Sub-processors
How to read this list
These are the third parties ewpire engages to process personal data on behalf of its customers (the controllers) in delivering the Service. For cookieless website measurement ewpire uses Cloudflare Web Analytics (a function of Cloudflare, row 1), which stores nothing on the visitor's device. For product and funnel analytics it uses PostHog (row 7, EU Cloud), loaded only after the visitor accepts the Analytics cookie category; PostHog then stores an anonymous identifier in the browser's local storage (no advertising cookie). It also engages an error-monitoring processor (Sentry, row 6) under legitimate interest for security and reliability; this is not analytics and sets no cookie. Payment-card data is handled by Stripe under its own terms.
Infrastructure and operations
| # | Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|---|
| 1 | Cloudflare, Inc. | User-site hosting (Pages/Workers) for generated MVPs and AEO/GEO presence; CDN, DDoS protection, edge compute and EU storage | US / EEA edge | EU edge/storage intra-EEA; SCC Module 2 + DPF where the recipient is certified, for any US leg |
| 2 | Daytona | Sandboxed build runtime for Validation (ephemeral, per-build) | SCC Module 2 + TIA if non-EEA; intra-EEA if EEA region | |
| 3 | Hetzner Online GmbH | VPS hosting ewpire's own consensus engine and Python worker (not user apps) | Germany (EEA) | Intra-EEA |
| 4 | Stripe Payments Europe Limited and/or other Stripe entities as applicable | Billing, subscription and credit-pack payments, and Connect Express referral payouts (Stripe acts as an independent controller for payment data) | Ireland (EEA) + US | Intra-EEA; controller-to-controller (Module 1) / DPF for the US Stripe entities; onward transfers under Stripe's own safeguards |
| 5 | Resend, Inc. | Transactional email | US | SCC Module 2 + DPF where certified |
| 6 | Functional Software, Inc. (dba Sentry) | Application error and performance monitoring (captures error/exception events, which may include IP address and technical request/session context) | EU data residency (Frankfurt, de.sentry.io); operator US | EU-region storage intra-EEA; SCC Module 2 + DPF where certified for any US support access |
| 7 | PostHog, Inc. (EU Cloud) | Product and funnel analytics (page views, product events); personal data processed only after the visitor accepts the Analytics cookie category; an anonymous identifier is stored in local storage (no advertising cookie) | EU Cloud (Frankfurt); operator US | EU-region storage intra-EEA; SCC Module 2 + DPF where certified for any US parent access |
Consensus LLM inference
These providers perform inference on controller inputs (idea text, interview answers, brand/site content, prompts, and in Validation generated code). All are engaged on a no-training / no-model-improvement basis. Because the consensus primitive selects the best model per task, a given input is transmitted only to the subset engaged for that deliberation.
| # | Sub-processor | Location | Transfer mechanism |
|---|---|---|---|
| 8 | Anthropic, PBC | US | SCC Module 2 + DPF where certified |
| 9 | OpenAI, L.L.C. | US | SCC Module 2 + DPF where certified |
| 10 | Google LLC (LLM inference only – not website analytics) | US | SCC Module 2 + DPF where certified |
| 11 | Alibaba Cloud (Qwen) | Singapore | SCC Module 2 + TIA |
| 12 | Mistral AI SAS | France (EEA) | Intra-EEA |
| 13 | DeepSeek | China | Off by default – see China note |
| 14 | Zhipu AI (GLM) | China | Off by default – see China note |
| 15 | OpenRouter, Inc. | US | SCC Module 2 / Module 3 for the onward routed lab, under equivalent safeguards |
China-provider note. DeepSeek and Zhipu AI (GLM) are established in the People's Republic of China, which has no EU adequacy decision. They are disabled by default; ewpire routes data to them only on explicit opt-in or after pseudonymisation such that no directly-identifying personal data leaves the EEA, and an account may permanently exclude China-based providers at no cost.
Change notice
ewpire gives advance notice before adding or replacing a sub-processor: at least 30 days for a new non-EEA sub-processor (which materially changes the transfer-risk profile), and at least 14 days for a new EEA sub-processor or a like-for-like replacement. Controllers may object under DPA §4.2; an unresolved objection entitles the controller to terminate with a pro-rata refund of prepaid, unused credits.