Legal
Subprocessor List
Providers Cloudlayer appoints to process customer or visitor data, plus customer-directed destinations and change-notice terms.
How are providers selected and changed?
Cloudlayer uses the providers below to deliver, secure, support, and operate the Service. A provider appears here when Cloudlayer appoints it to receive personal data for a production Service role. The list identifies the provider, service, role, categories of data, processing locations, and provider notice.
The Data Processing Addendum gives Cloudlayer general authorization to appoint subprocessors, requires written data-protection obligations, and describes notice and objection rights. A customer that needs change notice should use the legal or privacy contact in its order or email privacy@cloudlayer.io.
Cloudlayer reviews a provider before activation and when its product scope or data flow materially changes. Listing a provider does not assert that every product offered by that provider is used, covered by a certification, eligible for regulated data, or available in every region. The Privacy Notice explains recipients and transfers, and the Security page records the evidence-backed security posture.
Customer-directed destinations are disclosed separately below because the customer selects the provider, account, endpoint, and region. Cloudlayer transmits data there only when the customer configures the destination.
Cloudlayer-appointed subprocessors
This inventory was reviewed on August 13, 2026. Contractual notice and objection rights are governed by the Data Processing Addendum.
DigitalOcean application and data platform
- Provider
- DigitalOcean, LLC
- Role
- Runs Cloudlayer application services, managed PostgreSQL and Valkey, object storage, container images, private networking, monitoring, and render workloads.
- Data
- account, organization, and workspace data; templates, forms, submissions, signatures, and generated output; job payloads, service metadata, logs, and audit events
- Locations
- The United States service region configured by Cloudlayer, with provider support and resilience processing described by DigitalOcean.
Firebase Authentication and Firebase AI
- Provider
- Google LLC
- Role
- Authenticates users and processes the prompts and selected source content sent when a customer invokes an AI feature.
- Data
- account and authentication data; AI prompts and content when an AI feature is used; AI output and feature metadata
- Locations
- Google Cloud regions selected for the service, with support and resilience processing described by Google.
Cloudflare Workers and KV
- Provider
- Cloudflare, Inc.
- Role
- Delivers and protects the app, marketing site, and MCP service at the edge and stores MCP authorization state.
- Data
- network and request metadata; IP addresses and security signals; MCP authorization and OAuth metadata
- Locations
- Cloudflare global network, subject to the regional controls and transfer terms in its DPA.
Stripe payments and billing
- Provider
- Stripe, LLC
- Role
- Processes hosted payment entry, subscriptions, invoices, tax identifiers, and billing lifecycle events.
- Data
- billing contact and account identifiers; payment and subscription metadata; payment-card data entered directly into Stripe-hosted controls
- Locations
- United States and other locations used by Stripe and its service providers.
Mailchimp audience management
- Provider
- Mailchimp
- Role
- Adds a new customer email address to the Cloudlayer product-communication audience.
- Data
- email address and subscription status
- Locations
- United States and other locations identified in Mailchimp’s subprocessor notice.
Twilio SendGrid transactional email
- Provider
- Twilio Inc.
- Role
- Delivers account, billing, usage, and security-related transactional email.
- Data
- recipient email address; message subject and HTML body
- Locations
- United States and other locations identified in Twilio’s subprocessor notice.
Google Analytics
- Provider
- Google LLC
- Role
- Measures visits and product-feature use only after analytics consent.
- Data
- online identifiers, device and visit activity, and feature-use events
- Locations
- Google’s global analytics infrastructure under its applicable data-processing terms.
Crisp support chat
- Provider
- CRISP IM SAS
- Role
- Provides in-page customer support only after support consent.
- Data
- chat content and contact details a visitor sends; signed-in account, plan, and billing identifiers used to assist the customer
- Locations
- France and locations used by the subprocessors identified by Crisp.
Customer-directed destinations
These recipients are selected and configured by a customer. Cloudlayer does not appoint them as subprocessors for every customer.
S3-compatible storage or Google Cloud Storage
- Recipient
- Customer-selected storage provider
- Role
- Receives generated output only when the customer configures that destination.
- Data
- generated documents or images and their object metadata
- Locations
- The region and provider selected by the customer.
Job-completion webhook endpoint
- Recipient
- Customer-selected webhook operator
- Role
- Receives job completion or failure notifications at the endpoint the customer configures.
- Data
- job identifiers, status, output reference, and error metadata
- Locations
- The endpoint and hosting region selected by the customer.