Skip to main content

    Sub-Processors

    Complete transparency about the third-party providers that process your data, in compliance with GDPR Article 28.

    Last updated: September 2026 (rev. 7)

    1. What Is a Sub-Processor

    Under the General Data Protection Regulation (GDPR), Keypra makes this page publicly available to identify the third-party service providers that process personal data on its behalf.

    Keypra OÜ is the data controller for personal data collected through the Keypra platform.

    • Company: Keypra OÜ
    • Registry code: 17502390
    • Registered address: Sepapaja tn 6, 15551 Tallinn, Estonia, Tallinn, Estonia

    The sub-processors listed below act as processors or infrastructure providers processing personal data on our documented instructions and for the purposes described on this page.

    We provide at least 30 days' advance notice before engaging a new sub-processor or materially changing how an existing sub-processor handles personal data.

    2. Current Sub-Processors

    ProviderRolePurposeTypical DataLocationTransfer Safeguard
    Lovable Cloud (Supabase)Infrastructure & DatabaseDatabase, authentication, file storage, backend functionsAccount data, application data, filesEU (where configured)DPA; EU regional hosting where configured
    Lovable AI Gateway (Lovable AB)AI Routing LayerRoutes AI requests from Keypra backend to model providers; holds no Customer Data at restPrompt text, response text, model parameters (no end-user IP or account email attached by Keypra)EU / USStandard Contractual Clauses (SCCs)
    Google (Gemini models)AI Model ProviderLanguage model processing for prompt analysis, content generation, assessmentsPrompt text, response text, token metadataEU / USEU-US Data Privacy Framework (verified)
    OpenAI (GPT models)AI Model ProviderLanguage model processing, model diversity and fallbackPrompt text, response text, token metadataUSStandard Contractual Clauses (SCCs)
    Perplexity AI, Inc.AI Search ProviderReal-time web search inside Workflow search nodesSearch query text, returned citationsUSStandard Contractual Clauses (SCCs)
    Firecrawl (Mendable Labs, Inc.)Web Scraping ProviderServer-side fetching/scraping of user-supplied URLs in Workflow scrape/crawl nodes and Rafy ResearcherTarget URL, scraped page contents (no end-user identifier)USStandard Contractual Clauses (SCCs)
    ElevenLabs Inc.Text-to-Speech ProviderVoice generation in Workflow voice nodesText to be spoken, selected voice ID, generated audio outputUSStandard Contractual Clauses (SCCs)
    ResendEmail Delivery and Inbound ReceivingOutbound transactional and concierge email (verification, password reset, notifications, AI replies) and inbound receiving for the in.keypra.com subdomain (ask@in.keypra.com), including delivery of the signed inbound webhook to KeypraRecipient and sender email address, subject, email content and attachments, delivery metadataUSStandard Contractual Clauses (SCCs)
    StripePayment ProcessingSubscription billing, credit purchases, invoicingEmail, legal company name, VAT/Tax ID, billing address, tokenized card data, transaction records — collected and held directly by Stripe, not mirrored in Keypra's databaseUS / EUEU-US Data Privacy Framework (verified) + SCCs
    Linear Orbit, Inc.Issue TrackingReceives bug reports submitted via the in-app "Report a bug" flowBug description and screenshots (may contain personal data the user includes), reporter email, account IDUSStandard Contractual Clauses (SCCs)
    Zoho Corporation Pvt. Ltd. (Zoho Mail)Email InfrastructureInbound email routing for keypra.com addresses (support@, hello@, security@, dpo@, privacy@, legal@, compliance@, enterprise@, sales@, brand@, engineering@, feedback@, noreply@) and internal company email for Keypra staffEmail metadata (sender, recipient, subject, timestamps) and email message contentEU (Netherlands)EU hosting — no transfer required
    Xolo OÜAccounting & Financial Record-KeepingAccounting, invoicing, and bookkeeping in compliance with the Estonian Accounting ActCustomer billing data — company name, contact name, invoicing email, VAT ID, transaction amountsEstonia (EU)EU-based processor — no transfer required

    Bring Your Own Key (BYOK) Integrations

    Certain Keypra features (such as workflow nodes for voice, web research, and scraping) allow you to connect third-party AI services using your own API credentials. When you use BYOK, your data is transmitted directly between your browser and the provider you have connected — Keypra does not act as an intermediary or sub-processor for those requests. Providers you connect via BYOK (such as ElevenLabs, Firecrawl, or Perplexity AI) are your chosen integrations, not Keypra's sub-processors. You are responsible for reviewing the privacy policy and data processing terms of any service you connect via BYOK.

