This is the live list required by clause 4 of the Data Processing Agreement. Before we add or replace anyone here, every customer gets 30 days' notice by email and a right to object.
| Who | What they do for us | Where | Transfer basis |
|---|---|---|---|
| Hetzner Online GmbH | Servers, database, backups. Everything we store lives here. | Germany and Finland | EU — no transfer |
| Anthropic PBC | Writes the reply. Receives the incoming message, the recent conversation, and the knowledge and voice examples you gave us. | United States | Standard Contractual Clauses |
| Stripe Payments Europe, Ltd. | Takes the card payment and issues invoices. Your customers' messages never reach Stripe — only your own billing details. | Ireland, with onward processing by Stripe, Inc. (US) | Standard Contractual Clauses for the US leg |
| Cloudflare, Inc. | Authoritative DNS and TLS certificate issuance for our domains. No message content passes through Cloudflare — it does not proxy our traffic. | United States / global | Standard Contractual Clauses |
Meta is not on this list, deliberately — and it is the biggest thing outside the EU in the whole arrangement, so it is worth being clear why.
Instagram, Facebook and WhatsApp are your platforms under your agreement with Meta. Your customers' messages are on Meta's infrastructure before we ever see them, and they would be there whether or not you used us. We send and receive on your behalf through Meta's official APIs, with the access you granted and can revoke. Meta is not our sub-processor and we do not present it as one.
What we can tell you is which of our choices leave Europe. That is the table above, and the answer is one: Anthropic.
We are adding a provider to send password resets and handover notifications. It will appear here, with 30 days' notice, before it processes anything.
Last updated 13 September 2026.