Subprocessor Register
Stand: 08. Juni 2026
Responsible party: ex-nihilo GmbH
This register is an annex to the Data Processing Agreement (DPA) and supplements the technical and organisational measures described in the Privacy Policy.
At a glance
- Data processing takes place primarily in EU/EEA data centres.
- Subprocessors are announced at least 30 days before any change in use.
- Data processing agreements (DPAs) or equivalent arrangements are in place with all providers, where required.
- Security requirements are aligned with Art. 32 GDPR and reviewed regularly.
- Questions: [email protected].
| Name | Role | Location | Data categories | Transfer mechanism | DPA / agreement | Status |
|---|---|---|---|---|---|---|
| Hetzner Online GmbH | Infrastructure hosting (servers, storage, PostgreSQL) | Nuremberg, Germany | Account data, audio, transcripts, documents, workspace data, logs, technical metadata | EU/EEA – no third-country transfer | Hetzner privacy & DPA | Active |
| Mistral AI (Voxtral) | Live and batch transcription, speaker separation | EU/EEA, where technically/contractually configured | Audio during processing, transcript segments, technical metadata | No-training / zero-retention configuration where available | Mistral DPA | Active |
| Google (Gemini API) | Document generation, title generation | EU/EEA, where technically/contractually configured | Transcripts, prompts, transformer instructions, generated documents | No-training / zero-retention configuration where available; SCC if support access applies | Google DPT | Active |
| Stripe Payments Europe Ltd. | Payment processing, billing | Ireland / EU | Customer master data, payment references, plan and invoice status | EU/EEA; SCC if support access applies | Stripe DPA | Active |
| Brevo (formerly Sendinblue) | Transactional email, account/system communication | EU/EEA, as configured | Email address, name, email content, delivery metadata | EU/EEA; appropriate safeguards for any third-country access | Brevo DPA | Active |
| Cloudflare, Inc. | DNS, CDN, attack protection, performance | Global, per service configuration | IP addresses, request headers, security logs, limited content transit where applicable | SCC / adequacy decision where applicable | Cloudflare DPA | Active |
| SigNoz (self-hosted) | Observability, logging, tracing | Nuremberg, Germany (self-hosted on Nodl infrastructure) | Telemetry data, pseudonymous IDs, technical logs; customer content avoided where possible | EU/EEA – no external subprocessor when self-hosted | Self-operated – internal TOMs | Active |
| Google Analytics | Website/product analytics | Global, when activated | Online identifiers, usage data, technical data | Only after consent where required; SCC if applicable | Google DPT | Planned |
History and planned changes are announced by email. Customers may object within 30 days; where an objection is justified, we will seek alternative solutions.