Sub-processors
Why this page exists
When you use Ever Gauzy Cloud to process personal data, we act as your processor and you are the controller. Article 28 GDPR says we may not bring in another processor without your authorisation, and that you must be told in advance when we intend to add or replace one so that you have a real chance to object.
This page is that disclosure. It names every provider we engage to process personal data for the hosted Service, says what each one does, where it does it, and what categories of data reach it. Our Data Processing Addendum refers to this page, and your general authorisation to the providers listed here is given through it.
It is also written for people who are not our customers — someone whose employer uses the Service, or whose data ends up here for some other reason — because "who else can see this" is a fair question and the answer should not be available only to the person paying the invoice.
What counts as a sub-processor
A sub-processor is a third party we engage that processes personal data on our behalf and on our instructions, under a written contract meeting Article 28 GDPR. A provider that keeps the servers running, delivers your email, catches our errors or answers your support chat is a sub-processor.
Three things are not sub-processors, and lumping them in would make this page less accurate rather than more complete:
- A provider that never touches personal data. A design tool or an accounting package we use internally is not in the path of your data.
- A company that decides its own purposes. A payment processor acting on its own regulated obligations — fraud prevention, anti-money-laundering, card-scheme rules — is a controller in its own right for that part, not our processor. Those recipients are described in the Privacy Policy instead.
- Something we run ourselves. Our databases, object storage, secrets manager and container platform are ours. There is no third party to disclose. The infrastructure section below explains what we operate and what genuinely sits in front of it.
What this page covers
The hosted Service we operate at gauzy.co, for Ever Gauzy specifically. Other products in our range have their own list on their own domain, and the providers differ between them — do not read this one as covering a product it does not name.
It does not cover a deployment you run yourself. If you install our open-source software on your own infrastructure, you choose your own providers with your own credentials and contracts. The third tier below exists to make that distinction visible rather than to blur it.
This page is versioned and dated. The version in force, and the date it took effect, are at the end.
How to read this list
The three tables that follow mean genuinely different things, and reading them as one flat list will give you the wrong answer.
Here is why the split exists. Our products are open-source at their core and built to be connected to other things, so more than 160 distinct third-party providers appear somewhere in our source code across our whole range of products. The overwhelming majority of them are never engaged by us for anything. Some are optional integrations that do nothing until somebody switches them on. Many are reachable only in a deployment that somebody else runs, with their own account and their own credentials.
Publishing all of them as "our sub-processors" would be inaccurate, and inaccurate in the worst direction: it would tell you your data reaches companies it never touches, while burying the handful that it actually does. A list that is technically exhaustive and practically misleading is not a disclosure. So there are three tiers.
Tier 1 — always engaged
If you use the hosted Service, these providers are in the path. There is no setting that removes them, because they are part of how the Service is delivered to everyone.
This is the real Article 28 sub-processor list. It is the tier to use when you are completing a data protection impact assessment, mapping your transfers, or deciding whether you can use the Service at all. It is short, and it is short because we run our own infrastructure rather than renting someone else's.
Tier 2 — engaged only if you turn something on
A provider in this tier is engaged only when a specific feature, connector or integration is enabled. Enable nothing and it is never involved, and no data of yours ever reaches it.
Who does the enabling depends on the feature:
- You or your workspace administrator, by switching on a feature or connecting an account in the product's settings — a payment provider, an analytics tool, a chat widget, a calendar or repository connector.
- An individual user, by making a personal choice — signing in with a social account, for example, or connecting their own third-party tool.
The table names the feature or setting that activates each provider, so you can check your own configuration against it rather than take our word for the current state. If you want to know precisely which of these are live for your workspace today, ask us at [email protected] and we will tell you.
Enabling one of these is a decision to send your data somewhere else, and it is yours to make. The provider's own terms and privacy notice then apply to what it does, alongside our contract with it.
Tier 3 — self-hosted deployments only
Several of our products are published as open source and can be run on your own infrastructure. When you do that, you choose the database, the object storage, the email relay, the AI provider and everything else, using your own accounts and your own credentials.
The providers in this tier are listed only so that you can see what the software can be pointed at. They are not our sub-processors, and they never become ours by appearing here.
In a deployment you run: we process nothing, we have no access to it, we are not your processor for it, and nothing on this page or in our Data Processing Addendum describes it. You choose those providers, you contract with them, you hold the credentials, and the obligations to your own users are yours alone. The open-source section of our Terms of Service sets out the same split.
If you run a deployment yourself and need to publish a sub-processor list of your own, this tier is a useful starting inventory. It is not your list — only you know which of these you actually configured.
What the columns mean
- Sub-processor — the contracting legal entity, not the brand on the website. Where a provider has a separate European establishment that contracts with us, that is the one named.
- Purpose — what it does for the Service, specifically enough to be checked. Not "business operations".
- Location — where the processing takes place, or the provider's place of establishment where processing is distributed. Where a provider contracts through a European establishment but processes elsewhere, this column says both, because the two are different facts and only naming the first would flatter us.
- Transfer mechanism — for a provider outside the European Economic Area, the Chapter V instrument we actually rely on for that specific provider: an adequacy decision, the Standard Contractual Clauses, or nothing yet. Where it reads "To be confirmed", we have not yet evidenced an instrument for that provider, and we would rather say so here than print one we cannot produce. That is a live piece of work, not a formula. Providers established inside the EEA need no mechanism and say so. For the third tier the transfer is not ours at all — you choose the provider and hold the contract. The general rules behind this column are in the international transfers section of our Privacy Policy, and we will give you a copy of the safeguards for a named provider on request.
