Why this page exists
When you use Ever Traduora to process personal data, we act as your processor and you are the controller. Article 28 GDPR says we may not bring in another processor without your authorisation, and that you must be told in advance when we intend to add or replace one so that you have a real chance to object.
This page is that disclosure. It names every provider we engage to process personal data for the hosted Service, says what each one does, where it does it, and what categories of data reach it. Our Data Processing Addendum refers to this page, and your general authorisation to the providers listed here is given through it.
It is also written for people who are not our customers — someone whose employer uses the Service, or whose data ends up here for some other reason — because "who else can see this" is a fair question and the answer should not be available only to the person paying the invoice.
What counts as a sub-processor
A sub-processor is a third party we engage that processes personal data on our behalf and on our instructions, under a written contract meeting Article 28 GDPR. A provider that keeps the servers running, delivers your email, catches our errors or answers your support chat is a sub-processor.
Three things are not sub-processors, and lumping them in would make this page less accurate rather than more complete:
- A provider that never touches personal data. A design tool or an accounting package we use internally is not in the path of your data.
- A company that decides its own purposes. A payment processor acting on its own regulated obligations — fraud prevention, anti-money-laundering, card-scheme rules — is a controller in its own right for that part, not our processor. Those recipients are described in the Privacy Policy instead.
- Something we run ourselves. Our databases, object storage, secrets manager and container platform are ours. There is no third party to disclose. The infrastructure section below explains what we operate and what genuinely sits in front of it.
What this page covers
The hosted Service we operate at traduora.co, for Ever Traduora specifically. Other products in our range have their own list on their own domain, and the providers differ between them — do not read this one as covering a product it does not name.
It does not cover a deployment you run yourself. If you install our open-source software on your own infrastructure, you choose your own providers with your own credentials and contracts. The third tier below exists to make that distinction visible rather than to blur it.
This page is versioned and dated. The version in force, and the date it took effect, are at the end.
How to read this list
The three tables that follow mean genuinely different things, and reading them as one flat list will give you the wrong answer.
Here is why the split exists. Our products are open-source at their core and built to be connected to other things, so more than 160 distinct third-party providers appear somewhere in our source code across our whole range of products. The overwhelming majority of them are never engaged by us for anything. Some are optional integrations that do nothing until somebody switches them on. Many are reachable only in a deployment that somebody else runs, with their own account and their own credentials.
Publishing all of them as "our sub-processors" would be inaccurate, and inaccurate in the worst direction: it would tell you your data reaches companies it never touches, while burying the handful that it actually does. A list that is technically exhaustive and practically misleading is not a disclosure. So there are three tiers.
Tier 1 — always engaged
If you use the hosted Service, these providers are in the path. There is no setting that removes them, because they are part of how the Service is delivered to everyone.
This is the real Article 28 sub-processor list. It is the tier to use when you are completing a data protection impact assessment, mapping your transfers, or deciding whether you can use the Service at all. It is short, and it is short because we run our own infrastructure rather than renting someone else's.
Tier 2 — engaged only if you turn something on
A provider in this tier is engaged only when a specific feature, connector or integration is enabled. Enable nothing and it is never involved, and no data of yours ever reaches it.
Who does the enabling depends on the feature:
- You or your workspace administrator, by switching on a feature or connecting an account in the product's settings — a payment provider, an analytics tool, a chat widget, a calendar or repository connector.
- An individual user, by making a personal choice — signing in with a social account, for example, or connecting their own third-party tool.
The table names the feature or setting that activates each provider, so you can check your own configuration against it rather than take our word for the current state. If you want to know precisely which of these are live for your workspace today, ask us at [email protected] and we will tell you.
Enabling one of these is a decision to send your data somewhere else, and it is yours to make. The provider's own terms and privacy notice then apply to what it does, alongside our contract with it.
Tier 3 — self-hosted deployments only
Several of our products are published as open source and can be run on your own infrastructure. When you do that, you choose the database, the object storage, the email relay, the AI provider and everything else, using your own accounts and your own credentials.
The providers in this tier are listed only so that you can see what the software can be pointed at. They are not our sub-processors, and they never become ours by appearing here.
In a deployment you run: we process nothing, we have no access to it, we are not your processor for it, and nothing on this page or in our Data Processing Addendum describes it. You choose those providers, you contract with them, you hold the credentials, and the obligations to your own users are yours alone. The open-source section of our Terms of Service sets out the same split.
If you run a deployment yourself and need to publish a sub-processor list of your own, this tier is a useful starting inventory. It is not your list — only you know which of these you actually configured.
What the columns mean
- Sub-processor — the contracting legal entity, not the brand on the website. Where a provider has a separate European establishment that contracts with us, that is the one named.
- Purpose — what it does for the Service, specifically enough to be checked. Not "business operations".
- Location — where the processing takes place, or the provider's place of establishment where processing is distributed. Where a provider contracts through a European establishment but processes elsewhere, this column says both, because the two are different facts and only naming the first would flatter us.
