No third-country transfer takes place, neither from our systems nor from those of our subprocessors. The Data Privacy Framework column shows whether a US-based subprocessor is listed on the EU-US Data Privacy Framework; for EU-based entities it doesn’t apply (“entfällt”).
| Kategorie | Unternehmen | Adresse | Art der Dienstleistung | Verarbeitungsstandort | Data Privacy Framework |
|---|---|---|---|---|---|
| Hosting | Amazon Web Services EMEA Sàrl | Avenue John F. Kennedy 38, 1855 Luxemburg, Luxemburg | Anwendungshosting, Datenbankhosting, KI-Modelle | EU (Frankfurt, Paris) | Ja |
| Hetzner Online GmbH | Industriestr. 25, 91710 Gunzenhausen, Deutschland | Anwendungshosting | EU (Falkenstein, Nürnberg) | entfällt | |
| DigitalOcean LLC | 101 Avenue of the Americas, 10th Floor, New York, NY 10013, USA | Anwendungshosting (Caching, asynchrone Auftragsplanung) | EU (Frankfurt) | Ja | |
| Vercel, Inc. | 650 California St, San Francisco, CA 94108, USA | Anwendungshosting | EU, weltweit (CDN)1 | Ja | |
| Modal Labs, Inc. | 584 Broadway, Floor 10/1001, New York, NY 10012, USA | Anwendungshosting (nur bei Nutzung der Unitools-Funktion) | EU | Nein | |
| KI | Microsoft Deutschland GmbH | Walter-Gropius-Straße 5, 80807 München, Deutschland | Anwendungshosting, KI-Modelle | EU | entfällt |
| OpenAI Ireland Ltd | 70 Sir John Rogerson’s Quay, Dublin 2, Irland | KI-Modelle | EU | Nein, aber Zero-Data-Retention-Enterprise-Vereinbarung | |
| Monitoring | Functional Software, Inc. (Sentry) | 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA | Anwendungsüberwachung | EU | Ja |
| Better Stack, Inc. | 651 N Broad Street, Suite 206, Middletown, DE 19709, USA | Anwendungsüberwachung | EU | Nein | |
| Langfuse GmbH | Gethsemanestr. 4, 10437 Berlin, Deutschland | KI-Überwachung | EU (Frankfurt) | entfällt | |
| PostHog, Inc. | 2261 Market Street 4008, San Francisco, CA 94114, USA | Produktanalyse | EU (Frankfurt) | Ja |
| Unternehmen | Adresse | Art der Dienstleistung | Verarbeitungsstandort | Data Privacy Framework |
|---|---|---|---|---|
| Clerk, Inc. | 660 King Street, Unit 345, San Francisco, CA 94107, USA | Authentifizierung und Nutzerverwaltung (Plattform-Anmeldung) | Weltweit2 | Ja |
Data flow of end-user data
Every subprocessor processes end-user data within the EU, with no third-country transfer. The table below describes the role each one plays in the flow of that data.| Subprocessor | Role in the data flow |
|---|---|
| Amazon Web Services | Provides managed database hosting and object storage in eu-central-1 (Frankfurt), where all application data is stored long-term: website knowledge copies, employee-uploaded files, conversation and user data, and configuration. Also runs model inference through AWS Bedrock. |
| Hetzner | Hosts the servers in Nuremberg and Falkenstein that run the API and other botBrains-operated services. |
| DigitalOcean | Provides an in-memory database in Frankfurt for caching and scheduling asynchronous processing. Cached data may temporarily include customer data. |
| Vercel | Serves static HTML, JavaScript, CSS, and images for the chat widget (chat.botbrains.io) and the web app (platform.botbrains.io) over a global CDN, processing only the user’s IP address. |
| Modal | Provides the isolated execution environment (sandboxes), running in the EU region. |
| Microsoft Deutschland | Provides AI models. Inference runs in Sweden and France for capacity reasons; botBrains keeps the option to add further locations within the EU. |
| OpenAI Ireland | Provides AI models under an Enterprise Zero Data Retention agreement with EU data residency, so both storage (none, under ZDR) and inference stay within the EU. See ZDR and EU data residency. |
| Sentry | Captures application errors in the API and chat widget and alerts us to anomalies. EU region. |
| Better Stack | Collects logs and metrics for our applications and alerts us to anomalies. EU region, with headquarters in Poland. |
| Langfuse | Records AI model inputs and outputs, including the customer data in those conversations, for tracing and cost control. |
| PostHog | Tracks chat-user interaction after a conversation begins and platform-user (employee) interaction to monitor product issues and improve the interface. |