How this list relates to our public disclosures
Our public Privacy Policy discloses sub-processors by category (cloud infrastructure, AI model inference, payments, observability, communications, advertising/measurement) and names our largest infrastructure providers. GDPR Art. 13(1)(e)/(f) and the EDPB Opinion 22/2024 permit category-level public disclosure, with the full named list provided to controllers on request or under NDA. This document is that full named list.
The two are consistent, not contradictory: the public policy gives data subjects the required category-level transparency; this document gives business and enterprise customers the named, per-vendor detail their procurement and privacy teams need for Art. 28 due diligence.
Transfer-safeguard legend
- DPF — recipient self-certified under the EU-US Data Privacy Framework (Art. 45 adequacy). The General Court upheld the DPF in 2025; an appeal to the CJEU is pending, so we retain SCCs in DPF-vendor contracts as a fallback.
- SCCs + TIA — EU 2021 Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (controller→processor) or Module 3 (processor→sub-processor), plus a documented Transfer Impact Assessment and supplementary measures (encryption / pseudonymisation) where the TIA indicates residual risk.
- EU-hosted — data is processed and stored within the EU; no third-country transfer for in-region data.
Verify all DPF entries live before relying on them: https://www.dataprivacyframework.gov/list
1. AI model providers (first-party APIs)
| Sub-processor | Service / purpose | Data categories processed | Processing location | Transfer safeguard | No-training / retention note |
|---|---|---|---|---|---|
| Google LLC (Gemini) | Language generation + image generation/editing | Prompts, product data, reviews, uploaded images, generated images, chat messages | US (EU data-residency regions available for some workloads) | DPF (Google LLC certified) | No training on our API data; EU residency requested where available; default prompt retention configurable on enterprise tiers. ISO 27001 / 27701 / 42001, SOC 2. |
| OpenAI, L.L.C. | Language generation + image generation | Prompts, product data, reviews, uploaded images, generated images, chat messages | US | SCCs + TIA (not DPF-certified) | No training on API / enterprise data by default; SOC 2 Type II; zero/limited-retention configuration used where available. TIA notes US litigation-preservation risk (output-log retention). |
| Anthropic, PBC (Claude) | Language generation | Prompts, product data, reviews, chat messages, text extracted from images | US | SCCs + TIA (not DPF-certified) | No training on commercial/API inputs or outputs by default; zero-data-retention agreement used where eligible; SOC 2. |
2. Specialised image generation / processing
| Sub-processor | Service / purpose | Data categories processed | Processing location | Transfer safeguard | No-training / retention note |
|---|---|---|---|---|---|
| Fal.ai (Features and Labels, Inc.) | Specialised image generation / inference / processing | Uploaded images, generated images, image-generation prompts | US (assume; verify) | SCCs + TIA (assume non-DPF) | No customer data used for model training per our processing instructions; confirm Fal.ai's contractual no-training + retention terms. |
| Kie.ai | Specialised image generation / processing | Uploaded images, generated images, image-generation prompts | US (assume; verify) | SCCs + TIA (assume non-DPF) | No customer data used for model training per our processing instructions; confirm Kie.ai's contractual no-training + retention terms. |
3. Infrastructure
| Sub-processor | Service / purpose | Data categories processed | Processing location | Transfer safeguard | No-training / retention note |
|---|---|---|---|---|---|
| Vercel Inc. | Application hosting / edge / serverless functions | Request metadata, transient request/response payloads | US (global edge) | DPF (Vercel Inc. certified) | Not an AI training context. SOC 2 Type II + ISO 27001:2022. Data at rest AES-256; TLS 1.2/1.3 in transit. |
| Supabase, Inc. | Database, authentication, file storage | Account data, user content (uploads, prompts), generated images, usage metadata | EU (Frankfurt region) | EU-hosted (no third-country transfer for in-region data) | Not an AI training context. SOC 2 Type II + ISO 27001; HIPAA environments available. AES-256 at rest incl. backups/PITR/Storage; RLS tenant isolation. |
| Stripe, Inc. | Payment processing | Billing contact, payment-method tokens, transaction metadata (no card PANs stored by Scalable) | US (EU processing for some flows) | DPF (Stripe certified) | Not an AI training context. PCI DSS Level 1. Card data handled entirely by Stripe; Scalable receives only tokens. |
4. Observability
| Sub-processor | Service / purpose | Data categories processed | Processing location | Transfer safeguard | No-training / retention note |
|---|---|---|---|---|---|