- Transfer mechanism — for a provider outside the European Economic Area, the Chapter V instrument we actually rely on for that specific provider: an adequacy decision, the Standard Contractual Clauses, or nothing yet. Where it reads "To be confirmed", we have not yet evidenced an instrument for that provider, and we would rather say so here than print one we cannot produce. That is a live piece of work, not a formula. Providers established inside the EEA need no mechanism and say so. For the third tier the transfer is not ours at all — you choose the provider and hold the contract. The general rules behind this column are in the international transfers section of our Privacy Policy, and we will give you a copy of the safeguards for a named provider on request.
- Personal data — the categories that reach that provider. Categories, not a promise about volume: a provider that receives email addresses receives them for the people who trigger the feature, not for everyone.
Why this list is deliberately longer than it needs to be
We list providers we may engage, not only the ones engaged today. Where we have configured a provider, kept one available behind a feature flag, used one recently, or expect to use one for a purpose already described here, it appears in the tables below — even if no data has reached it this month, and even where we currently run the equivalent ourselves.
We do this on purpose, and you should read the tables with it in mind:
- A provider appearing here is not proof that your data has reached it. It means the provider is within the scope of what we have told you we may do, at the tier shown. The tier is the part that tells you when it is engaged.
- Where we self-host something today — our analytics, our job runner, our databases, our object storage — we say so, and we also name the hosted service we would move to, so that a later change is covered by a disclosure you have already seen rather than by a fresh surprise.
- The alternative is worse. A list that names only today's exact set has to be re-issued, and re-consented, every time an engineer changes a setting. A list drawn slightly wide stays true through ordinary operational change, which is what makes it dependable.
What we will not do is use this as cover. Breadth here does not license a purpose we have not described, a category of data we have not listed, or a transfer without a mechanism. If we start sending a new kind of personal data, or sending it for a new reason, that is a change to this page and to the notice period below — not something the width of a table quietly absorbs.
If you need to know precisely which providers are live for your workspace today, rather than which ones may be, ask us at [email protected] and we will tell you.
What is deliberately not in the tables
- Infrastructure we operate ourselves. Our databases, object storage, cache, secrets manager and container platform are not sub-processors, because there is no third party involved. The next section describes what we run and what really does sit in front of it.
- Recipients that are not processors — payment providers acting under their own regulatory obligations, professional advisers, public authorities, and an acquirer in a corporate transaction. Those are covered in the Privacy Policy.
- Sites you choose to visit by following a link out of the Service. Once you are on someone else's site, their notice applies.
Annex: Ever Traduora
Tier 1 — always engaged
| Sub-processor | Purpose | Location | Transfer mechanism | Personal data |
|---|---|---|---|---|
| Cloudflare, Inc. | DNS, content delivery, TLS termination, web application firewall and bot protection in front of traduora.co, docs.traduora.co and the content management hosts. Every request to those sites passes through it before it reaches our infrastructure. | United States, with traffic terminated at the edge location nearest the visitor anywhere in the world | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and device characteristics, requested URLs, referrer and request headers, TLS and connection metadata, security cookies set by the provider |
| GitHub, Inc. (a Microsoft Corporation company) | Hosts the source, builds and container images every product is deployed from, serves the desktop auto-update feed that every desktop client contacts unconditionally, and - separately and conditionally - powers the customer-installed GitHub App that syncs repositories and issues into tasks. | United States | Standard Contractual Clauses (EU 2021/914) | source, build, release and deployment metadata, developer and automation account identifiers, IP address and user agent of anyone downloading a desktop or server release, or performing an auto-update check, GitHub App installation id, repository, issue and commit content and contributor identities within the granted scope, for ever-works: customer Work repositories pushed into the platform-owned org ever-works-cloud, whose repo names and descriptions carry end-user free text and at least one identifiable person's name |
| Cloudflare, Inc. (R2 object storage) | Holds the encrypted off-site copy of our backups - Postgres WAL and dumps, Velero, etcd, Proxmox configuration and MinIO mirrors - as the third tier of the backup chain (node8 NVMe, then Ceph RGW, then Cloudflare R2). Encrypted by us before it leaves our network. | United States | Standard Contractual Clauses (EU 2021/914) | client-side encrypted backup archives only - no plaintext is ever readable by the provider, the archives themselves derive from every category of data the products hold |
| Google Ireland Limited (reCAPTCHA) | Scores whether the person submitting a signup, login or contact form is human, loading on the form page before any consent choice is made. | Ireland (contracting entity); processing in Ireland (contracting) / United States (onward processing by Google LLC) | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and device characteristics, mouse, touch and timing signals from the form page, cookies set on google.com |
