Subprocessors

This page lists every third party that may process personal data on our behalf when you use GPTpost. It forms Annex III of Data Processing Addendum and satisfies the subprocessor-disclosure obligation in Privacy Policy section 7.

Controller of record: GPT LLM ORAGLE Ltd. Liability Co., a Wyoming close limited liability company, registered office 30 N Gould St, Ste N, Sheridan, WY 82801, United States. Contact: dpa@oraglegpt.org.

We do not list a vendor here unless we actually use it. Categories we have deliberately not engaged are listed in section 5 as not engaged, so you can see what is absent as well as what is present.


1. Legend

StatusMeaning
ENGAGEDThe vendor is in use today and processes data as described in the row
CONDITIONALEngaged only for the specific optional feature named in the row, and only when that feature is switched on
CUSTOMER CHOICEEngaged only if a customer enables it inside their own workspace. The customer selects the vendor and accepts its terms
NOT ENGAGEDNot used. No data flows to a vendor of this kind
NOT IMPLEMENTEDThe capability the row describes does not exist in this build. No vendor is engaged, and no data of that kind is generated or transferred

Transfer mechanism column: Adequacy / EU-internal means no transfer tool is needed. SCCs means the European Commission Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum and the Swiss amendments where those apply.


2. Infrastructure and hosting

#SubprocessorLegal entity and countryService providedPersonal data categoriesProcessing locationTransfer mechanismStatus
1Contabo GmbHContabo GmbH, GermanyCompute, network, and server hosting for the application, and the primary PostgreSQL databaseAll Customer Personal Data at rest and in transit, account data, session records, audit and security logsGermany, European UnionAdequacy / EU-internal. No transfer tool required for EEA dataENGAGED
2Operator-managed object storageOperated by GPT LLM ORAGLE Ltd. Liability Co. on its own infrastructure (MinIO, S3-compatible)Object storage for uploaded media and its derivativesUploaded images, video, and documents, which may contain personal data such as images of identifiable individuals, plus object metadataGermany, European UnionNot a third-party transfer. The Company operates this storage itselfENGAGED
3Cloudflare, Inc.Cloudflare, Inc., United StatesDNS and reverse proxy for the marketing site oraglegpt.org, which serves the public policy pagesVisitor IP address, request metadata, and TLS connection data for requests to those pages. No workspace contentGlobal edge networkSCCsENGAGED (marketing site only)
4Let's Encrypt (ISRG)Internet Security Research Group, United StatesAutomated TLS certificate issuance for oraglegpt.org, requested by the reverse proxyThe administrative ACME_EMAIL address and the domain name. No Customer Personal DataUnited StatesNot applicable. No Customer Personal Data is transferredENGAGED

Contabo GmbH is established in Germany, so hosting personal data there requires no international transfer safeguard for EEA or UK customers. Uploaded media is held in object storage the Company runs on that same German infrastructure, so it is not transferred outside the EEA and no international transfer tool is required for it.

Cloudflare, Inc. proxies the marketing site oraglegpt.org, which is where the public policy pages are served from. As a reverse proxy it necessarily observes the IP address and request metadata of visitors to those pages. It does not sit in front of the application at app.oraglegpt.org or in front of uploaded media at media.oraglegpt.org; both resolve directly to our origin, so no Customer Personal Data held in a workspace passes through it.


3. Communications

#SubprocessorLegal entity and countryService providedPersonal data categoriesProcessing locationTransfer mechanismStatus
5Transactional email deliveryNone. No vendor is engaged and no Company mail service is wired into the applicationWould cover email verification, password reset, multi-factor, invitation, alert, and notification messagesNone. No such message is generatedNot applicableNot applicable. No data is transferredNOT IMPLEMENTED

This build sends no email of its own. The application contains no mail client and no email vendor library, and it exposes no email verification, password reset, invitation, or notification-delivery route, so none of the messages named in that row is generated or delivered by the Service. Where this site tells you to write to an address such as dpa@oraglegpt.org or privacy@oraglegpt.org, that is ordinary mailbox correspondence answered by a person, not product-generated mail, and no third-party email delivery platform receives your address or your message content. If we later add automated email, this row is updated first, and where that involves a vendor the notice period in section 8 applies before any message is routed through it.


4. AI model providers

The Service ships with no AI provider enabled by default. A workspace administrator configures one at settings/ai-providers, subject to that tenant's AI policy: allowed providers, allowed models, allowed tools, monthly budget, maximum output tokens, declared data region, and whether autonomous public actions are permitted. If no provider is configured, AI features either return a local fixture response that never leaves the deployment, or are unavailable.