- Personal data — the categories that reach that provider. Categories, not a promise about volume: a provider that receives email addresses receives them for the people who trigger the feature, not for everyone.
Why this list is deliberately longer than it needs to be
We list providers we may engage, not only the ones engaged today. Where we have configured a provider, kept one available behind a feature flag, used one recently, or expect to use one for a purpose already described here, it appears in the tables below — even if no data has reached it this month, and even where we currently run the equivalent ourselves.
We do this on purpose, and you should read the tables with it in mind:
- A provider appearing here is not proof that your data has reached it. It means the provider is within the scope of what we have told you we may do, at the tier shown. The tier is the part that tells you when it is engaged.
- Where we self-host something today — our analytics, our job runner, our databases, our object storage — we say so, and we also name the hosted service we would move to, so that a later change is covered by a disclosure you have already seen rather than by a fresh surprise.
- The alternative is worse. A list that names only today's exact set has to be re-issued, and re-consented, every time an engineer changes a setting. A list drawn slightly wide stays true through ordinary operational change, which is what makes it dependable.
What we will not do is use this as cover. Breadth here does not license a purpose we have not described, a category of data we have not listed, or a transfer without a mechanism. If we start sending a new kind of personal data, or sending it for a new reason, that is a change to this page and to the notice period below — not something the width of a table quietly absorbs.
If you need to know precisely which providers are live for your workspace today, rather than which ones may be, ask us at [email protected] and we will tell you.
What is deliberately not in the tables
- Infrastructure we operate ourselves. Our databases, object storage, cache, secrets manager and container platform are not sub-processors, because there is no third party involved. The next section describes what we run and what really does sit in front of it.
- Recipients that are not processors — payment providers acting under their own regulatory obligations, professional advisers, public authorities, and an acquirer in a corporate transaction. Those are covered in the Privacy Policy.
- Sites you choose to visit by following a link out of the Service. Once you are on someone else's site, their notice applies.
Annex: Ever Gauzy
The tiers below follow the explanation above. Read the tier, not just the name — a provider in the second or third table is not processing your data unless the condition next to it is true.
Tier 1 — always engaged
These are in the path for every customer of Ever Gauzy Cloud. There is no setting that removes them. This is the Article 28 sub-processor list proper.
| Sub-processor | Purpose | Location | Transfer mechanism | Personal data |
|---|---|---|---|---|
| Cloudflare, Inc. | DNS, content delivery, TLS termination, web application firewall and the tunnels that carry traffic from the edge to our own infrastructure for gauzy.co, app.gauzy.co, api.gauzy.co and docs.gauzy.co. Every request to the Service passes through it. | United States, with edge termination worldwide | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and device characteristics, requested URLs and request headers, TLS and connection metadata, cookies in transit |
| ActiveCampaign, LLC (Postmark) | Delivery of transactional and notification email — workspace invitations, email verification, sign-in codes, password resets, invoice and estimate emails, timesheet and approval notifications, and replies to the contact form on gauzy.co. | United States | Standard Contractual Clauses (EU 2021/914) | recipient name and email address, message subject and body, which can contain invoice, timesheet and HR content, single-use sign-in and verification codes, delivery, bounce and open metadata |
| Chargebee Inc. | Subscription billing and hosted checkout for licence and subscription purchases started from gauzy.co. Card details are entered on Chargebee's own hosted page and never reach us. | United States | To be confirmed — we do not yet evidence a mechanism | billing name and email address, billing address and tax identification number, plan, invoice and payment history, IP address |
| GitHub, Inc. (a Microsoft Corporation company) | Source hosting, continuous integration and the container registry that serves the production images for the Service. It is how the Service is built and deployed, not where your data lives. | United States | Standard Contractual Clauses (EU 2021/914) | build, release and deployment metadata, developer and automation account identifiers, no workspace content and no captured media |
| DigitalOcean, LLC | Object storage and content delivery for the public desktop, agent and server installers offered on the download page of gauzy.co. It serves the installer files themselves and nothing else. | United States | Standard Contractual Clauses (EU 2021/914) | IP address of the person downloading, user agent and requested file |
| iubenda s.r.l. | Consent management on gauzy.co — presenting the banner and preference centre, recording your choice and making it available to the scripts that wait on it. | Italy, European Union | None needed — established in the EEA | IP address, user agent, consent preferences and the timestamp of the choice |
| Google Ireland Limited (reCAPTCHA) | Bot protection on the public forms of gauzy.co — contact and newsletter — with server-side verification of the resulting token. Treated as strictly necessary for the reasons given in our Cookie Policy. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and device characteristics, mouse, touch and timing signals from the form page |
