Nodl
  • Examples
  • Who it's for
  • How it works
  • Pricing
  • FAQ
en
Sign in Start free

Subprocessor Register

Stand: 08. Juni 2026
Responsible party: ex-nihilo GmbH

This register is an annex to the Data Processing Agreement (DPA) and supplements the technical and organisational measures described in the Privacy Policy.

At a glance

  • Data processing takes place primarily in EU/EEA data centres.
  • Subprocessors are announced at least 30 days before any change in use.
  • Data processing agreements (DPAs) or equivalent arrangements are in place with all providers, where required.
  • Security requirements are aligned with Art. 32 GDPR and reviewed regularly.
  • Questions: [email protected].
Name Role Location Data categories Transfer mechanism DPA / agreement Status
Hetzner Online GmbH Infrastructure hosting (servers, storage, PostgreSQL) Nuremberg, Germany Account data, audio, transcripts, documents, workspace data, logs, technical metadata EU/EEA – no third-country transfer Hetzner privacy & DPA Active
Mistral AI (Voxtral) Live and batch transcription, speaker separation EU/EEA, where technically/contractually configured Audio during processing, transcript segments, technical metadata No-training / zero-retention configuration where available Mistral DPA Active
Google (Gemini API) Document generation, title generation EU/EEA, where technically/contractually configured Transcripts, prompts, transformer instructions, generated documents No-training / zero-retention configuration where available; SCC if support access applies Google DPT Active
Stripe Payments Europe Ltd. Payment processing, billing Ireland / EU Customer master data, payment references, plan and invoice status EU/EEA; SCC if support access applies Stripe DPA Active
Brevo (formerly Sendinblue) Transactional email, account/system communication EU/EEA, as configured Email address, name, email content, delivery metadata EU/EEA; appropriate safeguards for any third-country access Brevo DPA Active
Cloudflare, Inc. DNS, CDN, attack protection, performance Global, per service configuration IP addresses, request headers, security logs, limited content transit where applicable SCC / adequacy decision where applicable Cloudflare DPA Active
SigNoz (self-hosted) Observability, logging, tracing Nuremberg, Germany (self-hosted on Nodl infrastructure) Telemetry data, pseudonymous IDs, technical logs; customer content avoided where possible EU/EEA – no external subprocessor when self-hosted Self-operated – internal TOMs Active
Google Analytics Website/product analytics Global, when activated Online identifiers, usage data, technical data Only after consent where required; SCC if applicable Google DPT Planned

History and planned changes are announced by email. Customers may object within 30 days; where an objection is justified, we will seek alternative solutions.

Related documents

  • → Privacy
  • → Security
Nodl for: Doctors Dental practices Racing mind Journaling Interviews Coaches & consultants
© 2026 ex-nihilo GmbH. All rights reserved.
About Pricing Demo Articles Imprint Privacy Terms

Are you sure?