Sub-processors

List of our sub-processors

This English text is a convenience translation. The legally binding version is the German one (Deutsch), reachable via the language switch below.

Last updated: 2026-07-30

Effective / last updated: 2026-07-30. List version: 2.1

Change note (2026-07-30, version 2.1). No Sub-processor was added, replaced, or removed, so the Section 5 advance-notice and objection process is not engaged. Version 2.1 corrects and completes facts about the five Sub-processors already listed: Railway's hosting region is stated as the EU region actually in use, verified on 2026-07-30; the Stripe contracting entity is resolved; the per-recipient transfer mechanisms are stated on confirmed grounds rather than as alternatives; and the previous combined statement that a "no-training / zero-retention tier" was enabled for the language-model provider is split, because only the no-training half was correct. The corrected retention position is in row 2 and in Section 3.

This list is published by Finalform GmbH, Theodor-Heuss-Str. 106, 26129 Oldenburg, Germany ("Finalform", "we", "us"), the operator of Autopage.

1. Purpose and authorization basis

This list names the third parties (the "Sub-processors") that Finalform engages to process personal data on behalf of its customers when providing Autopage. For visitor data processed through the Autopage snippet, Finalform acts as the processor and the Customer is the controller.

This list operates under, and forms part of, the general written authorization that the Customer grants in the Data Processing Agreement (Article 28(2) GDPR). By entering into the Data Processing Agreement, the Customer authorizes Finalform to engage the Sub-processors named below. The Data Processing Agreement governs the notice and objection mechanism that applies before Finalform adds or replaces a Sub-processor (see Section 5).

Each row below states the Sub-processor's identity, role, the personal-data categories it receives, its processing location, and the transfer mechanism, so that the Customer can assess each Sub-processor and exercise the objection right.

The categories of personal data processed by each Sub-processor are also described in the Privacy Policy and the Data Processing Agreement. This list, the Privacy Policy, and the Data Processing Agreement name the same Sub-processors. Recipients that are not Article 28 Sub-processors (such as our external accounting provider / Steuerberater for the statutory billing hold) are addressed separately, not in this Sub-processor table.

2. Sub-processors

Exactly five Sub-processors are authorized. Four receive data today; Stripe begins processing personal data only when paid billing goes live. Railway provides both application hosting and the managed database under a single contracting entity and is shown as one row with both services named.

