Compliance
Subprocessors
These services process personal data on our behalf. Region and DPA status per service reflect our EU-resident infrastructure (Frankfurt, FRA1).
DigitalOcean (Managed Database)
managed-postgresEU-resident- Purpose
- Hosting of the application database (Postgres 16 + pgvector) incl. OKR data, legal documents and anonymized form submissions.
- Region
- EU · Frankfurt (FRA1)
- DPA
- DigitalOcean DPA
DigitalOcean (Spaces)
object-storageEU-resident- Purpose
- Object storage for document/file assets (S3-compatible, private).
- Region
- EU · Frankfurt (FRA1)
- DPA
- DigitalOcean DPA
DigitalOcean (App-Runtime)
app-runtimeEU-resident- Purpose
- Operation of the application runtime (Next.js/Payload process incl. consent gate and submit handler).
- Region
- EU · Frankfurt (FRA1)
- DPA
- DigitalOcean DPA
EU-Mail-Provider
mailEU-resident- Purpose
- Sending transactional notifications (e.g. form receipt, invitations).
- Region
- EU
- DPA
- DPA with EU email provider
KI-Anbieter (EU-Inferenz)
ai-providerEU-resident- Purpose
- AI inference for the OKR coach (production only with BYOK/EU fallback; locally a keyless mock, no egress).
- Region
- EU region pinned (fail-closed)
- DPA
- DPA per provider (in preparation)
KI-Anbieter (Fallback)
ai-provider- Purpose
- AI inference for the OKR coach is disabled unless an organisation's own API key is configured (must be explicitly enabled in organisation settings).
- Region
- Global (Non-EU)
- DPA
- OpenAI DPA