| Cloudflare, Inc. (R2 object storage) | Holds the encrypted off-site copy of our backups - Postgres WAL and dumps, Velero, etcd, Proxmox configuration and MinIO mirrors - as the third tier of the backup chain (node8 NVMe, then Ceph RGW, then Cloudflare R2). Encrypted by us before it leaves our network. | United States | Standard Contractual Clauses (EU 2021/914) | client-side encrypted backup archives only - no plaintext is ever readable by the provider, the archives themselves derive from every category of data the products hold |
| Google Ireland Limited (Google Workspace) | Hosts the corporate mailboxes that receive every support, privacy and rights request our own documents tell data subjects to write to, plus the recruitment mailbox that holds candidate CVs. | Ireland (contracting) / United States and global (Google LLC) | Standard Contractual Clauses (EU 2021/914) | all inbound and outbound company email, support, DSAR and privacy correspondence with data subjects, candidate CVs and application correspondence (ever-tech careers), customer and supplier correspondence and attachments |
| Cloudflare, Inc. (Turnstile) | Checks that the person completing registration, onboarding or an anonymous flow is not a bot; on ever-works the API refuses the anonymous flow when no CAPTCHA provider is configured, which is why it is unconditional there. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and device signals, mouse, touch and timing interaction signals, Turnstile challenge cookie |
| Clerk, Inc. | Holds the account identity for the hosted cloc platform - name, email address, avatar, password or federated identity, sessions and multi-factor settings - so that our own database does not, and brokers the short-lived source-control credential used when the Service acts in a user's name. | United States | Standard Contractual Clauses (EU 2021/914) | name, email address and avatar, password hash or federated identity, session, device and sign-in records, organisation membership and role, social-connection claims where a user signs in that way, the short-lived source-control credential brokered for a single request and not stored |
| Tavily | The default provider for public web search and page extraction, used by agents researching a topic and by the automated research that runs when an account is created, where the queries are built from the new account holder's name and email domain. | United States | To be confirmed — we do not yet evidence a mechanism | search queries, including a person's name and their employer's email domain, the addresses of pages retrieved and the extracted page content, our API key and request metadata |
| ui-avatars.com | Generates placeholder avatars where a person has no avatar of their own. The person's name or GitHub username is placed in the image URL, so it is disclosed to this provider every time the image is rendered in a customer's browser. | UNKNOWN - not published by the provider | To be confirmed — we do not yet evidence a mechanism | the developer's name or GitHub username, in the request URL, the viewing user's IP address and user agent |
| Prospect One sp. z o.o. (jsDelivr) | Serves the Lottie animation runtime hard-coded into the ever-works login and register pages, so every person who opens the login page hands their IP to it before authenticating. | Poland (operator); delivery worldwide | Standard Contractual Clauses (EU 2021/914) | IP address, user agent, referring page URL |
| UNKNOWN - community-run npm CDN; no obtainable DPA counterparty identified | Second permitted origin for the Lottie animation runtime on the ever-works login and register pages. | United States (unverified) | To be confirmed — we do not yet evidence a mechanism | IP address, user agent, referring page URL |
| Resend, Inc. | Sends transactional mail for the products and domains configured against it, relaying onward through Amazon SES. | United States | Standard Contractual Clauses (EU 2021/914) | recipient name and email address, message subject and body, delivery and bounce metadata |
| Langfuse GmbH | Stores the full prompts and completions of AI features together with model, latency and cost metadata, so that agent behaviour can be traced and scored. | Germany | None needed — established in the EEA | full prompt and completion text, which can contain user-authored content and personal data, user and session identifiers, model, latency, token and cost metadata, developer scoring outputs |
| Shopify International Limited | Runs the storefront and order pipeline for the shop product, holding customer, order and payment-status records. | Ireland (contracting) / Canada and United States (Shopify group) | Standard Contractual Clauses (EU 2021/914) | customer name, email address and shipping address, order and payment status, browsing and cart events on the storefront, cookies set by the storefront |
Tier 2 — engaged only when a feature, integration or consent brings them in
None of these is engaged by default. Each one arrives because someone switched something on: an administrator enabled a feature, connected an integration, or configured a provider; or a visitor consented to a cookie category.
Two of these deserve to be called out rather than left in a table.
- Integrations you connect are two-way. Where your organisation connects Hubstaff, Upwork, Jira, GitHub or a similar platform, data moves in both directions and the other platform's own terms and privacy notice apply to its half. Connecting it is the act that authorises the exchange.
- AI providers are often yours, not ours. Several AI features work on a bring-your-own-key basis. Where your organisation supplies its own API key, your organisation is the one contracting with that provider, and its terms and privacy notice govern what happens to the content sent there. We do not become that provider's customer on your behalf, and we cannot make commitments about it.
