Subprocessors (Annex 2 to the DPA)

Final version. An external legal review is still pending.

This page names two groups that are legally different: processors acting exclusively on our instructions, and recipients that decide on their own processing. The list of processors is part of the Data Processing Agreement (DPA) and is versioned.

Group 1 — processors under Art. 28 GDPR

These providers process personal data exclusively on our instructions. We announce intended changes to this group at least 30 days in advance (§ 21 of the terms).

SubprocessorPurposeLocationTransfer basisActive?
Hetzner Online GmbHHosting and object storageDE (Falkenstein/Nuremberg)EU — DPA Art. 28yes
ResendEmail (transactional)EU sending path; core processing USA (Plus Five Five, Inc.)EU sending path, core processing in the USA; EU-US Data Privacy Framework and standard contractual clauses (SCC)yes
SentryError tracking (Visz-internal errors only)EU FrankfurtEU — DPAyes
Grafana CloudMetrics and logsEU regionStandard contractual clauses (US parent); data processing agreement still to be obtainedyes
Better StackStatus page and SLA probeEU regionEU-US Data Privacy Framework and standard contractual clauses (US parent); data processing agreement still to be obtainedyes
Zoho MailSupport inbox info@visz.aiEU data centre (Amsterdam/Dublin), remote access from IndiaStandard contractual clauses (SCC); data processing agreement still to be obtainedyes
CloudflareCDN (visz.ai marketing site only)globalDPF adequacy and SCCyes
GitHub ActionsCI/CDUSSCC — NEVER production/customer datayes
MaxMind GeoLite2Geo lookuplocal on own serverNOT a subprocessor (no external call)documented
Google Cloud EMEA LimitedModel calls for the AI analysis (task routing, session reading)Contracting entity Ireland; no commitment on the processing locationStandard Contractual Clauses and transfer impact assessment for the onward transfer to Google LLC (USA); data processing agreement still to be obtainednot yet
Mistral AI SASModel calls for the AI analysis (wording, findings, condensation)France; inference is to run via the EU endpoint in data centres in the EU and EFTA countries. That commitment on the location is agreed together with the data processing agreement; without it the provider makes no commitment on the processing location for the general endpoint.EU/EEA, data processing agreement under Art. 28 GDPR; Switzerland on the basis of the adequacy decision; data processing agreement still to be obtainednot yet
Anthropic Ireland, LimitedModel calls for the AI analysis — fallback for task routing, not in operationContracting entity Ireland; processing in the USAStandard Contractual Clauses and transfer impact assessment for the onward transfer to Anthropic, PBC (USA); data processing agreement still to be obtainedno (fallback, not in operation)

Group 2 — recipients that are independent controllers

These companies are not processors. They decide on the purposes and means of their processing themselves; a data processing agreement is not the legally correct framework for that. The 30-day prior notice does not apply to this group. We list them here for transparency.

RecipientRoleDataLocation
Stripe Payments Europe, Ltd.payment processing for paid plans on direct purchase; acts as merchant of record (privacy notice section 9)payment and invoicing data, account email, contract detailsIreland; group USA
Shopify International Ltd.billing where installed via the Shopify App Store; acts as merchant of record; also the data source of the shop integrationbilling data; the customer's shop dataIreland; group Canada/USA
Google Ireland Ltd. / Google LLCsign-in with Google (OAuth)email address, display name, verification status of the address, permanent Google user ID, sign-in tokens (access, identity) and scopeIreland/USA
Apple Distribution International Ltd. / Apple Inc.sign-in with Apple (Sign in with Apple)email address or anonymous forwarding address, display name (first sign-in only), permanent Apple user ID (“sub”), sign-in tokens (access, identity) and scopeIreland/USA

For transfers to third countries these recipients rely on the EU-US Data Privacy Framework and/or standard contractual clauses.

Note: MaxMind GeoLite2 runs as a local database without any external call and is therefore not a subprocessor within the meaning of Art. 28. rrweb runs in the visitor's browser and is also not a subprocessor (code in the snippet, not a service provider).

Optional / conditional subprocessors

These are only listed when actually enabled:

  • Cloudflare R2 — optional object-storage backup (EU; DPA/SCC).
  • Vercel — optional marketing deploy (US; SCC; not a processor if marketing site only).
  • Slack — only if the customer connects an integration (US; the customer picks the channel and is responsible).
  • Postmark — optional mail backup (EU; Resend is primary).

Update process

We announce every intended change to group 1 — adding a new sub-processor as well as replacing an existing one — at least 30 days before it takes effect: in text form to the account email on file and by updating this page (30-day prior notice). Within that period you may object for an important data protection reason; if the objection cannot be resolved, you may terminate as of the effective date (§ 21 of the terms, DPA § 6). This prior notice does not apply to group 2. This list is versioned; earlier versions remain traceable.

Subprocessors · visz.ai