| Cloudflare, Inc. (Turnstile) | Checks that the person completing registration, onboarding or an anonymous flow is not a bot; on ever-works the API refuses the anonymous flow when no CAPTCHA provider is configured, which is why it is unconditional there. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and device signals, mouse, touch and timing interaction signals, Turnstile challenge cookie |
| Clerk, Inc. | Holds the account identity for the hosted cloc platform - name, email address, avatar, password or federated identity, sessions and multi-factor settings - so that our own database does not, and brokers the short-lived source-control credential used when the Service acts in a user's name. | United States | Standard Contractual Clauses (EU 2021/914) | name, email address and avatar, password hash or federated identity, session, device and sign-in records, organisation membership and role, social-connection claims where a user signs in that way, the short-lived source-control credential brokered for a single request and not stored |
| Tavily | The default provider for public web search and page extraction, used by agents researching a topic and by the automated research that runs when an account is created, where the queries are built from the new account holder's name and email domain. | United States | To be confirmed — we do not yet evidence a mechanism | search queries, including a person's name and their employer's email domain, the addresses of pages retrieved and the extracted page content, our API key and request metadata |
| ui-avatars.com | Generates placeholder avatars where a person has no avatar of their own. The person's name or GitHub username is placed in the image URL, so it is disclosed to this provider every time the image is rendered in a customer's browser. | UNKNOWN - not published by the provider | To be confirmed — we do not yet evidence a mechanism | the developer's name or GitHub username, in the request URL, the viewing user's IP address and user agent |
| Prospect One sp. z o.o. (jsDelivr) | Serves the Lottie animation runtime hard-coded into the ever-works login and register pages, so every person who opens the login page hands their IP to it before authenticating. | Poland (operator); delivery worldwide | Standard Contractual Clauses (EU 2021/914) | IP address, user agent, referring page URL |
| UNKNOWN - community-run npm CDN; no obtainable DPA counterparty identified | Second permitted origin for the Lottie animation runtime on the ever-works login and register pages. | United States (unverified) | To be confirmed — we do not yet evidence a mechanism | IP address, user agent, referring page URL |
| ActiveCampaign, LLC (Postmark) | Relays every transactional email a product sends - account invitations, verification and sign-in codes, invoices, approvals - and on ever.co also carries contact-form enquiries with PDF attachments, so CVs and the third parties named inside them reach a US processor. | United States | Standard Contractual Clauses (EU 2021/914) | recipient name and email address, full message subject and body - invitations, verification and sign-in codes, invoices, timesheets, HR and approval content, free-text enquiry content and attached CVs from website contact forms, anyone NAMED inside that free text or attachment, delivery, bounce and open metadata |
| Resend, Inc. | Sends transactional mail for the products and domains configured against it, relaying onward through Amazon SES. | United States | Standard Contractual Clauses (EU 2021/914) | recipient name and email address, message subject and body, delivery and bounce metadata |
| Langfuse GmbH | Stores the full prompts and completions of AI features together with model, latency and cost metadata, so that agent behaviour can be traced and scored. | Germany | None needed — established in the EEA | full prompt and completion text, which can contain user-authored content and personal data, user and session identifiers, model, latency, token and cost metadata, developer scoring outputs |
| OpenRouter, Inc. | Is the model provider behind the default 'Ever Works AI' option and the hard-coded default for AI Chat on every provisioned tenant site, receiving the raw prompt and forwarding it to whichever upstream model the selected model id resolves to. | United States | To be confirmed — we do not yet evidence a mechanism | full prompt text, including any customer or end-user content pasted into an agent - repo text, CVs, job descriptions, chat messages, generated completions, agent tool-call arguments, API key metadata and usage accounting |
Tier 2 — engaged only when a feature, integration or consent brings them in
| Sub-processor | Purpose | Location | Transfer mechanism | Personal data |
|---|---|---|---|---|
| Functional Software, Inc. d/b/a Sentry | Error and crash diagnostics on traduora.co, and browser SESSION REPLAY — a masked reconstruction of what happened in the page. Replay is sampled at roughly one in ten visits and captured for every visit in which an error occurs, with all text masked and all media blocked. Engaged only where you consent to the analytics category. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, user agent, operating system, browser and screen size, page URL and referrer, error events and stack traces, a masked session replay — page structure, navigation and interaction timing, with text masked and media blocked |
| PostHog, Inc. | Product analytics on traduora.co — page views and page-leave events, so we can see which pages are read and which are abandoned. Engaged only where you consent to the analytics category. | United States | Standard Contractual Clauses (EU 2021/914) | a persistent visitor identifier generated by the provider, IP address, user agent and device characteristics, pages viewed, referrer and event timestamps |
| Google Ireland Limited (Google Workspace) | Google Analytics on traduora.co, loaded from googletagmanager.com. The measurement identifier in the page is a legacy Universal Analytics property, so the request discloses your visit to Google whether or not anything is still measured behind it. Engaged only where you consent to the analytics category. | Ireland, with processing by Google LLC in the United States | Standard Contractual Clauses (EU 2021/914) | a client identifier stored in a first-party cookie, IP address, user agent and device characteristics, pages viewed and referrer |