| Sub-processor | Purpose | Location | Transfer mechanism | Personal data |
|---|---|---|---|---|
| Functional Software, Inc. d/b/a Sentry | Error, crash and performance reporting from the API, the web application, the desktop and agent applications and the gauzy.co website, where error reporting is enabled for the deployment. | United States | Standard Contractual Clauses (EU 2021/914) | IP address and device or operating-system details, user identifier and email address attached to an error event, URLs, route parameters and stack traces, which can contain fragments of the failing request, a masked replay of the website session in which an error occurred |
| PostHog, Inc. | Product analytics and, where it is switched on, session recording. Enabled per deployment and, on the website, gated on your consent to the analytics category. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, which the server-side integration uses to identify a visitor, user and workspace identifiers, page, screen and feature usage events, recordings of in-application sessions where session recording is enabled |
| Google Ireland Limited (Google Analytics 4 and Google Tag Manager) | Website traffic measurement on gauzy.co. Loads only after you consent to the analytics category. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, analytics client identifier, pages viewed, referrer, device and browser details |
| Liidio Oy (Leadfeeder), a Dealfront Group GmbH company | Business-audience identification on gauzy.co — resolving a visitor's IP address to the organisation it belongs to. Loads only after you consent to the marketing category. | Germany, European Union | None needed — established in the EEA | IP address, inferred employer or organisation, pages viewed and referrer |
| Chatwoot Inc. | The live support chat widget, which loads on gauzy.co and also inside the signed-in application when support chat is enabled. | United States | Standard Contractual Clauses (EU 2021/914) | name and email address you give the widget, the content of the chat, IP address and session identifiers, the page or screen you were on when you opened it |
| The Rocket Science Group LLC d/b/a Mailchimp | Newsletter and mailing-list management for people who subscribe on gauzy.co. | United States | Standard Contractual Clauses (EU 2021/914) | email address and name, subscription status and campaign engagement, IP address at the time of subscription |
| Google Ireland Limited (Google Maps Platform) | Map display, address autocomplete and location selection inside the application, where your administrator enables location features. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, the address text a user types into autocomplete, selected coordinates and resolved addresses |
| Algolia SAS | Hosted search on the documentation site at docs.gauzy.co, where search credentials are configured. | France, European Union | To be confirmed — we do not yet evidence a mechanism | search queries, IP address and user agent |
| Hound Technology, Inc. (d/b/a Honeycomb.io) | Distributed tracing and operational metrics for the API, where tracing is enabled and pointed at this provider. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, request URLs and route parameters, user and workspace identifiers carried in trace attributes |
| SigNoz Inc. | Distributed tracing and operational metrics for the API, as an alternative destination to the above, where tracing is enabled and pointed at this provider. | United States | To be confirmed — we do not yet evidence a mechanism | IP address, request URLs and route parameters, user and workspace identifiers carried in trace attributes |
| Aspecto Ltd. | Distributed tracing for the API, as a further alternative destination, where tracing is enabled and pointed at this provider. | Israel, which holds a European Commission adequacy decision | Adequacy decision — Israel | IP address, request URLs, identifiers carried in trace attributes |
| Jitsu Labs, Inc. | Event streaming to a product-analytics pipeline, where the hosted Jitsu service is configured as the destination rather than a destination we run ourselves. | United States | Standard Contractual Clauses (EU 2021/914) | user and workspace identifiers, product events and the changes that produced them, IP address and browser details |
| Bricks Software AS (Unleash) | Feature-flag evaluation, where the hosted Unleash service is configured rather than an instance we run ourselves. | Norway, European Economic Area | None needed — established in the EEA | application and instance identifiers, flag evaluation context, which can include a user or workspace identifier |
| Google Ireland Limited (Sign in with Google) | Sign-in, where a user chooses to authenticate with a Google account instead of a password. | United States | Standard Contractual Clauses (EU 2021/914) | Google account identifier, email address, display name and profile picture |
| Microsoft Corporation (Microsoft Entra ID) | Sign-in, where a user or an administrator chooses to authenticate with a Microsoft work or personal account. Profile details are read from Microsoft Graph. | United States | Standard Contractual Clauses (EU 2021/914) | Microsoft account identifier, email address and display name |
| LinkedIn Ireland Unlimited Company | Sign-in, where a user chooses to authenticate with a LinkedIn account. | United States | Standard Contractual Clauses (EU 2021/914) | LinkedIn account identifier, email address, name and profile picture |
| Meta Platforms Ireland Limited (Facebook Login) | Sign-in, where a user chooses to authenticate with a Facebook account. | United States | Standard Contractual Clauses (EU 2021/914) | Facebook account identifier, email address, name and profile picture |
| X Corp. (Twitter) | Sign-in, where a user chooses to authenticate with an X account. | United States | To be confirmed — we do not yet evidence a mechanism | X account identifier and screen name, email address where the provider releases it |
| Okta, Inc. (Auth0) | Sign-in, where an organisation chooses to authenticate its people through a hosted Auth0 tenant. | United States | Standard Contractual Clauses (EU 2021/914) | subject identifier issued by the identity provider, email address and name |
| Fiverr International Ltd. | Account linking for freelancer profiles, where a user connects a Fiverr account. | Israel, which holds a European Commission adequacy decision | Adequacy decision — Israel | Fiverr account identifier, the profile fields the connection returns |
| Red Hat, Inc. (Keycloak) | Sign-in against a Keycloak realm, where an organisation configures one. Whoever operates that realm holds the data, and where the organisation operates it there is no third party at all. | Determined by whoever operates the realm | Not our transfer — you choose the provider | subject identifier issued by the realm, username and email address |
