Skip to content
← Back to legal

Subprocessors

GDPR Art. 30 - Subprocessor list

We share specific data with vetted third-party subprocessors to deliver the Glowniq service. Each subprocessor is bound by a Data Processing Agreement (DPA) and operates under documented safeguards.

Last updated: 15 June 2026

Infrastructure

SubprocessorDataLocationSafeguard
Hetzner (fenix-ai)Backend API, PostgreSQL, Redis, MinIOEU (Germany/Finland)EU residency, self-hosted, encrypted at rest
CloudflareDNS, CDN, DDoS protectionGlobal anycast (EU edges)SOC 2 Type II, GDPR DPA

AI vision

SubprocessorDataLocationSafeguard
OpenAIFace image (temporary, not retained)United StatesAPI mode (no training), DPA, SCCs, TIA
AnthropicFace image (temporary, not retained)United StatesAPI mode (no training default), DPA, SCCs, TIA
GroqFace image (temporary, not retained)United StatesDPA in progress, SCCs planned
OpenRouterFace image + prompt (aggregator)United StatesAggregator - model-level DPA varies; trust whitelist only
EachLabsDisabled in productionFace imageUnited StatesEachLabs DPA not yet executed

Payments

SubprocessorDataLocationSafeguard
StripeCard metadata, billing recordsUnited States (EU subsidiary)PCI-DSS Level 1, DPA, SCCs
RevenueCatIn-app purchase receipts, App Store/Play billingUnited StatesPCI-DSS, App Store DPA, RevenueCat DPA

Email & push

SubprocessorDataLocationSafeguard
SMTP (self-hosted)Transactional email (SMTP)EU (fenix-ai)Self-hosted, no third-party delivery
Expo (Push)Push notification tokensUnited States (APNs/FCM relay)Apple APNs DPA, Google FCM DPA

Analytics

SubprocessorDataLocationSafeguard
CookieYesCookie consent preferencesEUGDPR-compliant consent management

Cookie policy

We use CookieYes to manage consent for non-essential cookies. Marketing and analytics cookies are off by default until you opt in.