| New Relic, Inc. | Browser performance monitoring on traduora.co — page load and rendering timings, and front-end errors. The agent is configured with its own cookies switched off, so it stores nothing on your device, but the beacon request itself is still a disclosure. Engaged only where you consent to the analytics category. | European Union — the agent reports to the provider's EU beacon endpoint. The provider is established in the United States. | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and device characteristics, page URL and referrer, page timing and performance measurements |
| SolarWinds Worldwide, LLC (Pingdom) | Real user monitoring on traduora.co — how long pages actually took to load for real visitors. Engaged only where you consent to the analytics category. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and device characteristics, page URL, page timing measurements |
| DigitalOcean, LLC | Serves desktop installer downloads from the gauzy.co download page, holds media in Spaces where a deployment selects it as the file provider, still carries legacy container images and gated deploy workflows, and for cloc provisions servers on a customer's behalf. | United States | Standard Contractual Clauses (EU 2021/914) | uploaded files, screenshots and captured media held in Spaces, IP address and user agent of anyone downloading an asset or a desktop installer, container images and build metadata (no personal data), for cloc: server handles, sizes and lifecycle state of infrastructure provisioned on a customer's behalf |
| Google Ireland Limited (Google Analytics 4 and Google Tag Manager) | Measures marketing-site and, on some properties, in-application usage through the GA4 tag loaded via Tag Manager, keyed to a persistent client-id cookie. | Ireland (contracting) / United States (processing) | Standard Contractual Clauses (EU 2021/914) | IP address (anonymize_ip is set on some sites, not all), _ga / _gid / _gat cookies (GA client identifier), page URLs, referrer and UTM parameters, device, browser and approximate location, conversion events, tied to a user id on gauzy.co |
| Google Ireland Limited (Sign in with Google) | Authenticates a user who chooses 'sign in with Google', returning their email, name and picture, and in ever-rec also exports recordings to the user's own Google Drive when they connect it. | Ireland (contracting) / United States (operating) | Standard Contractual Clauses (EU 2021/914) | email address, name and profile picture, Google account identifier, OAuth access and refresh tokens, Google Drive file metadata and content the user chooses to export, where the Drive scope is granted (ever-rec) |
| Algolia SAS | Answers the search box on the documentation sites, receiving each reader's query and IP where Algolia credentials are configured. | France (EEA) or United States, depending on the contracting entity and the index region | To be confirmed — we do not yet evidence a mechanism | search queries typed by the reader, IP address, user agent, indexed page content |
| Google Ireland Limited (Google Fonts) | Delivers typefaces to the visitor's browser at page load on the properties that hot-link them, disclosing the visitor's IP to Google before any consent choice. | Ireland (contracting entity); processing in Ireland (contracting) / United States (operating) | Standard Contractual Clauses (EU 2021/914) | IP address, user agent, referring page URL |
| Vercel Inc. | Hosts the cloc platform; routes AI prompts to downstream model providers for gauzy through the AI Gateway; and remains the deployment target of surviving workflows and DNS delegations for several frontends that have since moved to our own cluster. | United States | Standard Contractual Clauses (EU 2021/914) | for cloc: full application traffic and runtime data (the platform actually runs there), IP address and user agent of visitors where a site is served from Vercel, page-view and Web Vitals events, for gauzy: prompt content and model responses routed through the AI Gateway, plus routing and usage metadata, deployment metadata |
| Amazon Web Services, Inc. | S3 is the object-storage backend an operator or tenant can select for uploads and monitoring media; CloudFront serves maintenance.ever.co and security.ever.co on our flagship domain; SES sits underneath our email relay as that relay's own sub-processor. | United States (Luxembourg for the EEA contracting entity) | Standard Contractual Clauses (EU 2021/914) | uploaded files, avatars and document images in S3, employee-monitoring screenshots, webcam stills, audio and screen recordings where S3 is the file provider, static assets served from CloudFront, exposing visitor IP and user agent, outbound email envelope and content where SES is in the path, certificate validation records (no personal data) |
| Uptime Robot Service Provider Ltd - UNVERIFIED. The commonly cited registration is Cyprus (Nicosia); confirm from the current Terms or Imprint before publishing any location claim. | Hosts the public status page at status.<our-domain>, so anyone who opens it hands their IP and user agent to the vendor. | Cyprus (unverified) | To be confirmed — we do not yet evidence a mechanism | IP address and user agent of every visitor to a status page, cookies set by the status page, monitored endpoint URLs and response metadata |
| Wasabi Technologies, Inc. | Holds avatars, task attachments and time-tracker screenshots wherever the platform's or a tenant's file provider is set to Wasabi. | United States | Standard Contractual Clauses (EU 2021/914) | uploaded files and document attachments, avatars, employee time-tracker screenshots and captured monitoring media |
