🔥 Lite Plan for just €19.00/month! 🔥

Sub-processors

Complete list of third-party vendors that process personal data on behalf of Stepcode SRL in the provision of the Supportfast.ai service, with detail on purposes, data location and legal bases for extra-EU transfers.

Version: 2.3 | Last updated: 19/05/2026 | Contractual reference: DPA Section 8 and Annex A

Stepcode SRL relies on selected third-party vendors to deliver the Supportfast.ai software and services. Each vendor is bound by agreements pursuant to Article 28 GDPR and selected on the basis of documented criteria of reliability, security and compliance.

This page reflects in real time the sub-processors actually in use. It is the authoritative reference point provided for by our Data Processing Agreement, Section 8. Any material change (addition or replacement of a sub-processor) is communicated to Customers with 30 days prior notice, during which the Customer may object on legitimate and documented grounds.

1.“Bring Your Own Key” mode for AI providers

The platform supports two modes of use of artificial intelligence models. The distinction has material legal consequences on the qualification of AI providers as sub-processors.

Mode A: API key managed by Stepcode (default)

The Customer uses AI models through API keys managed by Stepcode. In this case, AI providers (currently OpenAI; any future providers listed in Section 2) are sub-processors of Stepcode pursuant to Article 28 GDPR, bound by the relevant DPAs and by the prohibition on using data for model training.

Mode B: Bring Your Own Key (BYOK)

The Customer may configure its Chatbots using an API key in its own name toward an AI provider (e.g. the Customer’s own corporate OpenAI key). In this case:

  • Conversational data flows directly from the Stepcode system to the AI provider using the Customer’s credentials.
  • The contractual relationship for that specific processing is directly between the Customer and the AI provider, not mediated by Stepcode.
  • Stepcode does not act as Processor for the processing carried out by the AI provider in BYOK mode; the AI provider does not qualify as a sub-processor of Stepcode for that Customer.
  • The Customer is required to independently verify the terms of service, privacy notice and DPA of the chosen AI provider.
  • The other components of the processing carried out by Stepcode (storage, logs, infrastructure) remain unchanged, and Stepcode continues to act as external Processor for them.

2.Core sub-processors

Vendors essential to the basic operation of the service. They are active for every Customer, regardless of the specific modules used.

Infrastructure and service data

VendorLocationPurposeData locationTransfer basisDPA
Hetzner Online GmbHNuremberg, GermanyHosting of the main application infrastructure (servers, databases)Germany (EU)Intra-EULink
Amazon Web Services EMEA SARLeu-central-1 FrankfurtStorage and CDN for cdn.supportfast.aiGermany (EU)Intra-EULink
Cloudflare, Inc.San Francisco, USACDN, Web Application Firewall, anti-DDoS, SSLUSA / global PoP networkDPFLink
Stripe Payments Europe Ltd.Dublin, IrelandPayment processing, subscription management, billingIreland (EU) — USA groupSCC + DPFLink
Acumbamail S.L.Cuenca, SpainSending of transactional and marketing e-mailsSpain (EU)Intra-EULink
PostHog Inc.San Francisco, USA — EU region pinningProduct analytics on showcase website and console (usage events)Frankfurt (EU)Intra-EULink
Microsoft Ireland Operations Ltd.Dublin, Ireland — USA groupMicrosoft Clarity (heatmaps, behavioural analysis) on showcase website and consoleIreland + USASCC + DPFLink

Artificial intelligence models (Stepcode mode)

All AI providers listed below are used exclusively with configurations that exclude the use of transmitted data for model training purposes (zero data retention for training or opt-out from training). This commitment is reflected in the relevant contractual agreements and in our DPA, Section 7.
VendorLocationPurposeData locationTransfer basisDPA
OpenAI, LLCSan Francisco, USALanguage models (LLM) for chatbots and voice — Stepcode modeUSADPFLink

Stepcode periodically evaluates the integration of further AI providers as alternatives selectable by the Customer in the console. Upon actual activation, each provider will be added to the table above with the relevant effective date, and Customers will receive the 30-day prior notice required by the DPA.

3.Optional sub-processors

Vendors involved in the processing only if the Customer activates the corresponding channel or feature. If the Customer does not use WhatsApp, for example, Meta receives no data.

Messaging channels

VendorLocationChannel / PurposeData locationTransfer basisTerms
Meta Platforms Ireland Ltd.Dublin, Ireland + USAWhatsApp Business API, Instagram Direct, Facebook MessengerIreland + USASCC + DPFLink

Voice module – Centralino AI

Voice architecture: LiveKit Cloud with EU region pinning. The Supportfast voice pipeline uses LiveKit Cloud, the managed service of LiveKit Inc., to orchestrate real-time calls via WebRTC and for the integrated SIP telephony (inbound and outbound numbers). LiveKit Cloud is configured in region pinning mode on the EU region (Belgium): audio, session metadata and SIP routing of the Customer’s calls remain in LiveKit’s European data centres for the entire duration of the call.

By default, LiveKit Cloud does not record or store audio streams: the packets transit in real time and are not persisted. Any recordings, where enabled by the Customer in the console, are sent directly to Stepcode storage (Hetzner EU) and do not remain on LiveKit systems.

