Subprocessors
This page lists every third party that may process personal data on our behalf when you use GPTpost. It forms Annex III of Data Processing Addendum and satisfies the subprocessor-disclosure obligation in Privacy Policy section 7.
Controller of record: GPT LLM ORAGLE Ltd. Liability Co., a Wyoming close limited liability company, registered office 30 N Gould St, Ste N, Sheridan, WY 82801, United States. Contact: dpa@oraglegpt.org.
We do not list a vendor here unless we actually use it. Categories we have deliberately not engaged are listed in section 5 as not engaged, so you can see what is absent as well as what is present.
1. Legend
| Status | Meaning |
|---|---|
| ENGAGED | The vendor is in use today and processes data as described in the row |
| CONDITIONAL | Engaged only for the specific optional feature named in the row, and only when that feature is switched on |
| CUSTOMER CHOICE | Engaged only if a customer enables it inside their own workspace. The customer selects the vendor and accepts its terms |
| NOT ENGAGED | Not used. No data flows to a vendor of this kind |
| NOT IMPLEMENTED | The capability the row describes does not exist in this build. No vendor is engaged, and no data of that kind is generated or transferred |
Transfer mechanism column: Adequacy / EU-internal means no transfer tool is needed. SCCs means the European Commission Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum and the Swiss amendments where those apply.
2. Infrastructure and hosting
| # | Subprocessor | Legal entity and country | Service provided | Personal data categories | Processing location | Transfer mechanism | Status |
|---|---|---|---|---|---|---|---|
| 1 | Contabo GmbH | Contabo GmbH, Germany | Compute, network, and server hosting for the application, and the primary PostgreSQL database | All Customer Personal Data at rest and in transit, account data, session records, audit and security logs | Germany, European Union | Adequacy / EU-internal. No transfer tool required for EEA data | ENGAGED |
| 2 | Operator-managed object storage | Operated by GPT LLM ORAGLE Ltd. Liability Co. on its own infrastructure (MinIO, S3-compatible) | Object storage for uploaded media and its derivatives | Uploaded images, video, and documents, which may contain personal data such as images of identifiable individuals, plus object metadata | Germany, European Union | Not a third-party transfer. The Company operates this storage itself | ENGAGED |
| 3 | Cloudflare, Inc. | Cloudflare, Inc., United States | DNS and reverse proxy for the marketing site oraglegpt.org, which serves the public policy pages | Visitor IP address, request metadata, and TLS connection data for requests to those pages. No workspace content | Global edge network | SCCs | ENGAGED (marketing site only) |
| 4 | Let's Encrypt (ISRG) | Internet Security Research Group, United States | Automated TLS certificate issuance for oraglegpt.org, requested by the reverse proxy | The administrative ACME_EMAIL address and the domain name. No Customer Personal Data | United States | Not applicable. No Customer Personal Data is transferred | ENGAGED |
Contabo GmbH is established in Germany, so hosting personal data there requires no international transfer safeguard for EEA or UK customers. Uploaded media is held in object storage the Company runs on that same German infrastructure, so it is not transferred outside the EEA and no international transfer tool is required for it.
Cloudflare, Inc. proxies the marketing site oraglegpt.org, which is where the public policy pages are served from. As a reverse proxy it necessarily observes the IP address and request metadata of visitors to those pages. It does not sit in front of the application at app.oraglegpt.org or in front of uploaded media at media.oraglegpt.org; both resolve directly to our origin, so no Customer Personal Data held in a workspace passes through it.
3. Communications
| # | Subprocessor | Legal entity and country | Service provided | Personal data categories | Processing location | Transfer mechanism | Status |
|---|---|---|---|---|---|---|---|
| 5 | Transactional email delivery | None. No vendor is engaged and no Company mail service is wired into the application | Would cover email verification, password reset, multi-factor, invitation, alert, and notification messages | None. No such message is generated | Not applicable | Not applicable. No data is transferred | NOT IMPLEMENTED |
This build sends no email of its own. The application contains no mail client and no email vendor library, and it exposes no email verification, password reset, invitation, or notification-delivery route, so none of the messages named in that row is generated or delivered by the Service. Where this site tells you to write to an address such as dpa@oraglegpt.org or privacy@oraglegpt.org, that is ordinary mailbox correspondence answered by a person, not product-generated mail, and no third-party email delivery platform receives your address or your message content. If we later add automated email, this row is updated first, and where that involves a vendor the notice period in section 8 applies before any message is routed through it.