| Cloudinary Ltd. | Stores and transforms images and video where a deployment's or the platform's media provider is set to Cloudinary, and serves them to viewers directly from its own CDN. | Israel | Adequacy decision — Israel | uploaded images and video, screenshots and captured media, IP address and user agent of every viewer fetching an asset |
| UNKNOWN - operated by an individual developer; no identifiable legal entity, no privacy policy, no DPA counterparty | Supplies fallback avatar and logo placeholder images whose URLs are written into persisted user, organization and team records and then fetched directly by the visitor's browser. | United States (unverified) | To be confirmed — we do not yet evidence a mechanism | IP address, user agent, referring page URL |
| Twilio Inc. (SendGrid) | Sends and tracks marketing or transactional email for gauzy.co through dedicated sending, reply and link-tracking subdomains, and stands as an alternative sender for githands. | United States | Standard Contractual Clauses (EU 2021/914) | recipient email address and name, message content, open and click tracking events (links.gauzy.co), recipient IP and user agent via tracking pixels |
| Twilio Inc. (Programmable Messaging) | Sends SMS where a tenant configures Twilio as its SMS gateway using its own account SID and token. | United States | Standard Contractual Clauses (EU 2021/914) | recipient telephone number, message body, which can contain a capture link or workspace content, delivery and status metadata |
| Jitsu Labs, Inc. | Collects product events into an event pipeline where a write key is configured, on Jitsu's US cloud. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, user and workspace identifiers, page and feature events, device and browser characteristics |
| Hound Technology, Inc. (d/b/a Honeycomb.io) | Receives OpenTelemetry traces from the API where Honeycomb is selected as the OTEL provider, including request URLs and database statements that routinely carry identifiers. | United States | Standard Contractual Clauses (EU 2021/914) | trace and span data including request URLs, route parameters and DB statements, service and host identifiers, anything a span attribute carries, which can include user and tenant ids |
| SigNoz Inc. (Delaware, USA) for SigNoz Cloud; SigNoz itself is Apache-2.0 and self-hostable. | Receives OpenTelemetry traces, metrics and logs from the API wherever the OTLP endpoint is configured, including route parameters and SQL text. | United States | To be confirmed — we do not yet evidence a mechanism | distributed traces including HTTP routes, query strings and SQL statements, service and host metadata, metrics and logs, anything attached as a span attribute |
| Better Stack, s.r.o. | Receives shipped application logs where a log token is configured, including the ChatGPT connector service in ever-teams and the cloc platform's observability pipeline. | Czech Republic | None needed — established in the EEA | application log lines, which may embed user ids, request paths and IP addresses, uptime probe results |
| OpenAI, L.L.C. | Generates completions and transcribes audio for in-application AI features, using either a platform-held key (cloc) or a key the customer supplies (gauzy, ever-works, ever-teams, hust). | United States | Standard Contractual Clauses (EU 2021/914) | prompt content, including workspace records, job posts, candidate and employee profile text, issue and task text and chat messages, audio submitted for transcription, model responses, OAuth device-auth identity for the Codex CLI plugin |
| Anthropic, PBC | Generates completions for in-application AI features - the default model in hust, a plugin or bring-your-own-key option in gauzy and ever-works. | United States | Standard Contractual Clauses (EU 2021/914) | prompt content, which can include workspace data the user pastes or references, model responses |
| Google Ireland Limited (Gemini API) | Generates completions for the in-application AI assistant where a customer connects a Gemini key, through the AI Studio endpoint rather than Vertex AI. | Ireland (contracting entity); processing in United States (AI Studio) / Ireland (Vertex AI) | Standard Contractual Clauses (EU 2021/914) | prompt content, which can carry workspace, HR and candidate data, model responses |
| Mistral AI SAS | Generates completions where the Mistral plugin is enabled for a Work. | France | None needed — established in the EEA | prompt text, completions |
| X.AI LLC | Generates completions where a customer selects Grok and supplies a key. | United States | To be confirmed — we do not yet evidence a mechanism | prompt content, model responses |
| Groq, Inc. | Serves completions where a user supplies a Groq key and selects it as the provider. | United States | To be confirmed — we do not yet evidence a mechanism | prompt content, model responses |
| Together Computer, Inc. (trading as Together AI) | Serves completions where a user selects Together as the provider and supplies a key, called from our own Next.js server route. | United States | To be confirmed — we do not yet evidence a mechanism | prompt content, including chat message text, model responses |
| Vercel Inc. | Routes AI prompts from the Gauzy assistant to whichever downstream model provider the customer's selected model resolves to. | United States | Standard Contractual Clauses (EU 2021/914) | prompt content, model responses, request routing and usage metadata |
| Intuition Machines, Inc. (hCaptcha) | Scores signup and login attempts wherever the CAPTCHA provider is set to hCaptcha. | United States | Standard Contractual Clauses (EU 2021/914) | IP address, user agent and browser/device fingerprint signals, mouse, touch and timing interaction signals, challenge solution and token |
| Meta Platforms Ireland Limited (Facebook Login) | Authenticates a user who chooses to sign in with Facebook, returning their email, name and profile picture. | Ireland (contracting entity); processing in Ireland (contracting for EEA users) / United States (Meta Platforms, Inc.) | Standard Contractual Clauses (EU 2021/914) | email address and name, Facebook user identifier, profile picture URL, OAuth tokens |
