Subprocessor schedule
Effective Date: pending activation (not set reserved for release).
Last Updated: pending activation (not set reserved for release).
Draft prepared: 6 October 2026. Complete deployment particulars before this schedule becomes DPA Annex C.
Draft revised: 7 October 2026. Activation remains pending.
Non-binding summary. These services are active. Their roles differ: some process project data, while others handle payments, login, email or measurement. Each customer subprocessor needs completed contractual and processing particulars before authorisation. This summary is outside the operative schedule.
1. Supplier roles
1.1. “Subprocessor” means a recipient appointed to process customer-controlled personal data on OwlMeans’ behalf under the DPA. Account/payment services may instead process OwlMeans-controlled data or act independently; their inclusion does not make them universal customer subprocessors. Contact: Igor Tkachenko OwlMeans Software (trading as “OwlMeans Software, JDG”), NIP 6772507251, EU VAT identifier PL6772507251, REGON 527979906, ul. Ariańska 9/5, 31-505 Kraków, Poland; support@owlmeans.com; telephone +48 780 256 571.
| Service and identified operator | Current status, use and data | Role and location status |
|---|---|---|
| Hetzner; published operator Hetzner Online GmbH, actual service contract to verify | Operator-confirmed sole infrastructure provider: workloads, databases, repositories and operational records; backup service particulars to verify | Customer subprocessor where hosting customer-controlled data. Actual data-centre countries, backup locations, contract and retention unresolved. |
| Mailgun; actual Sinch Email contracting entity shown on the service order to verify | Operator-confirmed email delivery: recipients, OTP, service/legal notifications and message content | Processor role depends on the message/data. Stage EU SMTP endpoint is evidenced; actual account region, onward processing and retention unresolved. |
| Google Gmail; actual Google contracting entity and account/service terms to verify | Operator-confirmed company receiving mailbox on 7 October 2026: inquiries, contact/routing/receipt evidence, correspondence and selected attachments | OwlMeans controller-facing mailbox processing. Any instructed customer-controlled support data requires completed DPA/subprocessor particulars. Actual account/service, contractual role, authorised access, countries, retention, DPA and transfer safeguards unresolved. |
| Google Tag Manager / Google Analytics; contracting entity to verify | Operator-confirmed measurement: consent-gated browser/network identifiers and configured events; no Google Ads | OwlMeans controller-facing optional measurement, not universal project-content processing. Actual account settings, measurement tags, destinations and retention unresolved. |
| Sentry; published operator Functional Software, Inc. d/b/a Sentry, actual account contract to verify | Operator-confirmed diagnostics: errors, request/context and identifiers as actually configured | Customer subprocessor where diagnostic content contains customer-controlled data; otherwise OwlMeans controller processing. SDK scope, redaction, replay, locations and retention unresolved. |
| OpenAI; actual contracting entity to confirm | Operator-confirmed active AI inference/fallback: prompts, selected context, request/output data for calls using this service | Customer subprocessor where processing instructed customer personal data; controller-facing roles separately assessed. Actual account, regions, retention and transfer basis unresolved. |
| Anthropic; published EEA commercial counterparty Anthropic Ireland, Limited; actual account to verify | Operator-confirmed active AI inference: prompts, selected context and request/output data | Customer subprocessor where processing instructed customer personal data. Irish contracting entity does not establish EU-only processing; actual account, retention and transfer particulars unresolved. |
| OpenRouter; actual contracting entity to confirm | Operator-confirmed active AI routing/model access: selected inference requests and related metadata | Routing can add an underlying model recipient. Identify the actual route and onward recipient before customer-data authorisation; locations, retention and safeguards unresolved. |
| Together AI; actual contracting entity to confirm | Operator-confirmed active model/inference service: selected requests and related data | Customer subprocessor where processing instructed customer personal data; actual service, account entity, locations, retention and safeguards unresolved. |
| Hugging Face; actual contracting entity to confirm | Operator-confirmed active model access/integration; downloads expose connection/model-request metadata, while hosted inference can receive selected prompts/context | Distinguish download-only access, customer-selected/local models and hosted inference. Do not infer that downloading a model sends project data. Actual product/endpoint, role, locations and contractual particulars unresolved. |