4. AI model providers
The Service ships with no AI provider enabled by default. A workspace administrator configures one at settings/ai-providers, subject to that tenant's AI policy: allowed providers, allowed models, allowed tools, monthly budget, maximum output tokens, declared data region, and whether autonomous public actions are permitted. If no provider is configured, AI features either return a local fixture response that never leaves the deployment, or are unavailable.
| # | Subprocessor | Legal entity and country | Service provided | Data sent | Processing location | Transfer mechanism | Status |
|---|---|---|---|---|---|---|---|
| 6 | Anthropic (Claude) | Anthropic PBC, United States | AI generation: drafting posts, reply suggestions, rewriting, summarisation | The agent system prompt, the user input, and any retrieved tenant knowledge citations that the feature assembles | United States | SCCs | ENGAGED (customer-enabled) |
| 7 | OpenAI | OpenAI, L.P., United States | AI generation: the same feature set, used as the alternate provider | As above | United States | SCCs | ENGAGED (customer-enabled) |
| 8 | Google Gemini | Google LLC, United States | AI generation, where a customer supplies its own credentials | As above | United States | SCCs, executed by the customer with Google | CUSTOMER CHOICE |
| 9 | Any OpenAI-compatible endpoint, including self-hosted | Selected and contracted by the customer | AI generation against a customer-supplied base URL | As above | Determined by the customer | The customer's responsibility | CUSTOMER CHOICE |
| 10 | Local fixture mode | None. No vendor involved | Deterministic canned responses for demonstration and testing | Nothing leaves the deployment | Local | Not applicable | Built in |
Commitments that apply to every AI provider above:
- Tenant content is not used to train a shared or public model. We do not grant any AI provider the right to train on Customer Personal Data or on Platform Data.
- An AI call happens only when a tenant uses an AI feature. There is no background AI processing of your content.
- We will not send Customer Personal Data to a provider the customer has not configured.
- Whether a given provider retains prompts, and for how long, is governed by that provider's own terms. Customers who enable a provider must satisfy themselves about those terms.
- Platform Data obtained from a social network is never sent to an AI provider for model training, in line with our commitments in Privacy Policy section 13.
5. Categories we have deliberately not engaged
Listing these matters as much as listing the vendors we do use, because it tells you which data flows do not exist.
| Category | Status | Note |
|---|---|---|
| Content delivery network (CDN) | ENGAGED for the marketing site only | See Cloudflare, Inc. in section 2. Uploaded media is served from our own origin and no CDN sees media requests; app.oraglegpt.org and media.oraglegpt.org resolve directly to our origin |
| Product analytics | NOT ENGAGED | The frontend ships with no analytics tag, no session recorder, and no third-party script |
| Error monitoring / APM | NOT ENGAGED | Diagnostics stay inside the deployment. No stack traces are sent to a third party |
| Advertising, attribution, or data-broker services | NOT ENGAGED | We do not sell or share personal information, and we run no advertising |
| Third-party helpdesk / ticketing | NOT ENGAGED | Support correspondence is handled in the Company's own mailboxes, by a person. No ticketing vendor sees it |
| SMS or push notification vendor | NOT ENGAGED | Notifications are shown in the product only. The Service sends no SMS, no push message, and no email of its own; see the transactional email row in section 3 |
| Payment processor | NOT ENGAGED at the date above | Where a paid plan is settled by card, a PCI-DSS compliant processor will be engaged and named here first. Card numbers never reach our systems |
6. Social platforms are recipients, not subprocessors
When a customer connects an account, the Service exchanges data with that platform. Platforms are independent controllers of the data they hold, not subprocessors of the Company, because they determine their own purposes and means. They are listed here for transparency.
This build's connectors are publish-only. Every call the Service makes to a social platform is one of three things: an OAuth authorisation, token exchange or refresh; a publish call; or, for Facebook, TikTok, Reddit and Snapchat, a single identity lookup at connection time that resolves which account was connected. There is no inbox or message fetcher, no comment or mention fetcher, no insights or analytics call, and no delete, hide, like, or moderation call for any platform in this build. So the "received" column below is limited to what an OAuth response, that one identity lookup, and a publish response contain.