| LinkedIn Ireland Unlimited Company | Authenticates a user who chooses to sign in with LinkedIn, returning their email, name and the profile fields in the granted scope. | Ireland (contracting entity); processing in Ireland (EEA contracting) / United States (processing) | Standard Contractual Clauses (EU 2021/914) | email address and name, LinkedIn member identifier, OAuth tokens, profile fields returned within the granted scope |
| X Corp. (Twitter) | Authenticates a user who chooses to sign in with X, where that provider is enabled for the deployment. | United States | To be confirmed — we do not yet evidence a mechanism | handle and public profile, X user identifier, OAuth tokens |
| Microsoft Corporation (Microsoft Entra ID) | Authenticates a user or administrator who chooses a Microsoft work or personal account, reading profile details from Microsoft Graph, where FEATURE_MICROSOFT_LOGIN is enabled. | United States | Standard Contractual Clauses (EU 2021/914) | email address and display name, Microsoft tenant identifier and user object id, OAuth access and refresh tokens, directory profile fields returned by Graph within the granted scope |
| Okta, Inc. (Auth0) | Authenticates an organisation's people where that organisation chooses to route sign-in through its own hosted Auth0 tenant. | United States | Standard Contractual Clauses (EU 2021/914) | email address and profile, OAuth/OIDC tokens, login IP address, device and user agent, authentication and MFA event logs |
| Atlassian Pty Ltd (Jira, Trello) | Syncs tasks, issues and attachments with a Jira or Trello site the customer connects using its own account. | Australia (Atlassian Pty Ltd) / Netherlands (Atlassian B.V.) / United States (Atlassian, Inc.) | Standard Contractual Clauses (EU 2021/914) | issue, project, card and board records, reporter and assignee identity, attachments, screenshots and recordings pushed to an issue, API key and OAuth tokens |
| Slack Technologies, LLC (a Salesforce, Inc. company) | Posts notifications into, and reads events from, a Slack workspace the customer connects by installing our app into its own workspace. | United States (group); Ireland (EEA contracting for Slack's own customers) | Standard Contractual Clauses (EU 2021/914) | channel and workspace identifiers, message content we post or receive, Slack user identity, including member email addresses, OAuth tokens and webhook payloads, shared recordings, screenshots and their links (ever-rec) |
| Zapier, Inc. | Forwards workspace records into whatever third-party apps a customer wires into a Zap, so the onward destinations are the customer's choice and outside our contract. | United States | Standard Contractual Clauses (EU 2021/914) | records pushed through a Zap (tasks, timesheets, contacts), OAuth tokens and authorization codes, arbitrary event payloads forwarded to whatever apps the customer wires up |
| Activepieces Inc. | Runs automation flows that read and receive whatever workspace records a customer wires in, on Activepieces' US cloud unless repointed at a self-hosted instance. | United States / Canada | Standard Contractual Clauses (EU 2021/914) | records pushed through a flow, which can be any workspace data, API keys, webhook payloads |
| Celonis SE (Make.com) | Runs automation scenarios that read and receive whatever workspace records the customer wires in, from EU infrastructure. | Germany / Czech Republic | None needed — established in the EEA | records pushed through a scenario, webhook payloads, OAuth tokens |
| Noti-Fire Apps Ltd. (Novu) | The in-application notification inbox and a delivery channel for notifications, where it is configured against Novu's hosted service rather than an instance you run. | Israel | Adequacy decision — Israel | a hashed subscriber identifier, computed server-side under NOVU_SECRET_KEY, notification content, email address where Novu is used as a delivery channel |
| Plausible Insights OÜ | Cookieless site analytics on a Work site, where the Work Owner enables it. | Estonia | None needed — established in the EEA | page views and referrer, coarse device and country, derived and not stored as an IP address |
| HubSpot, Inc. | Two-way contact synchronisation, engaged only when a customer connects its own HubSpot account. Data moves in both directions once connected. | United States (HubSpot, Inc.) / Ireland (HubSpot Ireland Limited, for HubSpot's own EEA customers) | Standard Contractual Clauses (EU 2021/914) | contact and company records the customer chooses to sync, names, email addresses, employers and job titles in those records, the OAuth credential for the connection |
| Chatwoot Inc. | Runs the support chat widget that visitors and signed-in users type into, receiving the whole conversation plus the page context. | United States | Standard Contractual Clauses (EU 2021/914) | visitor or user name and email when supplied, full chat message content, IP address, page URL and browser details |
| iubenda s.r.l. | Delivers hosted legal documents to visitors who open the /legal route in the Gauzy application, which still fetches the policy from iubenda in the visitor's browser. | Italy | None needed — established in the EEA | IP address, user agent, consent preferences and the timestamp of the choice |
| Google Ireland Limited (Google Maps Platform) | Renders maps and completes typed addresses for contacts, clients and organisations where the Maps and Places features are enabled with an API key. | Ireland (contracting entity); processing in Ireland (contracting) / United States (processing) | Standard Contractual Clauses (EU 2021/914) | IP address, typed address fragments and place queries, latitude and longitude of contacts, clients and organisations, session tokens for autocomplete billing |
Tier 3 — self-hosted deployments only
If you run Ever Traduora on your own infrastructure, you choose these providers and hold the credentials. We are not a processor for anything in a deployment you run: we do not receive that data, we cannot reach it, and we have no relationship with the providers you configure.
