Sub-processors
How to read this list
For every sub-processor we disclose its name, the service we use it for, the region where data is processed, the categories of data it receives, and a link to its own privacy policy. This page is the single source of truth, referenced by our Privacy Policy and, where applicable, our Data Processing Addendum. It reflects the services that are actually wired into the product, grouped by function.
Self-hosted components are not listed. Some processing runs on infrastructure we operate ourselves rather than a third party — for example, report PDFs are rendered by a self-hosted headless browser, not an external rendering service. Those are covered by the platform providers above (Vercel, Supabase) and are not separate sub-processors.
Infrastructure suppliers are not sub-processors. Delivering the Service also relies on infrastructure suppliers that retrieve public web content and process only system-generated, non-personal data — for example, public URLs and the market-research queries we generate to measure brand visibility. They do not receive customer personal data, and are therefore not sub-processors under Article 28 of the GDPR, so they are not listed individually here.
Platform, hosting & storage
Run the application, store your account and audit data, and route network traffic.
| Sub-processor | Service | Region | Data types | Privacy policy |
|---|---|---|---|---|
| Supabase | Postgres database, authentication, and file storage | EU (eu-west-1, Ireland) | account_email, session_tokens, oauth_identity, audit_data, usage_events, report_files | link → |
| Vercel | Application hosting and edge network | EU central (fra1, Frankfurt) | ip_address, user_agent, request_logs | link → |
| Inngest | Durable workflow runtime (audits, citation runs, email jobs) | US-east + EU | workflow_state, event_payloads, target_urls, prompts | link → |
| Cloudflare | DNS and network services for findrix.ai | Global | ip_address, connection_metadata | link → |
| Geoapify | Map tiles and geocoding for the region-selection UI | EU | approximate_location, business_region | link → |
AI model providers
Answer the generated queries we send to track brand mentions, power the deep-review and content features, and measure page performance.
| Sub-processor | Service | Region | Data types | Privacy policy |
|---|---|---|---|---|
| Anthropic | Claude API (citation probes, deep review, content) | US | prompt_text, response_text, site_content | link → |
| OpenAI | GPT API (citation probes, content) | US | prompt_text, response_text | link → |
| Gemini API (deep review, content) and PageSpeed Insights | US + EU | prompt_text, response_text, site_content, audited_url | link → | |
| Perplexity | Sonar API (citation probes) | US | prompt_text, response_text | link → |
| xAI | Grok API (citation probes) | US | prompt_text, response_text | link → |
| OpenRouter | Fallback LLM gateway for worker (non-probe) model calls | US / global | prompt_text, response_text | link → |
Email, support & scheduling
Send transactional and support email and, on our lead-generation funnel, schedule calls and notify our team.
| Sub-processor | Service | Region | Data types | Privacy policy |
|---|---|---|---|---|
| Resend | Transactional and support email | US-east | account_email, email_content | link → |
| Calendly | Call scheduling for the lead-generation funnel | US | name, email, meeting_time | link → |
| Telegram | Internal team notifications for the lead-generation funnel (carries prospect name / domain) | Global | lead_name, lead_domain, public_profile_link | link → |
Analytics & monitoring
Measure product usage, monitor errors and uptime, and render maps. Analytics tools are consent-gated as described in the Cookie Policy.
| Sub-processor | Service | Region | Data types | Privacy policy |
|---|---|---|---|---|
| Sentry | Error and performance monitoring (crash reports) | US (ingest.us.sentry.io; DPF + SCCs) | ip_address, user_agent, error_reports | link → |
| PostHog | Product analytics (consent-gated) | EU (eu.i.posthog.com) | anonymized_events | link → |
| Google Analytics 4 | Web analytics (consent-gated, Consent Mode v2) | US (Google LLC; DPF + SCCs) | usage_events, client_id, ip_address | link → |
| Google Tag Manager | Tag container for consent-gated marketing tags | US (Google LLC; DPF + SCCs) | usage_events, ip_address | link → |
| Better Stack | Uptime and cron liveness monitoring (no customer data) | US / EU | service_health_pings | link → |
Advertising & attribution partners
These receive data from the pixels on our marketing site so we can measure our own ad campaigns, build retargeting audiences, and credit the partner who referred you. Unlike the sub-processors above, they also use this data for their own purposes as independent controllers. Their pixels load only where and when permitted; see our Cookie Policy for how this works in your region and how to opt out.
| Sub-processor | Service | Region | Data types | Privacy policy |
|---|---|---|---|---|
| Meta | Meta Pixel (ads measurement & retargeting; consent-gated by region) | US (Meta Platforms; SCCs) | page_views, ad_click_ids, ip_address, user_agent | link → |
| Insight Tag (ads measurement & retargeting; consent-gated by region) | US (LinkedIn Corp; SCCs) | page_views, ad_click_ids, ip_address, user_agent | link → | |
| OpenAI (Ads) | OpenAI Ads pixel (conversion measurement; consent-gated by region) | US | page_views, conversion_events | link → |
| FirstPromoter | Affiliate attribution + partner payouts (referral tracking; 90-day attribution cookie) | EU | referral_id, ip_address, user_agent, email | link → |
Planned sub-processors
These are built into the product but not yet processing live customer data. We list them in advance for transparency; they begin processing only when the related feature is switched on.
| Sub-processor | Service | Region | Data types | Privacy policy |
|---|---|---|---|---|
| Stripe | Payments and billing (paid plans; activation pending) | Global (DPA available) | name, billing_email, payment_method | link → |
International transfers
Your account and audit data are stored primarily in the European Union (Supabase in Ireland; Vercel in Frankfurt). Several sub-processors — notably the AI model providers and some analytics tools — operate in the United States or globally. When personal data is transferred out of the EEA, UK, or Switzerland, we rely on an appropriate safeguard: the EU-US Data Privacy Framework where the recipient is certified, the European Commission's Standard Contractual Clauses, and the UK Addendum and Swiss adequacy references as applicable. Our Data Processing Addendum incorporates these safeguards for customers who need one.
Notification of changes
We commit to notify customers at least 30 days in advance of:
- Adding a new sub-processor that handles customer data;
- Changing the region where an existing sub-processor operates; or
- Materially expanding the categories of data a sub-processor receives.
Notification methods: email to the account billing contact, an in-app notice, and an update to this page. The change history of this list is available on request to dpo@findrix.ai.
Your right to object
Customers on plans that include a Data Processing Addendum may object, in writing, to a new sub-processor within the 30-day notice window on reasonable, documented data-protection grounds. We will work in good faith to address the objection; if it cannot be resolved because the sub-processor is essential to the Service, you may terminate the affected subscription and receive a pro-rata refund of prepaid, unused fees.
Contact
Sub-processor and data-protection questions: dpo@findrix.ai
