Subprocessors
Version 1.0 · As of 30 September 2026
This page forms Annex 3 of our Data Processing Agreement. We announce changes at least 30 days in advance by e-mail to customers and on this page (section 5 of the DPA).
1. Subprocessors for customer data
These providers process personal data on behalf of our customers (in particular data of end customers who use the configurator).
| Provider | Purpose | Data location | Transfer mechanism |
|---|---|---|---|
| Cloudflare, Inc., San Francisco, USA | Delivery of the configurator and website (CDN), serverless functions (license and domain check, signed asset links, API), object storage (3D assets, renders, uploaded files), DDoS protection | Global network; storage region [R2 location, e.g. EU jurisdiction] | EU Standard Contractual Clauses (Module 3); EU-U.S. Data Privacy Framework where certified |
| Google Ireland Limited / Google Cloud EMEA Limited, Dublin, Ireland (Firebase) | Authentication (Firebase Authentication), database (Cloud Firestore), file storage (Cloud Storage for Firebase) | Region [e.g. europe-west3, Frankfurt]; possible access by Google LLC, USA | EU-U.S. Data Privacy Framework (Google LLC certified); EU Standard Contractual Clauses |
| Google Cloud EMEA Limited, Dublin, Ireland (Google Workspace) | E-mail notifications about new configurations and enquiries; support correspondence | EU/USA | EU-U.S. Data Privacy Framework; EU Standard Contractual Clauses |
| [Render provider – not yet in use] | Photoreal renders and video export (only configuration data, no contact data) | – | Will be announced 30 days before first use |
2. Other service providers (not processing customer data)
These providers process personal data for our own purposes (billing, sales, communication), for which we are the controller. They have no access to end customer data of our customers.
| Provider | Purpose | Role | Transfer mechanism |
|---|---|---|---|
| Stripe Payments Europe, Limited, Dublin, Ireland | Checkout, subscription billing, invoices, customer billing portal | Processor; independent controller for fraud prevention and financial regulation | EU-based; transfers to Stripe, Inc. (USA) under DPF / SCC |
| Foo Monk, LLC dba Instantly.ai, Sheridan, Wyoming, USA | Sending business outreach e-mails from thesettinglab.com | Processor | EU Standard Contractual Clauses; DPF where certified |
| Google Cloud EMEA Limited, Dublin, Ireland (Google Workspace) | Our business e-mail and documents | Processor | DPF; EU Standard Contractual Clauses |
3. Jurisdiction and government access (Art. 28 Data Act)
We are established in Germany and subject to EU and German law. Our infrastructure providers Cloudflare and Google are US companies or group companies of US companies and may be subject to US law, including laws allowing access by US authorities. To protect against unlawful access by governments outside the EU, we rely on: encryption of all data in transit and at rest; storage of customer data in EU regions where the provider offers this; contractual commitments of our providers to challenge unlawful requests and to inform customers where legally permitted; data minimisation (no special categories of data, no IP addresses in the database). We will inform affected customers of any request from a non-EU authority for customer data unless the law prohibits this.
4. Notification of changes
Customers receive an e-mail to the address stored in their account at least 30 days before a new subprocessor is engaged. The date and version at the top of this page show the last change.