| Sub-processor | Purpose | Location | Transfer mechanism | Personal data |
|---|---|---|---|---|
| The database you provide — MySQL, MariaDB, PostgreSQL or SQLite | Holds everything in your instance: users, projects, terms, translations, labels, invitations and API client records. You choose the engine, the host and the operator, and you hold the credentials. | Wherever you run it | Not our transfer — you choose the provider | user name, email address and hashed password, password-reset tokens and expiry, sign-in attempt counts and last sign-in time, invitation email addresses, status and project role, project API client names, roles and secrets, term keys, context strings and translation values, which are free text and can contain anything your team types into them |
| The Rocket Science Group LLC d/b/a Mailchimp | Sends the transactional email your instance generates — welcome messages, password-change and password-reset messages, project invitations and platform invitations. The software has no default relay and no relay of ours. | Wherever your relay operates | Not our transfer — you choose the provider | recipient email address and name, password-reset links and invitation links, the project or instance the message concerns |
| Google Ireland Limited / Google LLC — Google Sign-In | Optional Google sign-in for your instance, active only where you switch it on and register your own OAuth client with your own Google account. It is off in the default configuration. | Ireland and the United States | Not our transfer — you choose the provider | your users' Google account identifier, email address, display name |
| Elestio | A one-click deployment of Ever Traduora offered by that vendor and linked from the project's documentation. If you use it, it hosts your instance and your contract is with it. We receive nothing and are not a party to it. | As stated by that vendor | Not our transfer — you choose the provider | everything in your instance, because it hosts it |
| none in a self-hosted deployment - the reader (or we) runs the runtime. Ollama Inc. (US) publishes the software and would become a processor only if a hosted Ollama service were adopted. | Runs open-weight models inside the deployment itself, so prompts reach no third party at all. | n/a (self-hosted); United States for Ollama Inc. | Not our transfer — you choose the provider | chat and prompt text, which never leaves the deployment |
| Red Hat, Inc. (Keycloak) | Authenticates users through a Keycloak realm that the organisation running the deployment operates itself. | United States (Red Hat, Inc.) / wherever the reader runs the realm | Not our transfer — you choose the provider | email address and profile, OIDC tokens |
| Mixpanel, Inc. | Records in-app screens and named events - 'Order Delivered' from the courier application, 'Order Failed' from the merchant tablet and similar - against a device identifier, where the operator configures a Mixpanel token and publishes a build containing it. | United States | Not our transfer — you choose the provider | device identifier, screens viewed and in-app events, IP address, user identifier once the person has signed in, the Mixpanel project token, which is compiled into the distributed binary |
| Intercom, Inc. | Runs the in-application support conversation in the shopping, merchant and courier mobile applications through cordova-plugin-intercom / @ionic-native/intercom, where the operator supplies Intercom credentials. | United States (Intercom, Inc.) / Ireland (Intercom R&D Unlimited Company) | Not our transfer — you choose the provider | user identifier and email address, full support conversation content, device and application context, the operator's Intercom app id and API key |
There is no hosted service, so this list is short
Ever Traduora is open source and self-hosted. We do not run a cloud version of it, which means we hold none of your translation data and engage no sub-processor for it. Tier 1 above covers only the traduora.co website and its documentation.
If you run Ever Traduora, every provider it talks to is one you configured, under your own account. That is the whole of tier 3, and none of it involves us.
Hosting and infrastructure
The tables above are short for a reason, and the reason is worth stating plainly: we run our own infrastructure. The Service is not a tenancy in a public cloud account. It runs on physical servers we own, in facilities we control, inside the European Union, on a virtualisation and container platform we operate ourselves.
The database, the object storage that holds your files, the cache and queue layers, the secrets manager and the deployment system are all components we run. None of them is a third party, so none of them appears as a sub-processor — there is nobody else to disclose. What we do with them is described on our Security page.
Where processing actually happens
- Your data at rest, and the applications that process it, sit on our own hardware in the European Union. That is the primary location for accounts, content, files and the databases behind them.
- Requests reach us through a global content delivery and security network. Traffic is terminated at the edge location nearest to whoever is making the request, which can be anywhere in the world, before being carried to our infrastructure in Europe. That provider is in the always-engaged tier above, and the transfer mechanism for it is described in our Privacy Policy.
- Off-site backup copies are held with an external object storage provider, encrypted by us before they leave our network. That provider holds ciphertext and no key, and cannot read what it stores.
- Our source code, build pipeline and container images are hosted with a third-party provider. That is how the Service is built and deployed rather than where your data lives day to day, but it is a genuine third party and it is disclosed as one.
Where a product does something different
A small number of products use a third-party managed database, managed storage or hosted platform for a specific function instead of our own infrastructure. Where that is the case for Ever Traduora, the provider appears in the always-engaged tier above and the product annex says which data goes there.
We are explicit about this because "self-hosted" is exactly the sort of claim that gets made once and then stops being true for one product in the range. If your data for a given feature sits with someone else, the table says so.
The regions you should design around
If you are completing a transfer mapping or a data protection impact assessment, the honest summary is: primary processing in the European Union on infrastructure we operate; edge termination worldwide; a small number of named providers established outside the European Economic Area, each with its own transfer mechanism. Every one of those providers is in the tables above, and the mechanism for each is in the international transfers section of the Privacy Policy.
If you need a copy of the safeguards for a named provider — the Standard Contractual Clauses and which modules apply — write to [email protected] and we will send them.
