Sub-processors

Every provider that can touch data we process for you, what it does, what it sees and where it is.

Last reviewed: September 4, 2026

Data Processing Agreement Sub-processors Legal Notice Refund Policy

See also: Terms Privacy Cookies Terms of AI

How to read this page

A sub-processor is an outside provider that processes data on our behalf. Our own server and our own code are us, not a sub-processor, even though they do most of the work.

The list below is the whole of it for the product as it works today, and it was built by going through the code and the infrastructure rather than by listing the providers that sounded likely. If you believe something is missing, tell us and we will either add it or explain why it is not there.

The current list

Provider What it does What it sees Country Transfer safeguard
Hetzner Online GmbH The server where the panel, its database and the backups live. All account data and all measurement data, at rest. Germany, European Union. Nuremberg. Inside the EU, so no transfer. Provider data processing agreement.
Cloudflare, Inc. DNS, network and the tunnel in front of the panel, the API that receives the events, the database that holds booking engine searches and confirmed bookings, and the routing of the replies to our mailboxes. Traffic in transit, the event data, the visitor IP address during the request, and booking dates and amounts. Global network. Company established in the United States. Standard contractual clauses in the provider data processing addendum.
Brevo (Sendinblue SAS) Sends the emails of the service: reports, alerts and account emails. Recipient name and email address, and the content of the message. France, European Union. Inside the EU, so no transfer.
DataForSEO OU Puts the questions of the AI visibility module to the real assistants and returns their answers. The text of the question and the domain being tracked. No data about your guests. Estonia, European Union. Its own providers in Germany and the United States. Inside the EU. The provider states that it uses standard contractual clauses for its own providers outside it.
Google Ireland Limited Search Console API: we read the search metrics of the property you grant us access to. Your domain and its aggregated search metrics. We send it no personal data. Ireland, European Union, for customers in the European Economic Area. Global infrastructure. Access granted by you and revocable by you at any moment. Provider standard contractual clauses.
SideGuide Technologies, Inc. (Firecrawl) Reads public web pages: the search results page for a question and the competitor page in the rival analysis. Public addresses and their public content. No data about your guests and no account data. United States. The provider does not publish a data processing agreement. It receives only public addresses and public content, so in our use it processes no personal data of yours.
Hangzhou DeepSeek Artificial Intelligence Co., Ltd. Writes the content drafts, judges them against the quality gates, and groups Search Console queries into questions. The text we send in the prompt: titles and content of your own public pages, and your Search Console queries. No data about your guests. People's Republic of China. The provider has appointed a representative in the European Union and describes safeguards for transfers, without naming standard contractual clauses. Can be disabled for your account.
OpenRouter, Inc. Fallback of the writer when the provider above is unavailable, and the surface behind the historical AI measurements kept for comparison. The same prompt text as above. No data about your guests. United States. Standard contractual clauses under Article 46 GDPR, per the provider.

List last reviewed on September 4, 2026

What is deliberately not on this list

  • No advertising network, no third-party analytics on our own site, no data broker and no tool that holds your visitors as contacts. We measure our own site with our own product.
  • No geolocation provider. Working out the country of a visit is done on our own server against a database file stored there, so the IP address never leaves our machine for that.
  • No payment processor. None is enabled today, so no provider holds any billing data of yours. See the refund policy for what that means in practice.
  • No customer support tool with a chat widget on the panel, and no session recording sent to a third party.

The one that will raise a question in your review

A provider processing in China inside the list of a product sold to European hotels is the kind of line that stops a review, so here is the full picture rather than a defence. It is used by the content features, meaning writing article drafts and judging them, and by the step that groups your Search Console queries into questions. What travels to it is text from your own public website and your own search queries.

It never sees measurement data, account data or anything about your guests. If your legal department will not accept it at all, tell us and we disable the content features for your account, which costs you those features and nothing else.

How this list changes

A new provider is announced at least 30 days before it starts processing anything, and you can object with reasons during those 30 days. The full mechanism, including what happens if we cannot offer an alternative, is in the sub-processors section of the data processing agreement.

To be told of every change, write to [email protected] with the word subprocessors in the subject. The date above says when this list was last reviewed, and it is edited by hand so it means what it says.

An honest note to close. This is a template written on what the system actually does, reviewed by the people who built it, and it is not legal advice. Before your legal department signs anything, have a lawyer read it. If a clause here does not match how your company works, write to us and we will discuss it instead of pointing at the page.