived)
This version was replaced on 9 October 2026. The current document is version 2026-10-09. The text below is unchanged (source text, SHA-256 a62f807188963b797620ce02214639386159cb600ae9bf1a5cba9a26d1882897). All versions: version archive.
Last updated: 7 October 2026
This list is Annex 3 of our Data Processing Agreement. For providers processing API content under the DPA, we announce additions or replacements at least 30 days in advance by email and on this page; you may object as described in section 6.2 (the 6 Oct 2026 UpCloud addition is an exception, see change history). Account data processed for our own purposes is outside the DPA under section 1.2 and is covered by our Privacy Policy.
May process API content — tier scope below
| Sub-processor | Service | Location of processing | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Hosting of the websites (including the dashboard), API gateway, database and encrypted backups | EU (data centre in Helsinki, Finland) | Provider's standard Art. 28 GDPR agreement required before customer-data processing; ISO/IEC 27001-certified data centres |
| DataCrunch Oy (trading as Verda), Helsinki, Finland | GPU servers for model inference (being phased out in October 2026; kept for now as a fallback) | Finland (EU) | Art. 28 GDPR data processing terms; ISO/IEC 27001 and SOC 2 Type II (per provider) |
| UpCloud Oy, Helsinki, Finland | GPU servers for model inference: our always-on inference capacity since 7 October 2026 for the EU tier and for Peer-to-Peer/Global base capacity, plus additional servers when EU capacity is busy (those only for the EU tier) | Finland (EU), data centre FI-HEL2 only | Art. 28 GDPR data processing terms in UpCloud's Terms of Service (effective 3 July 2026); EU data centres operated by UpCloud Oy without further sub-processors (per UpCloud's DPA); ISO/IEC 27001 (per provider) |
| Lium (lium.io), with independent third-party GPU providers | On-demand GPU inference for opted-in Peer-to-Peer keys when spare EU capacity is busy | worldwide (third-party GPU providers) | Transfers outside the EU/EEA happen only for keys you opted in; you are responsible for not sending personal data on such keys unless an adequate transfer basis applies for your use. The switch itself is not a transfer basis under Chapter V GDPR. |
EU-tier requests always stay in the EU. Without worldwide opt-in, Peer-to-Peer requests also stay in the EU. Request and response content is not stored on any node; this applies to EU capacity and Peer-to-Peer overflow alike. UpCloud runs our always-on GPU server and, while EU capacity is busy, additional servers that are deleted when no longer needed. All UpCloud servers are in data centre FI-HEL2 only, with encrypted disks and no request logs; request and response content is held in memory only for the duration of the request.
Account, billing and identity providers — no API content
The providers below may receive account, billing or sign-in data, but never API request content. Their roles depend on the service: some act as processors on our instructions; Stripe and Google act as independent controllers for their own payment or identity services. See the Privacy Policy for details.
| Provider | Service | Location | Role |
|---|---|---|---|
| Stripe Payments Europe, Ltd., Dublin, Ireland | Payments, tax calculation and invoices | EU; transfers to Stripe, Inc. (USA) under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses | Independent controller for payment processing; processor for invoicing |
| Scaleway SAS, 8 rue de la Ville-l'Évêque, 75008 Paris, France | Service emails (sign-in links, receipts and notices); planned, not in use at present | EU (Paris, France) | Processor, once enabled; its Art. 28 GDPR agreement is concluded before first use |
| Resend (Plus Five Five, Inc., San Francisco, USA) | Optional email sign-in links only; no Google sign-in data, billing emails or API content | Sending region Ireland; messages and delivery/account records stored in the USA | Account-data processor under its DPA; SCCs and EU-U.S. Data Privacy Framework |
| Google Ireland Limited, Dublin, Ireland | Google sign-in; verified email and stable account ID only | EU; transfers to Google LLC (USA) may occur under the EU-U.S. Data Privacy Framework | Independent controller for identity services |
Peer-to-Peer tier — current status
The Peer-to-Peer tier first uses spare EU capacity, with lower priority than EU-tier requests. When that capacity is busy, Peer-to-Peer requests may use on-demand GPU capacity rented through Lium (lium.io). Independent third-party providers operate the GPU hardware in various countries, including outside the EU/EEA. Processing outside the EU happens only for API keys whose customer has explicitly enabled the "Allow worldwide processing" switch. Without that opt-in, Peer-to-Peer requests stay on EU capacity and may be queued or rejected with a retryable error when busy. EU-tier requests always stay in the EU and have priority. Existing customers keep EU-only processing unless they opt in for the individual key. Request and response content is not stored on any node (zero payload retention). The existing 30-day notice and objection process still applies to new content sub-processors. This list does not assert Lium certifications or signed Standard Contractual Clauses.
Change history
| Date | Change |
|---|---|
| 27 Sep 2026 | First version |
| 28 Sep 2026 | Hetzner service scope and safeguard reference clarified; no provider added or removed |
| 30 Sep 2026 | Google sign-in and account-provider roles clarified; Hetzner data-centre location (Helsinki) and Scaleway status (not yet in use) stated; no provider added or removed |
| 1 Oct 2026 | Lium and independent third-party GPU providers added for opted-in Peer-to-Peer overflow; EU-only defaults, EU-tier priority, zero payload retention and transfer conditions clarified |
| 2 Oct 2026 | Resend added for optional email sign-in; US storage and transfer safeguards disclosed. API-content sub-processors, existing Google sign-in and billing paths unchanged. |
| 6 Oct 2026 | UpCloud Oy (Helsinki, data centre FI-HEL2) added as additional GPU capacity for EU-tier requests at peak load; EU-tier requests still stay in the EU. Added with effect from 6 Oct 2026 without the 30-day advance notice described above; existing customers were informed by email the same day. You may object in text form on reasonable data protection grounds until 5 Nov 2026; the rights in DPA section 6.2 otherwise apply, including termination with a refund of unused prepaid credit. |
| 7 Oct 2026 | UpCloud Oy (Helsinki, FI-HEL2), already listed since 6 Oct 2026, now hosts our always-on GPU for all tiers instead of DataCrunch Oy (Verda), which is being phased out in October 2026; no new sub-processor is added. EU-tier requests still stay in the EU; Peer-to-Peer requests without worldwide opt-in also stay in the EU. |