When this list changes
The notice period
We give at least 30 days' notice before a new or replacement sub-processor starts processing personal data for the hosted Service. The 30 days run from the date the notice is published or sent, whichever comes first, and they exist so that your objection right is a real one rather than a formality you learn about afterwards.
How you find out
- This page changes first. It carries the date it took effect and a dated record of what changed, so the page itself is the notice.
- By email, if you ask for it. Write to [email protected] and we will add your address to the notification list. We then email you before each change, at the same time the page is updated. We recommend a role address rather than an individual's — a notice sent to someone who has left your organisation has been sent and not received.
- In the product, for changes that affect a feature you are using, through a notice to workspace administrators.
What the notice tells you
The provider's legal name, what it will do, where it is established, the categories of personal data it will receive, the transfer mechanism if it is outside the European Economic Area, the date it takes effect, and whether it is a new provider or replaces one already on the list. If it replaces one, we say which.
Urgent replacements
Sometimes we have to move faster than 30 days — a provider suffers a security incident, terminates its service, loses the legal basis it relied on, or fails in a way that makes staying with it worse than leaving.
Where that happens we may engage the replacement sooner, and we will notify you as quickly as we can with the reason we could not wait. Your right to object is not affected: it simply runs from the notice instead of before the change. We do not use this route as a convenience, and a notice sent under it says plainly why the normal period was not followed.
Changes that do not need notice
Removing a provider does not need a notice period — it reduces the number of people handling your data. A provider changing its own name, or the group entity that contracts with us changing without a change in where or how the processing happens, is recorded here as an administrative update rather than announced as a new engagement. A provider moving its processing to a different country is not administrative, and gets the full notice.
The record
We keep the change history for this page so that you can reconstruct who was engaged during a given period. That matters if you are updating your own records of processing, refreshing an impact assessment, or answering a question about a period in the past. Ask [email protected] if you need the state of the list as it stood on a particular date.
Objecting to a sub-processor
Who can object
The customer — the organisation or person who contracts with us and acts as controller for the data in the workspace. If you are an individual whose data we hold, this is not your route: your rights are in the Privacy Policy, and if your data sits in an employer's workspace, your employer is the controller and the request goes to them.
How to object
Write to [email protected] within 30 days of the notice, and tell us:
- which provider you are objecting to;
- your reasons, on data protection grounds — a transfer you cannot justify, a conflict with a commitment you have given your own users, a regulator's position that applies to you, a documented security concern;
- which of your workspaces or environments the objection covers.
The reasons matter. This is a right to object on data protection grounds, not a veto over our choice of suppliers, and an objection with no stated ground gives us nothing to work with. Tell us what the problem is and we can usually solve it.
What we do next
We acknowledge your objection within five business days and respond substantively within 30 days. In between we look for a way to make the objection unnecessary:
- A different provider for your workspace, where one exists that does the job.
- A different configuration — narrowing what is sent, changing a region, or turning off the feature that needs the provider at all, if you can live without it.
- Excluding your workspace from the provider, where that is technically possible.
- Additional safeguards or contractual terms where your concern is about a specific risk rather than the provider as a whole.
Where it is technically possible to hold off, we will not start using the provider you have objected to for your data while the objection is open. Where it is not possible — because the provider is part of how the Service is delivered to everyone — we will tell you that plainly and quickly, rather than letting the clock run out on you.
If we cannot resolve it
If we cannot offer you a solution you can accept, you may terminate the affected subscription by written notice, without penalty, and we will refund the fees you have prepaid for the period after termination. That is the remedy: neither of us owes the other damages for a good-faith disagreement about a supplier.
Give us notice within 30 days of our final response, and we will keep your data available for export for the usual 30-day window described in the Terms of Service so that leaving does not cost you the data.
If you are on a free tier there is nothing to refund, and the same route is simply to stop using the Service and export your data.
Objecting to a provider already on the list
You do not have to wait for a change. You can raise a concern about a provider already listed at any time, using the same address and the same process, without the 30-day deadline. The realistic outcome differs by tier: a tier 2 provider can usually be switched off for you; a tier 1 provider generally cannot, because it is part of how the Service works — and if the answer is going to be no, you will get it as a straight no with the reason.
How to reach us about this list
- Questions about a provider, a request for the safeguards behind a transfer, or a request to join the change notification list — [email protected].
- An objection to a sub-processor — [email protected], as set out above.
- The Data Processing Addendum, a due diligence request, or a security questionnaire — [email protected].
We are Ever Technologies LTD, registered in Bulgaria under company number 204599535, with its registered office at Mladost 2, bl. 211, ent. A, Sofia 1799, Bulgaria. We are the controller for our own processing and your processor for the data in your workspace. By post, write to the registered office and mark the letter for the attention of the privacy team. We correspond in English.
You may also complain to a data protection supervisory authority. Ours is the Commission for Personal Data Protection (Комисия за защита на личните данни), the CPDP, at https://www.cpdp.bg/. You may instead complain to the authority for the country where you live or work.
This document is version 1.0.2 of the sub-processor list for traduora.co, in force from 2026-08-02. It lists the providers engaged as at that date. Earlier versions, with the dates they applied, are at https://traduora.co/subprocessors.