#SubprocessorLegal entity and countryService providedData sentProcessing locationTransfer mechanismStatus
6Anthropic (Claude)Anthropic PBC, United StatesAI generation: drafting posts, reply suggestions, rewriting, summarisationThe agent system prompt, the user input, and any retrieved tenant knowledge citations that the feature assemblesUnited StatesSCCsENGAGED (customer-enabled)
7OpenAIOpenAI, L.P., United StatesAI generation: the same feature set, used as the alternate providerAs aboveUnited StatesSCCsENGAGED (customer-enabled)
8Google GeminiGoogle LLC, United StatesAI generation, where a customer supplies its own credentialsAs aboveUnited StatesSCCs, executed by the customer with GoogleCUSTOMER CHOICE
9Any OpenAI-compatible endpoint, including self-hostedSelected and contracted by the customerAI generation against a customer-supplied base URLAs aboveDetermined by the customerThe customer's responsibilityCUSTOMER CHOICE
10Local fixture modeNone. No vendor involvedDeterministic canned responses for demonstration and testingNothing leaves the deploymentLocalNot applicableBuilt in

Commitments that apply to every AI provider above:

  1. Tenant content is not used to train a shared or public model. We do not grant any AI provider the right to train on Customer Personal Data or on Platform Data.
  2. An AI call happens only when a tenant uses an AI feature. There is no background AI processing of your content.
  3. We will not send Customer Personal Data to a provider the customer has not configured.
  4. Whether a given provider retains prompts, and for how long, is governed by that provider's own terms. Customers who enable a provider must satisfy themselves about those terms.
  5. Platform Data obtained from a social network is never sent to an AI provider for model training, in line with our commitments in Privacy Policy section 13.

5. Categories we have deliberately not engaged

Listing these matters as much as listing the vendors we do use, because it tells you which data flows do not exist.

CategoryStatusNote
Content delivery network (CDN)ENGAGED for the marketing site onlySee Cloudflare, Inc. in section 2. Uploaded media is served from our own origin and no CDN sees media requests; app.oraglegpt.org and media.oraglegpt.org resolve directly to our origin
Product analyticsNOT ENGAGEDThe frontend ships with no analytics tag, no session recorder, and no third-party script
Error monitoring / APMNOT ENGAGEDDiagnostics stay inside the deployment. No stack traces are sent to a third party
Advertising, attribution, or data-broker servicesNOT ENGAGEDWe do not sell or share personal information, and we run no advertising
Third-party helpdesk / ticketingNOT ENGAGEDSupport correspondence is handled in the Company's own mailboxes, by a person. No ticketing vendor sees it
SMS or push notification vendorNOT ENGAGEDNotifications are shown in the product only. The Service sends no SMS, no push message, and no email of its own; see the transactional email row in section 3
Payment processorNOT ENGAGED at the date aboveWhere a paid plan is settled by card, a PCI-DSS compliant processor will be engaged and named here first. Card numbers never reach our systems

6. Social platforms are recipients, not subprocessors

When a customer connects an account, the Service exchanges data with that platform. Platforms are independent controllers of the data they hold, not subprocessors of the Company, because they determine their own purposes and means. They are listed here for transparency.

This build's connectors are publish-only. Every call the Service makes to a social platform is one of three things: an OAuth authorisation, token exchange or refresh; a publish call; or, for Facebook, TikTok, Reddit and Snapchat, a single identity lookup at connection time that resolves which account was connected. There is no inbox or message fetcher, no comment or mention fetcher, no insights or analytics call, and no delete, hide, like, or moderation call for any platform in this build. So the "received" column below is limited to what an OAuth response, that one identity lookup, and a publish response contain.

Most of the platforms in this table cannot be connected in this release, so no data flows to them at all. The table describes what each connector would send and receive, because that is what a customer needs to know before connecting. Today the only platforms an account can actually be connected to are Facebook Pages, Instagram Professional, Threads and TikTok through OAuth, and Bluesky, Telegram, Discord and WordPress using a credential the customer supplies for that account. Every other row is dormant: the connector has no account-identity resolver in this build, or a provider-approval policy blocks it, so the authorisation flow refuses to start and nothing is transmitted. The live answer is GET /api/v1/capabilities, which reports oauth_connectable per provider and the reason when it is false.

