Trust Center

Sub-processors

The complete, named list of every sub-processor, with data categories, location, transfer safeguard, and our 30-day change-notice commitment.

Last updated
9 July 2026
Jurisdiction
Germany

How this list relates to our public disclosures

Our public Privacy Policy discloses sub-processors by category (cloud infrastructure, AI model inference, payments, observability, communications, advertising/measurement) and names our largest infrastructure providers. GDPR Art. 13(1)(e)/(f) and the EDPB Opinion 22/2024 permit category-level public disclosure, with the full named list provided to controllers on request or under NDA. This document is that full named list.

The two are consistent, not contradictory: the public policy gives data subjects the required category-level transparency; this document gives business and enterprise customers the named, per-vendor detail their procurement and privacy teams need for Art. 28 due diligence.


Transfer-safeguard legend

  • DPF — recipient self-certified under the EU-US Data Privacy Framework (Art. 45 adequacy). The General Court upheld the DPF in 2025; an appeal to the CJEU is pending, so we retain SCCs in DPF-vendor contracts as a fallback.
  • SCCs + TIA — EU 2021 Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (controller→processor) or Module 3 (processor→sub-processor), plus a documented Transfer Impact Assessment and supplementary measures (encryption / pseudonymisation) where the TIA indicates residual risk.
  • EU-hosted — data is processed and stored within the EU; no third-country transfer for in-region data.

Verify all DPF entries live before relying on them: https://www.dataprivacyframework.gov/list


1. AI model providers (first-party APIs)

Sub-processorService / purposeData categories processedProcessing locationTransfer safeguardNo-training / retention note
Google LLC (Gemini)Language generation + image generation/editingPrompts, product data, reviews, uploaded images, generated images, chat messagesUS (EU data-residency regions available for some workloads)DPF (Google LLC certified)No training on our API data; EU residency requested where available; default prompt retention configurable on enterprise tiers. ISO 27001 / 27701 / 42001, SOC 2.
OpenAI, L.L.C.Language generation + image generationPrompts, product data, reviews, uploaded images, generated images, chat messagesUSSCCs + TIA (not DPF-certified)No training on API / enterprise data by default; SOC 2 Type II; zero/limited-retention configuration used where available. TIA notes US litigation-preservation risk (output-log retention).
Anthropic, PBC (Claude)Language generationPrompts, product data, reviews, chat messages, text extracted from imagesUSSCCs + TIA (not DPF-certified)No training on commercial/API inputs or outputs by default; zero-data-retention agreement used where eligible; SOC 2.

2. Specialised image generation / processing

Sub-processorService / purposeData categories processedProcessing locationTransfer safeguardNo-training / retention note
Fal.ai (Features and Labels, Inc.)Specialised image generation / inference / processingUploaded images, generated images, image-generation promptsUS (assume; verify)SCCs + TIA (assume non-DPF)No customer data used for model training per our processing instructions; confirm Fal.ai's contractual no-training + retention terms.
Kie.aiSpecialised image generation / processingUploaded images, generated images, image-generation promptsUS (assume; verify)SCCs + TIA (assume non-DPF)No customer data used for model training per our processing instructions; confirm Kie.ai's contractual no-training + retention terms.

3. Infrastructure

Sub-processorService / purposeData categories processedProcessing locationTransfer safeguardNo-training / retention note
Vercel Inc.Application hosting / edge / serverless functionsRequest metadata, transient request/response payloadsUS (global edge)DPF (Vercel Inc. certified)Not an AI training context. SOC 2 Type II + ISO 27001:2022. Data at rest AES-256; TLS 1.2/1.3 in transit.
Supabase, Inc.Database, authentication, file storageAccount data, user content (uploads, prompts), generated images, usage metadataEU (Frankfurt region)EU-hosted (no third-country transfer for in-region data)Not an AI training context. SOC 2 Type II + ISO 27001; HIPAA environments available. AES-256 at rest incl. backups/PITR/Storage; RLS tenant isolation.
Stripe, Inc.Payment processingBilling contact, payment-method tokens, transaction metadata (no card PANs stored by Scalable)US (EU processing for some flows)DPF (Stripe certified)Not an AI training context. PCI DSS Level 1. Card data handled entirely by Stripe; Scalable receives only tokens.

