Dynalope SA uses the following sub-processors to deliver the Dynalope platform. Any change to this list is communicated to B2B customers at least 30 days before it takes effect, in accordance with GDPR Article 28 and our Data Processing Agreement.
| Name | Role | Data types processed | Region | Status |
|---|---|---|---|---|
| Vercel Inc. | Application hosting (Next.js apps + Astro marketing site) | Account metadata; Request logs | US (Frankfurt edge) | Active |
| Supabase, Inc. | Postgres database, auth, storage, edge runtime | All user content; Auth metadata | EU (self-hosted on Hisland VPS at MVP; Supabase Cloud EU planned post-pilot) | Active |
| Resend | Transactional email delivery | Recipient address; Message content for magic link, password reset, export download, deletion confirmation, DPA notice | EU (Ireland) | Active |
| Paddle.com Market Limited | Subscription billing (merchant of record) | Email; Billing address; Payment method (handled by Paddle directly; never reaches Dynalope) | UK + US (Paddle is the merchant of record) | Active |
| OpenAI, L.L.C. | Embeddings generation (text-embedding-3-small) and inline AI triage (Phase 2) | Individual item titles and descriptions (no bulk, no health data, no other-user content per ADR-024) | US (via Vercel AI Gateway; zero retention DPA per NFR24) | Active |
| Anthropic, PBC | Adaptive evening prompts + AI summarisation (Phase 2) | Per-user reflections, scoped to the active user only | US (via Vercel AI Gateway; zero retention DPA per NFR24) | Active |
| Sentry (Functional Software, Inc.) | Error monitoring with allowlisted field-stripping | Stack traces; Request URL; User ID (no body content, no health data) | US (project configured for EU-region storage where available) | Active |
| PostHog | Product analytics + RUM (PostHog Cloud EU — managed service) | Page paths; Feature usage events; RUM metrics (no body content, no health data) | EU (PostHog Cloud EU, Frankfurt). PostHog, Inc. is US-incorporated and self-certifies under the EU–US Data Privacy Framework, with SCCs as the contractual fallback. | Active |
| Cloudflare, Inc. | DNS + WAF in front of dynalope.com / db.dynalope.com | DNS query metadata; Request IPs (for WAF rules) | Global (DNS-only; no proxying of authenticated app traffic) | Active |
| Hostup AB | Virtual-private-server hosting for the self-hosted Supabase stack behind db.dynalope.com | Postgres database contents and Supabase Storage objects — all user content, including health data — reside on this host | EU/EEA — Sweden (Stockholm). Hostup AB, Swedish company registration 559290-1325; the host address is registered to Hostup AB and announced from AS214640. | Active |
| Backblaze, Inc. | Offsite storage of encrypted database backups | Client-side encrypted backup archives (restic, AES-256) of the full Postgres database — Backblaze stores ciphertext only and never receives the encryption key | EU (Backblaze B2 region eu-central-003, Amsterdam). Backblaze, Inc. is US-incorporated and self-certifies under the EU–US Data Privacy Framework. | Active |
| Groq LLC | Speech-to-text transcription of voice captures (GroqCloud, Whisper large-v3-turbo) | Raw voice-capture audio bytes only — the recording is fetched by our own server and posted to the transcription API with no account identifier and no other content | US — no EU data residency; audio is transferred outside the EEA. ⚠ As of the date of this list a data processing agreement and a zero-retention confirmation have NOT been obtained from Groq, and no Article 46 transfer safeguard is recorded for this sub-processor. | Active |
| Google Cloud Pub/Sub for Gmail capture notifications, plus user-authorised Gmail and Google Calendar integration | Google Cloud Pub/Sub (topic operated by Dynalope): the connected mailbox address and an opaque Gmail history cursor — no message content; Gmail API, against the connected mailbox on the user instruction: reads of messages within the capture scope the user selected, and outbound replies the user sends from Dynalope; Google Calendar API, against the connected calendar on the user instruction: title, start and end time and description of the calendar blocks Dynalope writes, plus a private Dynalope item reference | US / global (Google Cloud and Google APIs). ⚠ The contracting Google legal entity for this relationship is not yet confirmed and is deliberately left unstated rather than guessed. | Active | |
| Microsoft | User-authorised Outlook mail, Outlook Calendar and OneDrive/SharePoint integration via Microsoft Graph | Outlook mail, against the connected mailbox on the user instruction: reads of messages within the capture scope the user selected, category and archive changes written back to that mailbox, mailbox settings, and outbound replies the user sends from Dynalope; Outlook Calendar, against the connected calendar on the user instruction: title, start and end time and description of the calendar blocks Dynalope writes; OneDrive/SharePoint, against the connected drive on the user instruction: the contents of files the user chooses to store externally | US / global (Microsoft Graph / Microsoft 365). ⚠ The contracting Microsoft legal entity for this relationship is not yet confirmed and is deliberately left unstated rather than guessed. | Active |
| Hetzner Online GmbH | Withdrawn — listed in error on the 2026-05-11 list. Hetzner has never hosted Dynalope data: the VPS is provided by Hostup AB, and PostHog runs on PostHog Cloud EU rather than a self-hosted Hetzner instance. | None — no Dynalope data was ever processed by this vendor | Not applicable — entry withdrawn as a factual correction | Retired |
This list reflects all sub-processors as of .