PlatformData sent to itData received from it
Facebook Pages, Instagram Professional, Threads (Meta)Facebook: the post text and an optional link. Instagram: the caption and one image or video URL. Threads: the text and, optionally, one image or video URL. Plus the OAuth token on every callThe OAuth token response (access token, refresh state, expiry, granted scopes) and, per publish, the created container or post identifier or the provider's error. For Facebook only, one call to GET /me/accounts at connection time returns the Pages the authorising person administers, with each Page's identifier, name and Page access token, so that the connection knows which Page it publishes to. No comments, mentions, messages or insights are received, for any of the three: no such call is made
LinkedInPost commentary, author URN, visibility and distribution settings, the OAuth tokenThe OAuth token response and, per publish, the created post identifier or the provider's error
TikTokVideo or photo URLs, title, description, privacy level and post mode, the OAuth tokenThe OAuth token response and, per publish, the publish identifier or the provider's error
YouTube and Google Business Profile (Google)YouTube: the video bytes and its title, description and metadata. Google Business Profile: the post summary, language and call-to-action link. Plus the OAuth tokenThe OAuth token response and, per publish, the created video or local post identifier or the provider's error
XThe post text and the OAuth tokenThe OAuth token response and, per publish, the created post identifier or the provider's error
PinterestBoard id, title, description, link and one image URL, the OAuth tokenThe OAuth token response and, per publish, the created pin identifier or the provider's error
RedditPost title, body or link, and the OAuth tokenAccount identity (username and account id) and the result of each submission
Mastodon (per instance)The status text, visibility and language, and the OAuth tokenThe OAuth token response and, per publish, the created status identifier or the instance's error
Bluesky, Discord, Telegram, Tumblr, VK, Odnoklassniki, WordPressThe post text, an optional media URL, and the credential the connector usesThe credential exchange response where the connector performs one, and, per publish, the created item identifier or the provider's error

Each platform's own privacy policy governs what it does with that data.

Where a customer's own systems bring platform conversations or metrics into GPTpost through the ingest APIs described in Privacy Policy sections 4.4 and 4.5, that data reaches us from the customer, not from the platform, and the customer is responsible for having obtained it lawfully.


7. Company affiliates

The Company has no subsidiaries and no affiliates. If that changes, any affiliate that processes Customer Personal Data will be added to this page under the same notice period as any other subprocessor.


8. Notice of changes

  1. We will publish an update to this page and give at least 30 days' notice before a new subprocessor starts processing Customer Personal Data.
  2. To receive those notices by email, write to dpa@oraglegpt.org and ask to be added to the subprocessor notification list. We maintain that list manually and confirm each subscription.
  3. A customer may object on reasonable data protection grounds within the notice period, under Data Processing Addendum section 7. If the objection cannot be resolved, the customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid unused fees.
  4. Where a change is urgent, for example replacing a vendor after a security incident, we may act first and notify immediately afterwards with reasons.

9. What we require of every subprocessor

  1. A written contract containing GDPR Article 28(3) terms.
  2. A documented international transfer mechanism where the vendor is outside the EEA, the UK, or Switzerland.
  3. Confidentiality obligations binding on personnel with access.
  4. Security measures no less protective than those in Annex II of Data Processing Addendum.
  5. An obligation to assist with data subject requests and breach notification.
  6. Deletion or return of data at the end of the engagement.
  7. A prohibition on using our data, or Customer Personal Data, for the vendor's own purposes.

10. Version history

VersionDateChange
1.22026-08-04Corrections after verification against the running build. Object storage confirmed as storage the Company runs itself in Germany, and the erroneous reference to AWS S3 (United States) removed from this page, from Annex II of the Data Processing Addendum, and from the Security page. Transactional email moved from ENGAGED to NOT IMPLEMENTED, because this build contains no mail client. Annex III row identifiers renumbered so that no identifier is used twice: the AI provider rows, previously 5 to 9, are now 6 to 10
1.12026-08-04Vendors confirmed. Contabo (DE) recorded for hosting, and object storage recorded as run by the Company on that same German infrastructure. Anthropic and OpenAI recorded for AI. Categories not engaged listed explicitly. Placeholder rows removed
1.02026-08-04Initial version

11. Contact

TopicAddress
Subprocessor questions, DPA, SCCsdpa@oraglegpt.org
Privacy and data subject rightsprivacy@oraglegpt.org
Securitysecurity@oraglegpt.org
GPT LLM ORAGLE Ltd. Liability Co.
30 N Gould St, Ste N
Sheridan, WY 82801
United States