| Anthropic, PBC | Model provider for the in-application AI assistant, connected by you with your own account and API key. Your agreement with this provider governs what it does with the content you send it. | United States | Standard Contractual Clauses (EU 2021/914) | prompts and conversation content, any workspace content a user includes in a prompt |
| OpenAI, L.L.C. | Model provider for the in-application AI assistant, connected by you with your own account and API key. Also reachable indirectly where you supply an OpenAI key to our own AI service for image analysis. | United States | Standard Contractual Clauses (EU 2021/914) | prompts and conversation content, any workspace content a user includes in a prompt, screenshot-derived content where image analysis is routed to your OpenAI account |
| Google Ireland Limited (Gemini API) | Model provider for the in-application AI assistant, connected by you with your own account and API key. | United States | Standard Contractual Clauses (EU 2021/914) | prompts and conversation content |
| X.AI LLC | Model provider for the in-application AI assistant, connected by you with your own account and API key. | United States | To be confirmed — we do not yet evidence a mechanism | prompts and conversation content |
| OpenRouter, Inc. | Model routing for the in-application AI assistant, connected by you with your own account or through an authorisation flow you complete yourself. | United States | To be confirmed — we do not yet evidence a mechanism | prompts and conversation content, OpenRouter account identity where you connect one |
| Vercel Inc. (AI Gateway) | Gateway that forwards AI assistant requests to a downstream model provider, connected by you with your own account and API key. | United States | Standard Contractual Clauses (EU 2021/914) | prompts and conversation content |
| Netsoft Holdings, LLC (Hubstaff) | Integration you connect, importing organisations, projects, people, timesheets, activity levels and screenshots from your Hubstaff account into your workspace. | United States | Standard Contractual Clauses (EU 2021/914) | names and email addresses of the people in your Hubstaff account, time logs and activity levels, screenshots captured by Hubstaff, project and task assignments |
| Upwork Global Inc. | Integration you connect, importing contracts, freelancer profiles, time logs and income and expense reports from your Upwork account, and supporting job matching and proposal drafting. | United States | To be confirmed — we do not yet evidence a mechanism | freelancer name and profile details, contract, earnings and time-log data, screenshots captured by Upwork |
| Atlassian Pty Ltd (Jira, Trello) | Integration you connect, synchronising projects, issues and worklogs between Jira and your workspace. | United States | Standard Contractual Clauses (EU 2021/914) | Jira account identifiers, display names and email addresses, issue, comment and worklog content |
| GitHub, Inc. (a Microsoft Corporation company) | Integration you connect through a GitHub App, synchronising repositories, issues and labels with your workspace tasks. | United States | Standard Contractual Clauses (EU 2021/914) | GitHub account identifiers, usernames and email addresses, issue and repository content within the granted scope |
| Zapier, Inc. | Automation integration you connect, which reads and receives whatever records you wire into a Zap. | United States | Standard Contractual Clauses (EU 2021/914) | any workspace record you route through an automation, including tasks, time logs, contacts and invoices |
| Celonis SE (Make.com) | Automation integration you connect, which reads and receives whatever records you wire into a scenario. | Germany, European Union | None needed — established in the EEA | any workspace record you route through an automation |
| Activepieces Inc. | Automation integration you connect, which reads and receives whatever records you wire into a flow. | United States | Standard Contractual Clauses (EU 2021/914) | any workspace record you route through an automation |
| Sim Studio, Inc. (sim.ai) | AI workflow integration you connect, which receives the inputs you route into a workflow. | United States | To be confirmed — we do not yet evidence a mechanism | workflow inputs, which can contain workspace record content |
| WakaTime, LLC | Integration a developer connects, ingesting coding-activity heartbeats as time and activity records in your workspace. | United States | To be confirmed — we do not yet evidence a mechanism | developer identity, names of files and projects being edited, editor, language and operating-system metadata with timestamps |
| Vercel Inc. | Hosts the cloc platform; routes AI prompts to downstream model providers for gauzy through the AI Gateway; and remains the deployment target of surviving workflows and DNS delegations for several frontends that have since moved to our own cluster. | United States | Standard Contractual Clauses (EU 2021/914) | for cloc: full application traffic and runtime data (the platform actually runs there), IP address and user agent of visitors where a site is served from Vercel, page-view and Web Vitals events, for gauzy: prompt content and model responses routed through the AI Gateway, plus routing and usage metadata, deployment metadata |
| Hashnode Inc. | Serves the product blog at blog.<our-domain> under our own branding, so every reader's IP, user agent and cookies go to a US platform the reader has no way of identifying from the address bar. | United States (Delaware) | To be confirmed — we do not yet evidence a mechanism | reader IP address and user agent, blog analytics and referrer, newsletter subscriber email addresses where the subscribe widget is enabled, cookies set under our own subdomain |
| Uptime Robot Service Provider Ltd - UNVERIFIED. The commonly cited registration is Cyprus (Nicosia); confirm from the current Terms or Imprint before publishing any location claim. | Hosts the public status page at status.<our-domain>, so anyone who opens it hands their IP and user agent to the vendor. | Cyprus (unverified) | To be confirmed — we do not yet evidence a mechanism | IP address and user agent of every visitor to a status page, cookies set by the status page, monitored endpoint URLs and response metadata |
| UNKNOWN - operated by an individual developer; no identifiable legal entity, no privacy policy, no DPA counterparty | Supplies fallback avatar and logo placeholder images whose URLs are written into persisted user, organization and team records and then fetched directly by the visitor's browser. | United States (unverified) | To be confirmed — we do not yet evidence a mechanism | IP address, user agent, referring page URL |
| Twilio Inc. (SendGrid) | Sends and tracks marketing or transactional email for gauzy.co through dedicated sending, reply and link-tracking subdomains, and stands as an alternative sender for githands. | United States | Standard Contractual Clauses (EU 2021/914) | recipient email address and name, message content, open and click tracking events (links.gauzy.co), recipient IP and user agent via tracking pixels |