4. Observability

Sub-processorService / purposeData categories processedProcessing locationTransfer safeguardNo-training / retention note
Functional Software, Inc. (Sentry)Error / crash monitoringError events, technical diagnostics, limited request context (PII minimised)USDPF (Sentry / Functional Software certified)Not an AI training context. SOC 2 + ISO 27001. Configured to minimise/scrub PII.
Mixpanel, Inc.Product analyticsPseudonymised usage events, device/event metadata (personal data minimised)EU residency (EU data-residency configuration)DPF (Mixpanel certified) + EU residencyNot an AI training context. SOC 2 Type II + ISO 27001 + ISO 27701. Personal data minimised; EU data residency enabled.

5. Communications / email

Sub-processorService / purposeData categories processedProcessing locationTransfer safeguardNo-training / retention note
Loops (Astrodon, Inc.)Transactional + marketing emailEmail address, name, account/lifecycle metadataUSDPF (self-declared — verify)Not an AI training context. Email delivery only; no customer account content.
Instantly (Instantly.ai)Outbound prospecting (prospect data only — NOT customer account data)Business prospect contact data (name, work email, company) for outbound salesUSSCCs + TIA (not DPF-certified)Not an AI training context. Scope strictly limited to prospecting; no Scalable customer account data flows to Instantly.
Google LLC (Google Workspace)Internal email / docs / collaborationInternal correspondence; incidental customer contact data in support threadsUSDPF (Google LLC certified)Not an AI training context. Internal tooling.
Slack (Salesforce, Inc.)Internal team communicationInternal correspondence; incidental customer references in support discussionUSDPF (Salesforce / Slack covered entity)Not an AI training context. Internal tooling.

6. Advertising / measurement

These sub-processors receive conversion events and the minimised identifiers needed for measurement. Meta and Google may receive hashed contact/account identifiers, click/browser identifiers, IP address, and User-Agent. Where available, IP address and User-Agent are resolved from a service-role-only browser snapshot usable for no more than one hour; expired or future-dated values are ignored and cleared by a scheduled cleanup, and the snapshot is not copied into Scalable’s conversion outbox.

Sub-processorService / purposeData categories processedProcessing locationTransfer safeguardNo-training / retention note
Meta Platforms, Inc.Conversion tracking / advertising measurementConversion events, hashed identifiers, click/browser identifiers, IP address, User-AgentUSDPF (Meta certified — EU-US + Swiss-US)Not an AI training context. Data minimised for conversion measurement; provider retention applies.
LinkedIn (Microsoft Corporation)Conversion tracking / advertising measurementHashed identifiers, consent-based conversion eventsUSDPF (LinkedIn / Microsoft certified)Not an AI training context. Data minimised for conversion measurement; provider retention applies.
Google LLC (Google Ads)Conversion tracking / advertising measurementConversion events, hashed identifiers, click/browser identifiers, IP address, User-AgentUSDPF (Google LLC certified)Not an AI training context. Data minimised for conversion measurement; provider retention applies.

7. Change-notification commitment

  • Advance notice: We give customers 30 days' advance notice before a new or replacing sub-processor begins processing personal data (shorter notice only where an urgent security or legal requirement makes it strictly necessary).
  • Notification channel: Updates to this list plus email or in-product notice to the designated customer contact. Customers may subscribe to sub-processor change notifications.
  • Objection right: A customer may object on reasonable data-protection grounds within the notice period. We will work in good faith to resolve the concern (alternative sub-processor or supplementary measures). If the concern cannot be resolved, the customer may terminate the affected services without penalty. Objections are limited to genuine data-protection grounds, not competitive or commercial preference. Silence does not constitute consent.

This satisfies the GDPR Art. 28(2)/(3)(d) general-authorisation model: a maintained list + meaningful advance notice + a reasonable objection path.


8. Processing-chain notes

  • All sub-processors are engaged under Art. 28-compliant agreements (DPA or SCC-incorporating terms) that flow down our data-protection obligations. Scalable remains fully liable to the controller for sub-processor performance (Art. 28(4)).
  • Advertising/measurement sub-processors (Section 6) receive the minimised identifiers and request metadata described there for conversion measurement.
  • Instantly (Section 5) processes prospect data only and is segregated from all customer account data.

Machete Marketing Germany GmbH (brand: Scalable). legal@scalable.so. Provided for customer due diligence; not legal advice. DPF certifications must be verified live before reliance.