TheSetting Lab Get Started
Legal

Subprocessors

Version 1.0 · As of 30 September 2026

This page forms Annex 3 of our Data Processing Agreement. We announce changes at least 30 days in advance by e-mail to customers and on this page (section 5 of the DPA).

1. Subprocessors for customer data

These providers process personal data on behalf of our customers (in particular data of end customers who use the configurator).

ProviderPurposeData locationTransfer mechanism
Cloudflare, Inc., San Francisco, USADelivery of the configurator and website (CDN), serverless functions (license and domain check, signed asset links, API), object storage (3D assets, renders, uploaded files), DDoS protectionGlobal network; storage region [R2 location, e.g. EU jurisdiction]EU Standard Contractual Clauses (Module 3); EU-U.S. Data Privacy Framework where certified
Google Ireland Limited / Google Cloud EMEA Limited, Dublin, Ireland (Firebase)Authentication (Firebase Authentication), database (Cloud Firestore), file storage (Cloud Storage for Firebase)Region [e.g. europe-west3, Frankfurt]; possible access by Google LLC, USAEU-U.S. Data Privacy Framework (Google LLC certified); EU Standard Contractual Clauses
Google Cloud EMEA Limited, Dublin, Ireland (Google Workspace)E-mail notifications about new configurations and enquiries; support correspondenceEU/USAEU-U.S. Data Privacy Framework; EU Standard Contractual Clauses
[Render provider – not yet in use]Photoreal renders and video export (only configuration data, no contact data)–Will be announced 30 days before first use

2. Other service providers (not processing customer data)

These providers process personal data for our own purposes (billing, sales, communication), for which we are the controller. They have no access to end customer data of our customers.

ProviderPurposeRoleTransfer mechanism
Stripe Payments Europe, Limited, Dublin, IrelandCheckout, subscription billing, invoices, customer billing portalProcessor; independent controller for fraud prevention and financial regulationEU-based; transfers to Stripe, Inc. (USA) under DPF / SCC
Foo Monk, LLC dba Instantly.ai, Sheridan, Wyoming, USASending business outreach e-mails from thesettinglab.comProcessorEU Standard Contractual Clauses; DPF where certified
Google Cloud EMEA Limited, Dublin, Ireland (Google Workspace)Our business e-mail and documentsProcessorDPF; EU Standard Contractual Clauses

3. Jurisdiction and government access (Art. 28 Data Act)

We are established in Germany and subject to EU and German law. Our infrastructure providers Cloudflare and Google are US companies or group companies of US companies and may be subject to US law, including laws allowing access by US authorities. To protect against unlawful access by governments outside the EU, we rely on: encryption of all data in transit and at rest; storage of customer data in EU regions where the provider offers this; contractual commitments of our providers to challenge unlawful requests and to inform customers where legally permitted; data minimisation (no special categories of data, no IP addresses in the database). We will inform affected customers of any request from a non-EU authority for customer data unless the law prohibits this.

4. Notification of changes

Customers receive an e-mail to the address stored in their account at least 30 days before a new subprocessor is engaged. The date and version at the top of this page show the last change.