| Twilio Inc. (Programmable Messaging) | Sends SMS where a tenant configures Twilio as its SMS gateway using its own account SID and token. | United States | Standard Contractual Clauses (EU 2021/914) | recipient telephone number, message body, which can contain a capture link or workspace content, delivery and status metadata |
| self-hosted by us - no vendor. Cloud analogue: the Plane Cloud operator (entity name UNKNOWN/unverified; published by the makeplane team, US/India). | Syncs issues and projects with whatever Plane instance a customer configures - our own pm.gauzy.co, their own server, or Plane Cloud. | n/a (self-hosted on own EU hardware); United States / India for Plane Cloud | None needed — established in the EEA | issue, cycle and project records, assignee identity and team-member names, API tokens |
| Google Ireland Limited (Google Fonts) | Delivers typefaces to the visitor's browser at page load on the properties that hot-link them, disclosing the visitor's IP to Google before any consent choice. | Ireland (contracting entity); processing in Ireland (contracting) / United States (operating) | Standard Contractual Clauses (EU 2021/914) | IP address, user agent, referring page URL |
| Better Stack, s.r.o. | Receives shipped application logs where a log token is configured, including the ChatGPT connector service in ever-teams and the cloc platform's observability pipeline. | Czech Republic | None needed — established in the EEA | application log lines, which may embed user ids, request paths and IP addresses, uptime probe results |
| Mistral AI SAS | Generates completions where the Mistral plugin is enabled for a Work. | France | None needed — established in the EEA | prompt text, completions |
| Groq, Inc. | Serves completions where a user supplies a Groq key and selects it as the provider. | United States | To be confirmed — we do not yet evidence a mechanism | prompt content, model responses |
| Together Computer, Inc. (trading as Together AI) | Serves completions where a user selects Together as the provider and supplies a key, called from our own Next.js server route. | United States | To be confirmed — we do not yet evidence a mechanism | prompt content, including chat message text, model responses |
| Intuition Machines, Inc. (hCaptcha) | Scores signup and login attempts wherever the CAPTCHA provider is set to hCaptcha. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and browser/device fingerprint signals, mouse, touch and timing interaction signals, challenge solution and token |
| Stripe Payments Europe, Limited | Takes card payments and holds the resulting billing and invoice records for products that sell subscriptions. Acts as an independent controller for fraud prevention, anti-money-laundering and card-scheme compliance, on its own legal obligations rather than our instructions. | Ireland (EEA), with onward group processing in the United States | Standard Contractual Clauses (EU 2021/914) | billing identity and address, plan, invoice and payment history, IP address, card data - entered on Stripe's own hosted page and never reaching us |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Takes payments for a commerce deployment, where the merchant running that deployment contracts with PayPal directly. Acts as an independent controller for fraud prevention, anti-money-laundering and card-scheme compliance, on its own legal obligations rather than our instructions. | Luxembourg (EEA users) / United States (PayPal, Inc.) | None needed — established in the EEA | payer identity and email address, transaction amount and order reference, payment status and history |
| Slack Technologies, LLC (a Salesforce, Inc. company) | Posts notifications into, and reads events from, a Slack workspace the customer connects by installing our app into its own workspace. | United States (group); Ireland (EEA contracting for Slack's own customers) | Standard Contractual Clauses (EU 2021/914) | channel and workspace identifiers, message content we post or receive, Slack user identity, including member email addresses, OAuth tokens and webhook payloads, shared recordings, screenshots and their links (ever-rec) |
| Noti-Fire Apps Ltd. (Novu) | The in-application notification inbox and a delivery channel for notifications, where it is configured against Novu's hosted service rather than an instance you run. | Israel | Adequacy decision — Israel | a hashed subscriber identifier, computed server-side under NOVU_SECRET_KEY, notification content, email address where Novu is used as a delivery channel |
| Plausible Insights OÜ | Cookieless site analytics on a Work site, where the Work Owner enables it. | Estonia | None needed — established in the EEA | page views and referrer, coarse device and country, derived and not stored as an IP address |
| HubSpot, Inc. | Two-way contact synchronisation, engaged only when a customer connects its own HubSpot account. Data moves in both directions once connected. | United States (HubSpot, Inc.) / Ireland (HubSpot Ireland Limited, for HubSpot's own EEA customers) | Standard Contractual Clauses (EU 2021/914) | contact and company records the customer chooses to sync, names, email addresses, employers and job titles in those records, the OAuth credential for the connection |
| Lemon Squeezy, LLC | Takes payments from a Work site's own visitors as merchant of record where the Work Owner connects it, so the Work Owner contracts with it directly. Acts as an independent controller for fraud prevention, anti-money-laundering and card-scheme compliance, on its own legal obligations rather than our instructions. | United States (Delaware) | Not our transfer — you choose the provider | name and email address, billing address and tax location, payment identifiers and purchase history, card data entered on Lemon Squeezy's own hosted checkout and never reaching us |
| Polar Software Inc. | An alternative payment and subscription provider for a Work site's own visitors, connected and contracted by the Work Owner. Acts as an independent controller for fraud prevention, anti-money-laundering and card-scheme compliance, on its own legal obligations rather than our instructions. | United States (Delaware) | Not our transfer — you choose the provider | name and email address, billing and tax location, payment identifiers and subscription history, card data entered on Polar's own hosted checkout and never reaching us |
| SolidGate | A further card payment option for a Work site's own visitors, where the Work Owner enables it and contracts with the payment institution directly. Acts as an independent controller for fraud prevention, anti-money-laundering and card-scheme compliance, on its own legal obligations rather than our instructions. | Cyprus (EEA) | None needed — established in the EEA | cardholder name, email address, billing address, payment identifiers |
Tier 3 — self-hosted deployments only
Ever Gauzy can be run on your own infrastructure. If you do that, you choose these providers, you hold the credentials, and you contract with them directly.
