Steerd
For freelancersFor teamsFeaturesPricingGuides
ENDE
Log inStart free

Annex 3: Subprocessors

Last updated 17 August 2026

This annex forms part of the data processing agreement between the Customer and Unbogify GmbH, Zelterstr. 10, 10439 Berlin, Germany (the "Processor"), operating the service under the name Steerd. Section 5 of that agreement governs how this list changes and how the Customer objects.

1. The subprocessors engaged

As at 13.08.2026 the Processor engages the following subprocessors for the processing of personal data on the Customer's behalf.

ProviderPurposeLocation of processingTransfer basis
Hetzner Online GmbH, GermanyThe servers, the database, the cache and the object storage on which Steerd runs. This is the whole applicationGermany (fsn1, Falkenstein)None required (EEA)
Amazon Web ServicesNightly backups of the database, and container images, which hold no personal dataGermany (eu-central-1, Frankfurt)None required at rest. The standard contractual clauses in the AWS GDPR data processing addendum apply to any transfer
Amazon Web Services (SES)The relay that delivers transactional email, behind the Processor's own self-hosted mail sender. It sees every recipient address, subject and message bodyGermany (eu-central-1, Frankfurt)as above, same addendum and same account
OpenAI Ireland LtdAI-assisted import. On the Customer's action only, and limited to the one document or page the Customer submits for importIreland, with onward processing in the United States by OpenAI OpCo, LLCNone required for the transfer to OpenAI Ireland (EEA). The onward transfer is OpenAI Ireland's own, on the standard contractual clauses in its data processing addendum. OpenAI is not certified under the EU-US Data Privacy Framework

Every provider in the table above is established in the European Economic Area. The Processor makes no transfer under Chapter V GDPR to any of them.

Both statements are about the providers this section lists and no others, which are the ones the Processor engages and holds a contract with. A destination the Customer designates is not one of them, and section 4 discloses those. Assessing a transfer to such a destination falls to the party that chose the recipient, which in those cases is the Customer and not the Processor.

The one onward transfer to the United States that occurs anywhere in the chain is OpenAI Ireland's, under its own agreement, and section 6 of the agreement requires the Processor to tell the Customer if a transfer basis it relies on ceases to be valid.

The Processor has concluded a data protection agreement with each provider above, and provides a copy on request under section 6.3 of the agreement, redacted only as necessary to protect the confidentiality of third parties.

2. AI-assisted import, stated separately because it is the row customers ask about

The last row is the only row of the table above where the Customer's content leaves the Processor's own infrastructure to be read by a model, so it is worth stating plainly rather than leaving in a table cell. A draft reply written by an AI provider the Customer itself sets up is a different path and is section 4's row, not this one.

  • It runs only on the Customer's action. Nothing is sent in the background, on a schedule, or as

part of ordinary use of the service.

  • What is sent is the one document or page the Customer submits for import, and nothing else from

the account.

  • It is not used for training. Section 2.5 of the agreement is a contractual promise that the

Processor does not use personal data to train artificial intelligence models, whether its own or a third party's, and the Processor does not opt in to any data-sharing or feedback arrangement by which that would change.

  • Content sent to the API is retained by the provider for at most 30 days for abuse detection and

is then deleted, and it is readable during that window by the provider's staff and by specialist contractors performing abuse review. That is a retention and access disclosure rather than a training one, and the two are stated separately here because a quick reading conflates them.

3. Providers that are not subprocessors under this agreement

Section 5.5 of the agreement excludes providers that process personal data for which the Processor itself is the controller. These are named here so that their absence from the table above is not mistaken for an omission:

ProviderWhat it processesWhose data
StripePayments and subscription billing for the Customer's own contract with the ProcessorThe Processor's billing relationship with the Customer
CloudflareBot protection on the forms of the Processor's marketing websiteVisitors to the Processor's website
Google Ireland LtdWebsite analytics on the Processor's marketing website, subject to consentVisitors to the Processor's website

Listing them as subprocessors would misstate their role and would give the Customer a right to object to processing that is not the Customer's data. They are named in the Processor's privacy notice, where the Processor's own controller-side processing belongs.

The Processor's own control plane and its self-hosted mail sender run on the Processor's own infrastructure within Germany and are operated by the Processor itself, so they are not third parties and are not listed as subprocessors.

4. Disclosures that are not subprocessing, listed rather than discovered

None of the following is a subprocessor. Each is a way personal data can leave the service as a result of something the Customer or its users do, and each is stated here so that a security review finds it in this document rather than in the product.

WhatWhat leaves, and to whom
Website icon lookupWhen a user records a website address for an organization, the Processor's server requests that site's icon. The operator of that site sees a request for the icon, made by the Processor's server. No user identifier and no cookie is sent
A mailbox the Customer connectsThe Customer's own mailbox credentials go to the mail server the Customer designates, over enforced TLS. The destination is the Customer's choice, not a fixed provider
An AI provider the Customer sets up for draft repliesWhere the Customer has entered its own AI credentials and a user asks for a draft reply, the thread being answered goes to the endpoint the Customer named: at most twelve messages of it, the plain-text alternative only and never the HTML one, each carrying its date, and its subject where the message has one. A message that came in also carries the sender's address, and the display name it arrived under where the message carried one. A message the user sent is marked as the user's own and carries no name and no address. The thread is capped at 12,000 characters and each message body at 3,000, and a message that was cut says so. Sent with the thread are the user's own instruction, the tone and the length the user selected, each of which leaves as one of a fixed set of style instructions written by the Processor rather than as anything the user typed, the answers the reply is to contain (availability, location and working preference), and, from the Customer's own records, the linked project title, the organization name and its role on the project, and the contact name. Where the reply is to quote a rate, that rate goes too, as the amount, its currency and whether it is charged per day, per hour or as a fixed price, and where the rate is a colleague's rather than the user's own, that colleague is named as well where a name is on file. Attachment contents are never read and nothing else in the account is sent. It runs only on that action, under the Customer's own key and at the Customer's own cost, and the endpoint may be anywhere in the world. The destination is the Customer's choice, not a fixed provider
Contact synchronisationWhere a user connects an address book client, full contact records including photographs synchronise out to whichever client the user connected. Steerd is the server in that exchange
The browser extensionReads the page the user is viewing when the user asks it to. Nothing is sent to the site being read beyond that user's ordinary browsing

5. How this list changes

The Processor informs the Customer at least 30 days in advance of any intended addition or replacement of a subprocessor, stating the provider, the purpose, the location of processing, the intended start date and how to object. The notice goes to the addresses in section 11.4 of the agreement, and the Customer may object on reasonable grounds relating to data protection within that period. Section 5 of the agreement sets out what follows an objection, including the Customer's right to terminate.

The current version of this annex is published at the address the agreement names, and the Processor keeps it current.

Steerd

The home base for independent professionals who sell their services. Start solo; it grows as you do.

Product

For freelancersFor teamsPricingCompareE-invoicingGuidesHelp centerRelease notesContact

Developers

API documentationMCP server

Company

Nightly Build Group

Legal

ImprintPrivacyTerms
© 2026 Unbogify GmbH. All rights reserved.
ENDE