Sub-processors

This page separates two groups: the sub-processors under Art. 28 GDPR that take part in processing your data, and further providers that process only data for which PrivatAI is itself the controller. The distinction is legally material — only the first group falls under Art. 28 — and the second is listed anyway, because transparency about the whole data path is worth more than a formally narrower list.

Controller: Artur Parutkin (sole proprietorship), Hamburg. Data-protection contact: datenschutz@privatai.com — address see imprint.

Core data stays in the EU. Your prompts and documents are processed exclusively in the EU (inference in France, hosting in Germany) and are not stored. Email stays in the EU too: inbound on our own server in Germany with no further provider, outbound via Scaleway Transactional Email in France. Payment data alone is processed via a US provider — a condition of the service, safeguarded primarily by the EU-US Data Privacy Framework, supplemented by the EU Standard Contractual Clauses.

1. Sub-processors under Art. 28 GDPR

These providers process data you entrust to us as our customer — prompts, outputs and the platform data in which they are processed. A data processing agreement under Art. 28 GDPR is in place with each.

Scaleway S.A.S.
PurposeAI inference (running the language models)
DataPrompts and outputs — not stored, not logged, no training
LocationFrankreich (EU)
TransferDPA Art. 28; no third-country transfer
Hetzner Online GmbH
PurposeHosting, servers, database
DataAccount, usage and platform content data
LocationGermany (EU)
TransferDPA Art. 28; EU/EEA only

2. Further providers (not sub-processors within the meaning of the DPA)

These providers process account, payment and correspondence data for which PrivatAI is itself the controller. They are not part of the processing you entrust to us and are therefore not sub-processors within the meaning of the DPA. Data processing agreements are in place with both, with PrivatAI as controller.

Scaleway S.A.S. — Transactional Email
PurposeSending transactional and newsletter email
DataEmail addresses, names, email content
LocationFrance (EU)
TransferArt. 28 DPA; no third-country transfer
Stripe Payments Europe, Ltd.
PurposePayment processing
DataPayment, billing and identity data (KYC). Card details never reach our systems.
LocationIreland (contracting party) and USA (Stripe, LLC)
TransferUnder Stripe’s terms the transfer to Stripe, LLC (USA) is a condition of the service. Adequacy decision for the EU-US Data Privacy Framework (Stripe, LLC certified), supplemented by the EU Standard Contractual Clauses.
RolePartly processing on our instructions, partly Stripe’s own controller processing (fraud prevention, anti-money-laundering and identity checks).

Inbound email. We receive email ourselves: the MX records point to our own server at Hetzner in Germany. No further provider is involved in receiving it. Please do not send us third parties’ personal data by email — the service itself, not the mail path, is the place for such content.

3. Planned

The following provider is envisaged but not yet engaged: no contract is currently in place and no data is transmitted. Affected customers will be informed with reasonable advance notice before any engagement.

T-Systems International GmbH (Telekom) planned — not yet engaged
PurposeAI inference with German hosting (EU models only, T-Cloud Public)
DataPrompts and outputs — not stored, no training
LocationGermany (EU)
TransferDPA (EU SCC Art. 28, 2021/915); EU models only

Further notes

Web analytics run on a self-hosted instance (GoatCounter) on our EU infrastructure — no separate sub-processor, no third-party trackers, no cookies.

We inform affected customers of intended changes to this list (adding or replacing a sub-processor) with reasonable advance notice and grant a right to object.

Last updated: August 2026