We are not a processor for anything in a deployment you run. We do not receive that data, we cannot reach it, and we have no relationship with the providers you configure. They appear here only so that readers running their own copy know which external services the software can be configured to use.
| Sub-processor | Purpose | Location | Transfer mechanism | Personal data |
|---|---|---|---|---|
| Amazon Web Services, Inc. (S3) | One of the object-storage backends the open-source software can be pointed at for uploads, avatars, attachments and captured media in a deployment you run yourself. | The region you select in your own account | Not our transfer — you choose the provider | whatever your deployment stores, including screenshots, webcam stills, audio, video and uploaded documents |
| Wasabi Technologies, Inc. | An S3-compatible object-storage backend the open-source software can be pointed at in a deployment you run yourself. | The region you select in your own account | Not our transfer — you choose the provider | whatever your deployment stores, including captured media and uploaded documents |
| Cloudinary Ltd. | An image and media storage and delivery backend the open-source software can be pointed at in a deployment you run yourself. | The region you select in your own account | Not our transfer — you choose the provider | whatever your deployment stores, including screenshots, avatars and uploaded images |
| DigitalOcean, LLC (Spaces) | An S3-compatible object-storage backend the open-source software can be pointed at in a deployment you run yourself. Distinct from the installer delivery listed in the always-engaged table above. | The region you select in your own account | Not our transfer — you choose the provider | whatever your deployment stores, including captured media and uploaded documents |
| none in a self-hosted deployment - the reader (or we) runs the runtime. Ollama Inc. (US) publishes the software and would become a processor only if a hosted Ollama service were adopted. | Runs open-weight models inside the deployment itself, so prompts reach no third party at all. | n/a (self-hosted); United States for Ollama Inc. | Not our transfer — you choose the provider | chat and prompt text, which never leaves the deployment |
| Mixpanel, Inc. | Records in-app screens and named events - 'Order Delivered' from the courier application, 'Order Failed' from the merchant tablet and similar - against a device identifier, where the operator configures a Mixpanel token and publishes a build containing it. | United States | Not our transfer — you choose the provider | device identifier, screens viewed and in-app events, IP address, user identifier once the person has signed in, the Mixpanel project token, which is compiled into the distributed binary |
| Intercom, Inc. | Runs the in-application support conversation in the shopping, merchant and courier mobile applications through cordova-plugin-intercom / @ionic-native/intercom, where the operator supplies Intercom credentials. | United States (Intercom, Inc.) / Ireland (Intercom R&D Unlimited Company) | Not our transfer — you choose the provider | user identifier and email address, full support conversation content, device and application context, the operator's Intercom app id and API key |
Storage of monitoring media
Screenshots, webcam stills, audio and video captured by the desktop applications are stored through the file-provider configured for the deployment. For Ever Gauzy Cloud that is our own object storage, on our own infrastructure, which is why the commercial object-storage providers the software supports appear in tier 3 rather than tier 1. If that ever changes for the hosted Service, this list changes with it and the change is announced under the notification process above.
Hosting and infrastructure
The tables above are short for a reason, and the reason is worth stating plainly: we run our own infrastructure. The Service is not a tenancy in a public cloud account. It runs on physical servers we own, in facilities we control, inside the European Union, on a virtualisation and container platform we operate ourselves.
The database, the object storage that holds your files, the cache and queue layers, the secrets manager and the deployment system are all components we run. None of them is a third party, so none of them appears as a sub-processor — there is nobody else to disclose. What we do with them is described on our Security page.
Where processing actually happens
- Your data at rest, and the applications that process it, sit on our own hardware in the European Union. That is the primary location for accounts, content, files and the databases behind them.
- Requests reach us through a global content delivery and security network. Traffic is terminated at the edge location nearest to whoever is making the request, which can be anywhere in the world, before being carried to our infrastructure in Europe. That provider is in the always-engaged tier above, and the transfer mechanism for it is described in our Privacy Policy.
- Off-site backup copies are held with an external object storage provider, encrypted by us before they leave our network. That provider holds ciphertext and no key, and cannot read what it stores.
- Our source code, build pipeline and container images are hosted with a third-party provider. That is how the Service is built and deployed rather than where your data lives day to day, but it is a genuine third party and it is disclosed as one.
Where a product does something different
A small number of products use a third-party managed database, managed storage or hosted platform for a specific function instead of our own infrastructure. Where that is the case for Ever Gauzy, the provider appears in the always-engaged tier above and the product annex says which data goes there.
We are explicit about this because "self-hosted" is exactly the sort of claim that gets made once and then stops being true for one product in the range. If your data for a given feature sits with someone else, the table says so.
The regions you should design around
If you are completing a transfer mapping or a data protection impact assessment, the honest summary is: primary processing in the European Union on infrastructure we operate; edge termination worldwide; a small number of named providers established outside the European Economic Area, each with its own transfer mechanism. Every one of those providers is in the tables above, and the mechanism for each is in the international transfers section of the Privacy Policy.
If you need a copy of the safeguards for a named provider — the Standard Contractual Clauses and which modules apply — write to [email protected] and we will send them.
When this list changes
The notice period
We give at least 30 days' notice before a new or replacement sub-processor starts processing personal data for the hosted Service. The 30 days run from the date the notice is published or sent, whichever comes first, and they exist so that your objection right is a real one rather than a formality you learn about afterwards.
How you find out
- This page changes first. It carries the date it took effect and a dated record of what changed, so the page itself is the notice.
- By email, if you ask for it. Write to [email protected] and we will add your address to the notification list. We then email you before each change, at the same time the page is updated. We recommend a role address rather than an individual's — a notice sent to someone who has left your organisation has been sent and not received.
- In the product, for changes that affect a feature you are using, through a notice to workspace administrators.
What the notice tells you
The provider's legal name, what it will do, where it is established, the categories of personal data it will receive, the transfer mechanism if it is outside the European Economic Area, the date it takes effect, and whether it is a new provider or replaces one already on the list. If it replaces one, we say which.
Urgent replacements
Sometimes we have to move faster than 30 days — a provider suffers a security incident, terminates its service, loses the legal basis it relied on, or fails in a way that makes staying with it worse than leaving.
Where that happens we may engage the replacement sooner, and we will notify you as quickly as we can with the reason we could not wait. Your right to object is not affected: it simply runs from the notice instead of before the change. We do not use this route as a convenience, and a notice sent under it says plainly why the normal period was not followed.
Changes that do not need notice
Removing a provider does not need a notice period — it reduces the number of people handling your data. A provider changing its own name, or the group entity that contracts with us changing without a change in where or how the processing happens, is recorded here as an administrative update rather than announced as a new engagement. A provider moving its processing to a different country is not administrative, and gets the full notice.
The record
We keep the change history for this page so that you can reconstruct who was engaged during a given period. That matters if you are updating your own records of processing, refreshing an impact assessment, or answering a question about a period in the past. Ask [email protected] if you need the state of the list as it stood on a particular date.
Objecting to a sub-processor
Who can object
The customer — the organisation or person who contracts with us and acts as controller for the data in the workspace. If you are an individual whose data we hold, this is not your route: your rights are in the Privacy Policy, and if your data sits in an employer's workspace, your employer is the controller and the request goes to them.
How to object
Write to [email protected] within 30 days of the notice, and tell us:
- which provider you are objecting to;
- your reasons, on data protection grounds — a transfer you cannot justify, a conflict with a commitment you have given your own users, a regulator's position that applies to you, a documented security concern;
- which of your workspaces or environments the objection covers.
The reasons matter. This is a right to object on data protection grounds, not a veto over our choice of suppliers, and an objection with no stated ground gives us nothing to work with. Tell us what the problem is and we can usually solve it.
What we do next
We acknowledge your objection within five business days and respond substantively within 30 days. In between we look for a way to make the objection unnecessary:
- A different provider for your workspace, where one exists that does the job.
- A different configuration — narrowing what is sent, changing a region, or turning off the feature that needs the provider at all, if you can live without it.
- Excluding your workspace from the provider, where that is technically possible.
- Additional safeguards or contractual terms where your concern is about a specific risk rather than the provider as a whole.
Where it is technically possible to hold off, we will not start using the provider you have objected to for your data while the objection is open. Where it is not possible — because the provider is part of how the Service is delivered to everyone — we will tell you that plainly and quickly, rather than letting the clock run out on you.
If we cannot resolve it
If we cannot offer you a solution you can accept, you may terminate the affected subscription by written notice, without penalty, and we will refund the fees you have prepaid for the period after termination. That is the remedy: neither of us owes the other damages for a good-faith disagreement about a supplier.
Give us notice within 30 days of our final response, and we will keep your data available for export for the usual 30-day window described in the Terms of Service so that leaving does not cost you the data.
If you are on a free tier there is nothing to refund, and the same route is simply to stop using the Service and export your data.
Objecting to a provider already on the list
You do not have to wait for a change. You can raise a concern about a provider already listed at any time, using the same address and the same process, without the 30-day deadline. The realistic outcome differs by tier: a tier 2 provider can usually be switched off for you; a tier 1 provider generally cannot, because it is part of how the Service works — and if the answer is going to be no, you will get it as a straight no with the reason.
How to reach us about this list
- Questions about a provider, a request for the safeguards behind a transfer, or a request to join the change notification list — [email protected].
- An objection to a sub-processor — [email protected], as set out above.
- The Data Processing Addendum, a due diligence request, or a security questionnaire — [email protected].
We are Ever Technologies LTD, registered in Bulgaria under company number 204599535, with its registered office at Mladost 2, bl. 211, ent. A, Sofia 1799, Bulgaria. We are the controller for our own processing and your processor for the data in your workspace. By post, write to the registered office and mark the letter for the attention of the privacy team. We correspond in English.
You may also complain to a data protection supervisory authority. Ours is the Commission for Personal Data Protection (Комисия за защита на личните данни), the CPDP, at https://www.cpdp.bg/. You may instead complain to the authority for the country where you live or work.
This document is version 1.0.2 of the sub-processor list for gauzy.co, in force from 2026-08-02. It lists the providers engaged as at that date. Earlier versions, with the dates they applied, are at https://gauzy.co/subprocessors.