Sub-processors, service or role, personal data received, hosting region, and transfer mechanism
Sub-processor (legal entity)Service / rolePersonal data receivedHosting regionTransfer mechanism
Railway Corporation, Delaware, USApplication hosting and compute (engine API and web dashboard) and managed PostgreSQL primary databaseAll processed and persisted personal data: pseudonymous visitor session identifier and behavioral events, customer account data, billing metadata. The raw visitor IP address transits the Railway edge and proxy layer and may appear in provider access logs (infrastructure layer); no Autopage application code stores it.Amsterdam, Netherlands (europe-west4-drams3a). All production services and the database volume, verified in the Railway control plane on 2026-07-30. The Railway workspace default region is set to the same EU region, so newly created services inherit it.EU residency at rest only. Data at rest is in the EU. That establishes where the data rests and not the absence of a Chapter V transfer, because the same data is reached by the leg below. A United States processing leg remains and is a third-country transfer: Railway Corporation is a US entity, and the Railway data processing addendum states that its primary processing operations take place in the United States and that the transfer of personal data to the United States is necessary to provide the services. For that leg the addendum provides that transfers out of the EEA occur under the EU-US Data Privacy Framework (DPF) where the recipient is certified, and otherwise under the EU Standard Contractual Clauses (SCCs), which the addendum deems entered into and incorporates by reference (Module Two, controller to processor), with a transfer impact assessment maintained for that leg regardless of which of the two applies. Railway states it is certified under the EU-US DPF, the UK Extension, and the Swiss-US DPF.
Anthropic, PBC, Delaware, USLarge language model that generates and rewrites landing-page copyNo per-visitor personal data. Only the customer's optimization brief, baseline page copy, and population-level aggregate metrics (rates and medians) are sent. Direct identifiers are stripped; no session identifier, IP address, or raw visitor event reaches a prompt. No prompt or response content is logged by Finalform (only token-count telemetry).United States (api.anthropic.com, no region override). Anthropic does not commit to the United States alone: its privacy policy states that data goes to its servers in the US, or to other countries outside the EEA and the UK.Third-country transfer on Article 46 SCCs plus a transfer impact assessment (TIA). Anthropic makes no DPF claim: its privacy policy states that it relies on standard contractual clauses to transfer information to certain affiliates and third parties in countries without an adequacy decision.No training: yes. Anthropic does not train its models on inputs or outputs submitted through the commercial API (Anthropic Commercial Terms). The one customer-controllable exception, the setting that would send full prompts and responses for future model improvements, is switched off (verified 2026-07-30).Retention: 30 days, not zero. Zero Data Retention is not enabled. Inputs and outputs are retained by Anthropic for 30 days and may be accessed by Anthropic for safety and security purposes. Because no per-visitor personal data reaches a prompt, direct identifiers are stripped, and Finalform logs no prompt or response content, that window covers optimization briefs, baseline page copy, and population-level aggregates, not visitor data.
Cloudflare, Inc., Delaware, USBrowser Rendering API that renders the customer's single-page-application landing page during the baseline scrapeOnly the customer's public landing-page URL; the API returns rendered HTML. No visitor personal data and no account data are sent.United States (api.cloudflare.com, anycast)Third-country transfer on DPF certification. Cloudflare states that it relies on its certifications under the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework, and the UK Extension, with SCCs plus supplementary measures as the fallback if a certification lapses, and a transfer impact assessment maintained either way. The Cloudflare data processing addendum forms part of the main agreement and takes effect with it, so it is incorporated by reference through the subscription and needs no separate signature; it covers all cloud-based solutions offered by Cloudflare without enumerating Browser Rendering by name.
Stripe Payments Europe, Limited, IrelandPayments: Checkout, Customer Portal, subscription management, webhooks. Payment processor, not merchant of record; Finalform is the legal seller.Customer billing email and name, organization-id metadata, subscription and transaction data. Card and PAN data go directly to Stripe-hosted pages; Finalform stores no card data.European Union for the contracting leg, with onward processing in the United StatesThe contracting leg is intra-EEA, on the recipient test rather than on a storage fact: the Stripe Services Agreement assigns accounts located outside North and South America to Stripe Payments Europe, Limited. Finalform is a German GmbH, so the contracting entity follows from the agreement rather than from an account-by-account choice. Stripe's onward processing in the United States is a third-country transfer resting on Stripe's own safeguards; Stripe states it is DPF-certified.
Resend: Plus Five Five, Inc., USTransactional email: verification, magic-link, password reset, invitations, and service notificationsRecipient customer email address and email content (subject and HTML body), and the recipient name in templates.United States (api.resend.com, no region override)Third-country transfer on DPF certification. Plus Five Five, Inc. states that it has self-certified to the U.S. Department of Commerce under the EU-US Data Privacy Framework, with SCCs plus TIA as the fallback.

Transmission boundary. The customer-side snippet transmits behavioral and event data only to the first-party Autopage API; it calls no third party directly. Every third-party transfer of visitor data takes place server-side from the Autopage engine, never browser-to-vendor. This supports Finalform's role as processor and the Customer's role as controller.

Providers that are not Sub-processors. The following are not active recipients and are therefore not listed: OpenAI (not integrated; Anthropic is the sole language-model provider), Keak (not integrated), Google OAuth (not enabled), error-monitoring and third-party analytics services (not active), Cloudflare Turnstile (not active, distinct from the active Browser Rendering above), and object storage. If any of these becomes active, it will be added to this list under the change-notification process in Section 5. Object storage is dormant at launch.

3. International transfers

Where the data rests. All personal data that Autopage persists, including the pseudonymous visitor session identifier and behavioral events, is stored in the European Union: the managed PostgreSQL database and every production service run in Railway's Amsterdam region (europe-west4-drams3a), verified on 2026-07-30. That establishes EU residency at rest only. It does not establish the absence of a Chapter V transfer: Railway's separate US processing and access leg reaches the same data and remains a third-country transfer, covered by the safeguards set out below.

That is not the same as saying no personal data leaves the EEA, and Finalform does not claim it. Two things remain:

  1. The hosting provider, Railway Corporation, is a US entity whose data processing addendum states that its primary processing operations take place in the United States and that the transfer of personal data to the United States is necessary to provide the services. A US processing leg therefore persists alongside the EU storage location, and the raw visitor IP address transits Railway's edge and proxy layer.
  2. The language-model provider (Anthropic), the page-render API (Cloudflare), and the transactional email provider (Resend) process data outside the EEA.