| Functional Software, Inc. (Sentry) | Error / crash monitoring | Error events, technical diagnostics, limited request context (PII minimised) | US | DPF (Sentry / Functional Software certified) | Not an AI training context. SOC 2 + ISO 27001. Configured to minimise/scrub PII. |
| Mixpanel, Inc. | Product analytics | Pseudonymised usage events, device/event metadata (personal data minimised) | EU residency (EU data-residency configuration) | DPF (Mixpanel certified) + EU residency | Not an AI training context. SOC 2 Type II + ISO 27001 + ISO 27701. Personal data minimised; EU data residency enabled. |
5. Communications / email
| Sub-processor | Service / purpose | Data categories processed | Processing location | Transfer safeguard | No-training / retention note |
|---|---|---|---|---|---|
| Loops (Astrodon, Inc.) | Transactional + marketing email | Email address, name, account/lifecycle metadata | US | DPF (self-declared — verify) | Not an AI training context. Email delivery only; no customer account content. |
| Instantly (Instantly.ai) | Outbound prospecting (prospect data only — NOT customer account data) | Business prospect contact data (name, work email, company) for outbound sales | US | SCCs + TIA (not DPF-certified) | Not an AI training context. Scope strictly limited to prospecting; no Scalable customer account data flows to Instantly. |
| Google LLC (Google Workspace) | Internal email / docs / collaboration | Internal correspondence; incidental customer contact data in support threads | US | DPF (Google LLC certified) | Not an AI training context. Internal tooling. |
| Slack (Salesforce, Inc.) | Internal team communication | Internal correspondence; incidental customer references in support discussion | US | DPF (Salesforce / Slack covered entity) | Not an AI training context. Internal tooling. |
6. Advertising / measurement
These sub-processors receive conversion events and the minimised identifiers needed for measurement. Meta and Google may receive hashed contact/account identifiers, click/browser identifiers, IP address, and User-Agent. Where available, IP address and User-Agent are resolved from a service-role-only browser snapshot usable for no more than one hour; expired or future-dated values are ignored and cleared by a scheduled cleanup, and the snapshot is not copied into Scalable’s conversion outbox.
| Sub-processor | Service / purpose | Data categories processed | Processing location | Transfer safeguard | No-training / retention note |
|---|---|---|---|---|---|
| Meta Platforms, Inc. | Conversion tracking / advertising measurement | Conversion events, hashed identifiers, click/browser identifiers, IP address, User-Agent | US | DPF (Meta certified — EU-US + Swiss-US) | Not an AI training context. Data minimised for conversion measurement; provider retention applies. |
| LinkedIn (Microsoft Corporation) | Conversion tracking / advertising measurement | Hashed identifiers, consent-based conversion events | US | DPF (LinkedIn / Microsoft certified) | Not an AI training context. Data minimised for conversion measurement; provider retention applies. |
| Google LLC (Google Ads) | Conversion tracking / advertising measurement | Conversion events, hashed identifiers, click/browser identifiers, IP address, User-Agent | US | DPF (Google LLC certified) | Not an AI training context. Data minimised for conversion measurement; provider retention applies. |
7. Change-notification commitment
- Advance notice: We give customers 30 days' advance notice before a new or replacing sub-processor begins processing personal data (shorter notice only where an urgent security or legal requirement makes it strictly necessary).
- Notification channel: Updates to this list plus email or in-product notice to the designated customer contact. Customers may subscribe to sub-processor change notifications.
- Objection right: A customer may object on reasonable data-protection grounds within the notice period. We will work in good faith to resolve the concern (alternative sub-processor or supplementary measures). If the concern cannot be resolved, the customer may terminate the affected services without penalty. Objections are limited to genuine data-protection grounds, not competitive or commercial preference. Silence does not constitute consent.
This satisfies the GDPR Art. 28(2)/(3)(d) general-authorisation model: a maintained list + meaningful advance notice + a reasonable objection path.
8. Processing-chain notes
- All sub-processors are engaged under Art. 28-compliant agreements (DPA or SCC-incorporating terms) that flow down our data-protection obligations. Scalable remains fully liable to the controller for sub-processor performance (Art. 28(4)).
- Advertising/measurement sub-processors (Section 6) receive the minimised identifiers and request metadata described there for conversion measurement.
- Instantly (Section 5) processes prospect data only and is segregated from all customer account data.
Machete Marketing Germany GmbH (brand: Scalable). legal@scalable.so. Provided for customer due diligence; not legal advice. DPF certifications must be verified live before reliance.