Most of the platforms in this table cannot be connected in this release, so no data flows to them at all. The table describes what each connector would send and receive, because that is what a customer needs to know before connecting. Today the only platforms an account can actually be connected to are Facebook Pages, Instagram Professional, Threads and TikTok through OAuth, and Bluesky, Telegram, Discord and WordPress using a credential the customer supplies for that account. Every other row is dormant: the connector has no account-identity resolver in this build, or a provider-approval policy blocks it, so the authorisation flow refuses to start and nothing is transmitted. The live answer is GET /api/v1/capabilities, which reports oauth_connectable per provider and the reason when it is false.
| Platform | Data sent to it | Data received from it |
|---|---|---|
| Facebook Pages, Instagram Professional, Threads (Meta) | Facebook: the post text and an optional link. Instagram: the caption and one image or video URL. Threads: the text and, optionally, one image or video URL. Plus the OAuth token on every call | The OAuth token response (access token, refresh state, expiry, granted scopes) and, per publish, the created container or post identifier or the provider's error. For Facebook only, one call to GET /me/accounts at connection time returns the Pages the authorising person administers, with each Page's identifier, name and Page access token, so that the connection knows which Page it publishes to. No comments, mentions, messages or insights are received, for any of the three: no such call is made |
| Post commentary, author URN, visibility and distribution settings, the OAuth token | The OAuth token response and, per publish, the created post identifier or the provider's error | |
| TikTok | Video or photo URLs, title, description, privacy level and post mode, the OAuth token | The OAuth token response and, per publish, the publish identifier or the provider's error |
| YouTube and Google Business Profile (Google) | YouTube: the video bytes and its title, description and metadata. Google Business Profile: the post summary, language and call-to-action link. Plus the OAuth token | The OAuth token response and, per publish, the created video or local post identifier or the provider's error |
| X | The post text and the OAuth token | The OAuth token response and, per publish, the created post identifier or the provider's error |
| Board id, title, description, link and one image URL, the OAuth token | The OAuth token response and, per publish, the created pin identifier or the provider's error | |
| Post title, body or link, and the OAuth token | Account identity (username and account id) and the result of each submission | |
| Mastodon (per instance) | The status text, visibility and language, and the OAuth token | The OAuth token response and, per publish, the created status identifier or the instance's error |
| Bluesky, Discord, Telegram, Tumblr, VK, Odnoklassniki, WordPress | The post text, an optional media URL, and the credential the connector uses | The credential exchange response where the connector performs one, and, per publish, the created item identifier or the provider's error |
Each platform's own privacy policy governs what it does with that data.
Where a customer's own systems bring platform conversations or metrics into GPTpost through the ingest APIs described in Privacy Policy sections 4.4 and 4.5, that data reaches us from the customer, not from the platform, and the customer is responsible for having obtained it lawfully.
7. Company affiliates
The Company has no subsidiaries and no affiliates. If that changes, any affiliate that processes Customer Personal Data will be added to this page under the same notice period as any other subprocessor.
8. Notice of changes
- We will publish an update to this page and give at least 30 days' notice before a new subprocessor starts processing Customer Personal Data.
- To receive those notices by email, write to
dpa@oraglegpt.organd ask to be added to the subprocessor notification list. We maintain that list manually and confirm each subscription. - A customer may object on reasonable data protection grounds within the notice period, under Data Processing Addendum section 7. If the objection cannot be resolved, the customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid unused fees.
- Where a change is urgent, for example replacing a vendor after a security incident, we may act first and notify immediately afterwards with reasons.
9. What we require of every subprocessor
- A written contract containing GDPR Article 28(3) terms.
- A documented international transfer mechanism where the vendor is outside the EEA, the UK, or Switzerland.
- Confidentiality obligations binding on personnel with access.
- Security measures no less protective than those in Annex II of Data Processing Addendum.
- An obligation to assist with data subject requests and breach notification.
- Deletion or return of data at the end of the engagement.
- A prohibition on using our data, or Customer Personal Data, for the vendor's own purposes.
10. Version history
| Version | Date | Change |
|---|---|---|
| 1.2 | 2026-08-04 | Corrections after verification against the running build. Object storage confirmed as storage the Company runs itself in Germany, and the erroneous reference to AWS S3 (United States) removed from this page, from Annex II of the Data Processing Addendum, and from the Security page. Transactional email moved from ENGAGED to NOT IMPLEMENTED, because this build contains no mail client. Annex III row identifiers renumbered so that no identifier is used twice: the AI provider rows, previously 5 to 9, are now 6 to 10 |
| 1.1 | 2026-08-04 | Vendors confirmed. Contabo (DE) recorded for hosting, and object storage recorded as run by the Company on that same German infrastructure. Anthropic and OpenAI recorded for AI. Categories not engaged listed explicitly. Placeholder rows removed |
| 1.0 | 2026-08-04 | Initial version |
11. Contact
| Topic | Address |
|---|---|
| Subprocessor questions, DPA, SCCs | dpa@oraglegpt.org |
| Privacy and data subject rights | privacy@oraglegpt.org |
| Security | security@oraglegpt.org |
GPT LLM ORAGLE Ltd. Liability Co.
30 N Gould St, Ste N
Sheridan, WY 82801
United States