| Cloudflare; actual contracting affiliate to confirm | Operator-confirmed active network/domain/security functions: connection/request data and content to the extent the configured service carries it | Role depends on the actual service. Hetzner remains the operator-confirmed infrastructure provider; active Cloudflare use does not establish a separate storage arrangement. Edge handling, logs, account entity and DPA particulars unresolved. |
| GitHub; actual contracting entity to confirm | Operator-confirmed active repository/OAuth operations: authorised identities, permissions, tokens and repository data | Customer-controlled connection versus OwlMeans processor role must be identified; not automatically appointed for all projects. Actual account, locations and safeguards unresolved. |
| Stripe; actual contracting entity to confirm | Operator-confirmed active payments: payment credentials, transaction, billing and anti-fraud information | Payment roles and retained evidence depend on actual services/contracts; no routine project-content recipient established. Account entity, locations and retention unresolved. |
| Google reCAPTCHA; actual Google Cloud contracting entity to verify | Operator-confirmed active on 7 October 2026: bot, fraud and abuse prevention; connection/browser/device and challenge signals, verification tokens and assessment results as exposed by the selected integration | Google processes reCAPTCHA Customer Data as a processor under the applicable Google Cloud terms. For OwlMeans account/website security this is controller-facing processing; it is a customer subprocessor only for customer-controlled data processed on instructions. Actual entity, configuration, locations, retention and transfer safeguards require completion. |
| Google sign-in; account/service entity to confirm | Operator-confirmed active identity service: authorised login identity/profile and authentication information | Distinct from Google measurement. Actual login fields/scopes, account/service entity, locations and role require completion. |
2. Selected routes and approval conditions
2.1. The operator confirmed current use of the previously listed services during the 6 October 2026 provider review and added Google reCAPTCHA on 7 October 2026. A route can involve more than one recipient, and an active service is not selected for every request. Customer-selected/local inference and generated-application integrations must be assessed individually; supported adapters do not themselves grant processing permission. Deployment configuration and contractual particulars remain separate from confirmation of service use. Google Ads, personalised marketing profiling, partner marketing and independent improvement/training are inactive Platform purposes.
2.2. For each active subprocessor, the release schedule shall state its actual legal entity, service, data categories, countries/regions, retention, Chapter V mechanism and any supplementary safeguards. Supplier public terms do not prove execution of a DPA or SCCs. No unresolved row authorises a restricted transfer. Model-output reuse for own training requires separate supplier-rights clearance; customer consent alone is insufficient.
2.3. The configured website and Platform inquiry flow uses Hetzner infrastructure for the separate inquiry database and delivery queue, and Mailgun to transport the message, contact/routing evidence and selected attachments to OwlMeans’ Google Gmail mailbox. Gmail receives and stores that correspondence and its attachments for company request handling. Google reCAPTCHA processes security signals for that protected flow; consent-gated Google measurement may receive the dialog-opening event and its widget/topic/trigger fields, rather than the form’s email, text or files. The receiving Gmail account/service, actual Google contracting entity, contractual role, authorised access, countries, retention, DPA, transfer safeguards and onward handling must be verified separately from Mailgun delivery before activation. Messenger/video examples in a form do not establish active integrations or authorised recipients. Inquiries are OwlMeans controller processing for its own contact administration; customer data handled on support instructions requires the corresponding DPA/subprocessor particulars. No inquiry contents are automatically routed to the listed AI suppliers or optional improvement/training datasets by this service.
3. Changes and regional rights
3.1. The DPA governs advance supplier-change notice, objections, equivalent obligations and OwlMeans’ responsibility. Obtain current recipient/safeguard information at support. Controller-facing services and optional tracking follow the Privacy and Cookie notices. EU/EEA and applicable UK transfer rules, US state roles and mandatory data-subject rights remain preserved; no universal adequacy or EU-residency promise is made.