Last updated: 19 September 2026.
Sub-processors
This list describes the service providers used for Steinkauz Cloud. Where they process customer content on our behalf, we engage them as sub-processors under Article 28 GDPR. We announce changes to these sub-processors in accordance with the DPA. Payment and sign-in services may also act as independent controllers for their own processing; listing them alone does not establish a sub-processing relationship.
Model providers and gateways connected by you (BYOK / your own gateway) are not listed. They are your processors.
We operate c15t (consent) ourselves on our infrastructure; it is not an external sub-processor.
We operate Better Auth ourselves; authentication data is held in our database (Neon).
Infrastructure and operations
| Entity | Purpose | Location / region | Third-country processing |
|---|---|---|---|
| Databricks, Inc. (Neon Postgres; under the current Neon terms) | Main database (accounts, organisations, encrypted content, billing references) | AWS Europe Central 1, Frankfurt, Germany (eu-central-1) | Databricks DPA, section 8 and Annex B: SCCs for covered third-country transfers; incorporated through the online terms |
| Hetzner Online GmbH | Object storage for chat attachments (S3-compatible) | Falkenstein, Germany (fsn1; network zone eu-central) | DPA section 3: processing in the EU/EEA; relocation to a third country only with prior consent and the necessary transfer safeguards. |
| Vercel Inc. | Application hosting, Functions, Cron, optional web analytics | Production region for Functions: Frankfurt, Germany (fra1). This does not promise exclusively European processing for all Vercel services. | Standard contractual clauses under the DPA, Annex 3; incorporated through Terms of Service section 10.1 |
| Redis EMEA Ltd., London, United Kingdom (Redis Cloud; managed through the Vercel interface) | Redis service for application operations | Hosting region: Frankfurt, Germany (fra1) | Redis DPA, section 7 and Annex 1: applicable adequacy decisions or SCCs (Module 2 or 3 depending on the role). International processing is possible; the hosting region is not a comprehensive EU-only commitment. |
Billing, messaging and sign-in
| Entity | Purpose | Location / region | Third-country processing |
|---|---|---|---|
| Stripe Payments Europe, Limited / Stripe Technology Europe, Limited (depending on the service under the agreement for Germany); Stripe, LLC (USA) | Payment processing, tax calculation, customer portal, invoice data; roles under the Stripe DPA | EU / USA; further international processing is possible under the DPA | Data Transfer Addendum: primarily DPF where applicable, otherwise SCCs; DPA and transfer addendum are incorporated through the online agreement |
| Plus Five Five, Inc. (Resend) | Transactional emails (confirmation, invitation, payment, withdrawal consent) | Primary processing in the USA under the DPA, section 6.1; configured sending region: Ireland (eu-west-1) | The DPA incorporated through the online terms specifies DPF and SCCs; an EU sending region does not promise exclusively European processing. |
| Google Ireland Limited (only when using “Sign in with Google”) | Optional sign-in service; Google processes Google account data under its own responsibility, and we process the received sign-in data for our user account | International processing under the Google Privacy Policy | Google specifies DPF and SCCs in its transfer information. Sign-in is not classified as sub-processing of our customer content. |
Measurement and product analytics
| Entity | Purpose | Location / region | Third-country processing |
|---|---|---|---|
| PostHog, Inc. | Product analytics, session replay (where active), LLM telemetry without prompt/response bodies | EU cloud (eu.posthog.com) | The DPA, section 10 also provides for processing outside the EU and specifies DPF and SCCs. |
| Vercel Analytics / Speed Insights | Website performance and visitor statistics | As part of Vercel | Only with consent to the measurement category |
Client-side and browser-related measurement takes place only with consent. Independently of this, server-side events from the Platform API and billing may be processed for operations, security and error analysis. These may include account, organisation, API key or transaction identifiers and model, usage, cost, runtime and error metadata; they are not necessarily anonymous. Prompt and response bodies are excluded from LLM telemetry. The Privacy Policy explains purposes and legal bases.
Notes
- Where processing on behalf of another party takes place, it is based on an agreement under Article 28 GDPR; the DPA applies to processing customer content.
- Categories: depending on the provider, master data, usage and billing data and/or content entered by the customer.
- Last updated: 19 September 2026. We notify existing customers of intended changes to sub-processors in advance by email to the organisation contact on file, in accordance with the DPA.
- Further contractual documents: Hetzner DPA, current Neon terms. Public provider documents do not replace evidence of the agreement applicable to our account.
- Redis: the entity for our registered location in Germany follows from the Cloud Agreement, section 10.11(c); section 5.3 incorporates the DPA. Further information: Privacy Policy and Sub-processors.