Speech recognition (STT) and voice synthesis (TTS) technologies are provided by external vendors listed below, integrated into the LiveKit pipeline.

VendorLocationRoleData locationTransfer basisTerms
LiveKit, Inc.San Francisco, USA — EU region pinningLiveKit Cloud: WebRTC orchestration, integrated SIP telephony, EU regionEU (Belgium)DPF + SCCLink
Deepgram, Inc.San Francisco, USASpeech-to-text — real-time audio transcriptionUSADPFLink
ElevenLabs Inc.New York, USAText-to-speech — voice synthesis of Chatbot responsesUSADPFLink

4.Stepcode vendors – internal business use

Vendors used by Stepcode SRL for its own internal business operations. They do not process Customer Data (end-user conversational data) but may process B2B Customer contact and billing data. They are listed for transparency, although they do not strictly fall within the sub-processors under Article 28 in relation to the processing of Customer Data.

VendorPurposeData locationTransfer basis
Google Ireland Ltd.Google Workspace — corporate e-mail, internal drive, calendarIreland + USASCC + DPF
Accounting firmTax management, accounting, billing, social-security filingsItaly (EU)Intra-EU

Marketing tools on the showcase website

The tools listed below are installed on the showcase website supportfast.ai for marketing and web statistics purposes. Pursuant to the EDPB and Italian Garante guidelines, these vendors act as autonomous Controllers of the navigation data collected, and not as sub-processors of Stepcode. They are listed for full transparency. Detail of the cookies used is in the Cookie Policy.

Microsoft Clarity and PostHog are instead also used within the authenticated console and act as external Processors of Stepcode (see Section 2 — Core sub-processors).

VendorPurposeLocationTransfer basis
Google Ireland Ltd.Google Analytics 4, Google Tag Manager — statistical analysis of the showcase websiteIreland + USASCC + DPF
Meta Platforms Ireland Ltd.Meta Pixel — measurement of advertising campaigns and retargetingIreland + USASCC + DPF
Calendly LLCBooking of demos and commercial meetings by leadsUSASCC
Wistia, Inc.Hosting and player for the videos embedded in the showcase websiteUSASCC

5.Independent verification of certifications

The certification status of US vendors to the EU-U.S. Data Privacy Framework can be independently verified on the official register maintained by the U.S. Department of Commerce. The register is updated in real time and also indicates any suspensions or withdrawals of certification.

Official DPF register: dataprivacyframework.gov

Glossary of legal bases

  • Intra-EU: processing takes place within the European Economic Area, with no need for specific bases for international transfer.
  • DPF (EU-U.S. Data Privacy Framework): adequacy decision of the European Commission of 10 July 2023 for certified US vendors. Constitutes an autonomous legal basis for the transfer.
  • SCC (Standard Contractual Clauses): standard clauses adopted by Decision 2021/914/EU, signed between Stepcode and the sub-processor, supplemented by additional technical measures on the basis of a Transfer Impact Assessment.
  • SCC + DPF: dual basis — the vendor is DPF-certified but SCCs are also signed as a supplementary measure, to provide maximum guarantees to Customers.

6.Notice of changes to the list

Any addition or replacement of a sub-processor is communicated to Customers with at least 30 days prior notice, as provided for in DPA Section 8.4. The communication channels are cumulative: update of this page, in-console notice and  for material changes  direct e-mail to the registered contact.

During the notice period, the Customer may object to the change on legitimate and documented grounds. In such case, the Parties shall negotiate in good faith a solution; failing agreement, the Customer may withdraw from the Contract without penalty (DPA Section 8.5).

To receive e-mail notice of every change to the list, write to [email protected] indicating the address at which updates should be received.

7.Change history

Chronology of changes to the list of sub-processors. The most recent entries appear at the top. Dates refer to the effective date of the change.

Pre-2026 — Version 1

Informal list consisting of OpenAI as the only AI provider, Hetzner for hosting, Cloudflare for CDN/WAF, Stripe for payments, AWS S3 for the CDN, Meta for messaging channels.

8.Sub-processor selection criteria

Each sub-processor is assessed and periodically reviewed against documented criteria that prioritise Customer data security and compliance with European law.

  • EU location preference: all other things being equal in terms of technical quality and price, the vendor with servers in the EU is preferred.
  • DPF certification: for US vendors, the vendor certified to the Data Privacy Framework is preferred.
  • Public DPA and Article 28 GDPR: the vendor must make available a DPA compliant with Article 28 GDPR, signed before processing begins.
  • Demonstrable security measures: ISO 27001, SOC 2 certifications or equivalent independent audits are a preference criterion.
  • No AI training: for AI model providers, a contractual prohibition or explicit technical configuration of non-use of transmitted data for training.
  • Financial and operational stability: vendors with documentable track record and technical support in English or a European language are preferred.
  • Reversibility: preference for vendors that allow migration or export of data without lock-in constraints.

Review of the main sub-processors is carried out at least once a year and whenever relevant events occur (security incidents, loss of certification, material changes to terms of service).

9.Contacts and related documents

For any clarification, request for a copy of the DPAs signed with individual sub-processors, request for SCCs, objection to a change or report:

Related documents: