Complete list of third-party vendors that process personal data on behalf of Stepcode SRL in the provision of the Supportfast.ai service, with detail on purposes, data location and legal bases for extra-EU transfers.
Stepcode SRL relies on selected third-party vendors to deliver the Supportfast.ai software and services. Each vendor is bound by agreements pursuant to Article 28 GDPR and selected on the basis of documented criteria of reliability, security and compliance.
This page reflects in real time the sub-processors actually in use. It is the authoritative reference point provided for by our Data Processing Agreement, Section 8. Any material change (addition or replacement of a sub-processor) is communicated to Customers with 30 days prior notice, during which the Customer may object on legitimate and documented grounds.
The platform supports two modes of use of artificial intelligence models. The distinction has material legal consequences on the qualification of AI providers as sub-processors.
The Customer uses AI models through API keys managed by Stepcode. In this case, AI providers (currently OpenAI; any future providers listed in Section 2) are sub-processors of Stepcode pursuant to Article 28 GDPR, bound by the relevant DPAs and by the prohibition on using data for model training.
The Customer may configure its Chatbots using an API key in its own name toward an AI provider (e.g. the Customer’s own corporate OpenAI key). In this case:
Vendors essential to the basic operation of the service. They are active for every Customer, regardless of the specific modules used.
| Vendor | Location | Purpose | Data location | Transfer basis | DPA |
|---|---|---|---|---|---|
| Hetzner Online GmbH | Nuremberg, Germany | Hosting of the main application infrastructure (servers, databases) | Germany (EU) | Intra-EU | Link |
| Amazon Web Services EMEA SARL | eu-central-1 Frankfurt | Storage and CDN for cdn.supportfast.ai | Germany (EU) | Intra-EU | Link |
| Cloudflare, Inc. | San Francisco, USA | CDN, Web Application Firewall, anti-DDoS, SSL | USA / global PoP network | DPF | Link |
| Stripe Payments Europe Ltd. | Dublin, Ireland | Payment processing, subscription management, billing | Ireland (EU) — USA group | SCC + DPF | Link |
| Acumbamail S.L. | Cuenca, Spain | Sending of transactional and marketing e-mails | Spain (EU) | Intra-EU | Link |
| PostHog Inc. | San Francisco, USA — EU region pinning | Product analytics on showcase website and console (usage events) | Frankfurt (EU) | Intra-EU | Link |
| Microsoft Ireland Operations Ltd. | Dublin, Ireland — USA group | Microsoft Clarity (heatmaps, behavioural analysis) on showcase website and console | Ireland + USA | SCC + DPF | Link |
| Vendor | Location | Purpose | Data location | Transfer basis | DPA |
|---|---|---|---|---|---|
| OpenAI, LLC | San Francisco, USA | Language models (LLM) for chatbots and voice — Stepcode mode | USA | DPF | Link |
Stepcode periodically evaluates the integration of further AI providers as alternatives selectable by the Customer in the console. Upon actual activation, each provider will be added to the table above with the relevant effective date, and Customers will receive the 30-day prior notice required by the DPA.
Vendors involved in the processing only if the Customer activates the corresponding channel or feature. If the Customer does not use WhatsApp, for example, Meta receives no data.
| Vendor | Location | Channel / Purpose | Data location | Transfer basis | Terms |
|---|---|---|---|---|---|
| Meta Platforms Ireland Ltd. | Dublin, Ireland + USA | WhatsApp Business API, Instagram Direct, Facebook Messenger | Ireland + USA | SCC + DPF | Link |
Voice architecture: LiveKit Cloud with EU region pinning. The Supportfast voice pipeline uses LiveKit Cloud, the managed service of LiveKit Inc., to orchestrate real-time calls via WebRTC and for the integrated SIP telephony (inbound and outbound numbers). LiveKit Cloud is configured in region pinning mode on the EU region (Belgium): audio, session metadata and SIP routing of the Customer’s calls remain in LiveKit’s European data centres for the entire duration of the call.
By default, LiveKit Cloud does not record or store audio streams: the packets transit in real time and are not persisted. Any recordings, where enabled by the Customer in the console, are sent directly to Stepcode storage (Hetzner EU) and do not remain on LiveKit systems.
Speech recognition (STT) and voice synthesis (TTS) technologies are provided by external vendors listed below, integrated into the LiveKit pipeline.
| Vendor | Location | Role | Data location | Transfer basis | Terms |
|---|---|---|---|---|---|
| LiveKit, Inc. | San Francisco, USA — EU region pinning | LiveKit Cloud: WebRTC orchestration, integrated SIP telephony, EU region | EU (Belgium) | DPF + SCC | Link |
| Deepgram, Inc. | San Francisco, USA | Speech-to-text — real-time audio transcription | USA | DPF | Link |
| ElevenLabs Inc. | New York, USA | Text-to-speech — voice synthesis of Chatbot responses | USA | DPF | Link |
Vendors used by Stepcode SRL for its own internal business operations. They do not process Customer Data (end-user conversational data) but may process B2B Customer contact and billing data. They are listed for transparency, although they do not strictly fall within the sub-processors under Article 28 in relation to the processing of Customer Data.
| Vendor | Purpose | Data location | Transfer basis |
|---|---|---|---|
| Google Ireland Ltd. | Google Workspace — corporate e-mail, internal drive, calendar | Ireland + USA | SCC + DPF |
| Accounting firm | Tax management, accounting, billing, social-security filings | Italy (EU) | Intra-EU |
The tools listed below are installed on the showcase website supportfast.ai for marketing and web statistics purposes. Pursuant to the EDPB and Italian Garante guidelines, these vendors act as autonomous Controllers of the navigation data collected, and not as sub-processors of Stepcode. They are listed for full transparency. Detail of the cookies used is in the Cookie Policy.
Microsoft Clarity and PostHog are instead also used within the authenticated console and act as external Processors of Stepcode (see Section 2 — Core sub-processors).
| Vendor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Google Ireland Ltd. | Google Analytics 4, Google Tag Manager — statistical analysis of the showcase website | Ireland + USA | SCC + DPF |
| Meta Platforms Ireland Ltd. | Meta Pixel — measurement of advertising campaigns and retargeting | Ireland + USA | SCC + DPF |
| Calendly LLC | Booking of demos and commercial meetings by leads | USA | SCC |
| Wistia, Inc. | Hosting and player for the videos embedded in the showcase website | USA | SCC |
The certification status of US vendors to the EU-U.S. Data Privacy Framework can be independently verified on the official register maintained by the U.S. Department of Commerce. The register is updated in real time and also indicates any suspensions or withdrawals of certification.
Official DPF register: dataprivacyframework.gov
Any addition or replacement of a sub-processor is communicated to Customers with at least 30 days prior notice, as provided for in DPA Section 8.4. The communication channels are cumulative: update of this page, in-console notice and for material changes direct e-mail to the registered contact.
During the notice period, the Customer may object to the change on legitimate and documented grounds. In such case, the Parties shall negotiate in good faith a solution; failing agreement, the Customer may withdraw from the Contract without penalty (DPA Section 8.5).
To receive e-mail notice of every change to the list, write to [email protected] indicating the address at which updates should be received.
Chronology of changes to the list of sub-processors. The most recent entries appear at the top. Dates refer to the effective date of the change.
Informal list consisting of OpenAI as the only AI provider, Hetzner for hosting, Cloudflare for CDN/WAF, Stripe for payments, AWS S3 for the CDN, Meta for messaging channels.
Each sub-processor is assessed and periodically reviewed against documented criteria that prioritise Customer data security and compliance with European law.
Review of the main sub-processors is carried out at least once a year and whenever relevant events occur (security incidents, loss of certification, material changes to terms of service).
For any clarification, request for a copy of the DPAs signed with individual sub-processors, request for SCCs, objection to a change or report:
Related documents:
Automated page speed optimizations for fast site performance