For each transfer outside the EEA, Finalform relies on an appropriate safeguard under Chapter V GDPR:

  • EU-US Data Privacy Framework (DPF) adequacy, where the recipient entity is certified under the DPF. The transfer then relies on the European Commission's adequacy decision for the DPF.
  • Standard Contractual Clauses (SCCs) plus a transfer impact assessment (TIA), where the recipient is not DPF-certified or makes no DPF claim. The TIA evaluates the legal regime in the recipient country and the supplementary measures in place.

Per-recipient position, resolved from vendor primary sources on 2026-07-30:

  • Railway: data at rest in the EU (Amsterdam), which establishes EU residency at rest only. The residual US processing leg remains a third-country transfer, and for it the Railway addendum applies the DPF where the recipient is certified, and otherwise the EU SCCs, which the addendum deems entered into and incorporates by reference (Module Two), with a transfer impact assessment maintained for that leg either way. Railway states it is DPF-certified.
  • Anthropic: third-country transfer on SCCs plus TIA. Anthropic makes no DPF claim and states that it relies on standard contractual clauses for countries without an adequacy decision, and that data goes to its US servers or to other countries outside the EEA and the UK, so the position is not limited to the United States. The exposure is mitigated by the data-minimisation posture: no per-visitor data, direct identifiers stripped, no prompt or response content logged by Finalform. Anthropic does not train on commercial API inputs or outputs, and retains inputs and outputs for 30 days (see row 2; Zero Data Retention is not enabled).
  • Cloudflare (US): third-country transfer on DPF certification, with SCCs plus supplementary measures as the fallback. This is the lowest-exposure recipient, since only a public URL leaves Finalform's systems.
  • Stripe: the contracting entity is Stripe Payments Europe, Limited (Ireland), which the Stripe Services Agreement assigns to accounts located outside North and South America. The billing leg is therefore intra-EEA, on the recipient test rather than on a storage fact; Stripe's onward processing in the United States is a third-country transfer resting on Stripe's own safeguards, and Stripe states it is DPF-certified.
  • Resend (US): third-country transfer on DPF certification (Plus Five Five, Inc. self-certified with the U.S. Department of Commerce), with SCCs plus TIA as the fallback.

The recipients that remain third-country, and for which Finalform maintains an SCC reference and a short-form TIA, are Anthropic, Cloudflare, Resend, and Railway for its residual US processing leg.

On request, Finalform will disclose in advance the recipient country and the Article 44 et seq. transfer mechanism for any Sub-processor, and will make a copy of the relevant safeguards (including the SCCs) available to the Customer through the contact details in the Privacy Policy.

4. Flow-down and residual liability

Finalform imposes on each Sub-processor data-protection obligations that are equivalent to those agreed with the Customer in the Data Processing Agreement, in particular under Article 28(4) GDPR. Where a Sub-processor fails to fulfil its data-protection obligations, Finalform remains fully liable to the Customer for the performance of that Sub-processor's obligations.

On the end of the provision of services, Finalform instructs each Sub-processor to delete or return the Customer's personal data on the same basis as set out in the Data Processing Agreement.

5. Change notification and objection

This list operates under the general written authorization in the Data Processing Agreement (Section 1). Finalform may add or replace Sub-processors as Autopage evolves, subject to the following:

  • Advance notice. Finalform gives affected Customers at least 30 days' advance notice before a new or replaced Sub-processor begins processing personal data, by email to the registered account holder and by an in-app notice, and by updating this list with a new effective date and version.
  • Objection. Within an appropriate period after notice, the Customer may object to the change on reasonable, data-protection-related grounds. German supervisory guidance reads the appropriate objection period as typically up to about two weeks; this objection period is distinct from the 30-day advance-notice period and runs in parallel within it.
  • Consequence of objection. If the Customer does not object within the period, the change is deemed approved. If the Customer raises a justified objection on data-protection grounds that the parties cannot resolve, the Customer may terminate the affected part of the service without penalty.

6. Cookie and storage disclosure

This list covers Sub-processors that process personal data on behalf of Customers. For information on the cookies and device storage used on Finalform's own websites, see the Cookie and Storage Policy.