Working draft — not yet legally reviewed

This page is HostPal's engineering-drafted statement of intent and is published in good faith. It has not been reviewed by licensed counsel and may not reflect every legal nuance of your jurisdiction. For a binding answer to a specific question, please contact [email protected].

Sub-processors

Version: 2026-05-21 · Last changed: 2026-05-21

To subscribe to email notifications about future changes, email [email protected]. Material changes are announced at least 30 days in advance per GDPR Art. 28(2). You may object to a change by emailing [email protected] within the notice window.

Sub-processorPurposeDataLocationSafeguards
MongoDB AtlasPrimary databaseAll Host and Guest dataEU (Frankfurt)At-rest encryption (AES-256), SOC 2 Type II, signed DPA + SCCs
CloudflareCDN, R2 file storage, WAF, DDoS protectionHost-uploaded files, public assets, edge cacheGlobal edgeDPA + SCCs
TwilioWhatsApp + SMS routingGuest phone numbers, message contentsUSDPA + SCCs
Telegram (Bot API)Telegram messaging channelGuest Telegram IDs, message contentsGlobal (Telegram FZ-LLC, Dubai)Telegram does not publish a GDPR DPA. Treated as independent controller of transport metadata. Hosts can choose WhatsApp-only at property setup for EU-sensitive deployments.
OpenRouterLLM routing gatewayPrompt contents (Guest messages + Host context)USDPA; routes to OpenAI / Anthropic / Google AI per model selection
OpenAILLM inference + Whisper voice transcriptionPrompt contents, voice audioUSZero data retention agreement for API; DPA + SCCs
AnthropicLLM inferencePrompt contentsUSNo training on API traffic by default; DPA + SCCs
Google AI / GeminiLLM inference (fallback)Prompt contentsUS / EUDPA + SCCs
StripeBilling + paymentsHost name, email, billing address, card tokenUS / IEPCI-DSS Level 1, DPA + SCCs
ResendTransactional emailHost email, account event contentUSDPA + SCCs
SentryError monitoringStack traces, server logs (PII scrubbed at SDK)EUDPA + SCCs
PostHogProduct analytics (consent-gated)Anonymised event data, truncated IPEUDPA
Google Analytics 4Web analytics (consent-gated)Truncated IP, page eventsUSDPA + SCCs
Microsoft ClaritySession replay sampled for UX research (consent-gated)UI interaction data, IPUSDPA + SCCs

Changelog