    Note on the Lovable AI Gateway: Keypra does not attach user identifiers, account email, IP address, or other end-user metadata to the request payload sent to the Gateway; only the model name, message contents, and standard generation parameters (e.g. temperature, max tokens) are transmitted. The Gateway forwards requests on a pass-through basis using its own infrastructure IP, so model providers do not receive the data subject's network identifier from Keypra. The content of prompts is not redacted by Keypra and may itself contain personal data if the user includes it. Where an Enterprise customer activates BYOK (Bring Your Own Key), AI requests bypass the Lovable AI Gateway and are sent directly to the customer's own model provider account.

    Note on OpenRouter (not a sub-processor): Keypra's internal admin tooling periodically performs an unauthenticated GET https://openrouter.ai/api/v1/models to monitor newly released AI models for governance review. This request transmits no personal data, no prompts, no account identifiers, and no end-user metadata — it only retrieves OpenRouter's public model catalogue. OpenRouter does not process any personal data on Keypra's behalf and is therefore not a sub-processor under GDPR Article 28. No production AI traffic from Keypra users is ever routed through OpenRouter; all generative AI calls go through the Lovable AI Gateway listed above (or, where Enterprise BYOK is enabled, directly to the customer's own provider).

    2a. Marketing & Advertising Technologies (Consent-Gated)

    The providers below are not GDPR Article 28 sub-processors — Keypra does not instruct them to process data on Keypra's behalf. Each acts as an independent controller for its own ad-measurement and conversion-tracking purposes when a visitor has granted Marketing consent. They are listed here, separately from Section 2, for the same transparency reasons that apply to sub-processors: German courts and data protection authorities (see e.g. the June 2026 Stuttgart Higher Regional Court decision on loss-of-control damages arising from vendor/tracking services) treat incomplete disclosure of third-party tracking tools as a material transparency failure, regardless of whether the vendor is technically a "processor."

    ProviderLegal entityTechnologyPurposeData shared (when consent is granted)LocationTransfer safeguard
    Google Analytics 4Google Ireland Ltd (EEA) / Google LLC (US)Analytics tag (gtag.js, measurement ID G-Y8FE3QV5RG, property 548361453)Aggregate audience measurement (page views, sessions, traffic sources, approximate region) for product and marketing decisionsPage path and title, referrer, approximate country/region derived from IP (IP anonymisation on), device/browser class, non-identifying product-event counts. No user IDs, e-mail addresses, prompt or document content. Google Signals and ads personalisation off; event/user data retention set to 2 monthsEU / USEU-US Data Privacy Framework (Google is a verified participant)
    Google AdsGoogle Ireland Ltd (EEA) / Google LLC (US)Conversion tag (gtag.js, account AW-18144700120)Conversion tracking for paid-search and display advertising campaignsHashed/pseudonymous click identifiers, conversion event name, page URL, approximate value/currency where configuredEU / USEU-US Data Privacy Framework (Google is a verified participant)
    LinkedIn Insight TagLinkedIn Ireland Unlimited Company (EEA), data may be processed by Microsoft group entities in the USInsight Tag (Partner ID 10229937)Conversion tracking and campaign reporting for LinkedIn advertisingPage visit and conversion events, LinkedIn-set identifiers (li_gc, lidc, bcookie, bscookie)EU / USStandard Contractual Clauses (SCCs)
    X (Twitter) PixelX CorpPixel (ID rcjxd) and server-side Conversion APIConversion tracking and campaign reporting for X advertisingConversion event name, page URL, X-set identifiers (_twclid, personalization_id). Keypra may also send server-side conversion events: conversion type and timestamp only for email-lane signups (anonymous by design); the stored ad click ID for web signups only when Marketing consent was grantedUSStandard Contractual Clauses (SCCs)

    Consent gating (technical implementation). All four scripts are wired through Keypra's cookie-consent layer (see src/lib/analytics/ga4.ts, googleAds.ts, linkedinInsight.ts, xPixel.ts, and PrivacyGuard.tsx):

    • The Google Analytics 4 tag is injected only when Analytics consent is active, and is removed with its _ga / _ga_* cookies cleared on withdrawal. A read-only Google Cloud service account reads aggregated reports through the Google Analytics Data API to render Keypra's internal admin dashboard; it sends no personal data to Google.
    • The Google Ads base tag is present on every page load so Google Consent Mode v2 can receive the visitor's choice, but defaults to ad_storage/ad_user_data/ad_personalization denied until Marketing consent is granted.
    • The LinkedIn Insight Tag and X Pixel scripts are only injected into the page — and are removed, with their cookies cleared, on withdrawal — when Marketing consent is active.
    • CCPA/CPRA and Global Privacy Control (GPC): all four are hard-disabled for visitors geolocated to California and for any browser sending the GPC signal, regardless of the visitor's Marketing-cookie choice, to honour Keypra's "do not sell or share" commitment (Privacy Policy §16.3, Terms §18).

    Why these are not listed as Article 28 sub-processors. Google (for both Analytics and Ads), LinkedIn, and X each determine, independently of Keypra, the purposes and means of their own ad-measurement processing (e.g. cross-site conversion modelling, audience building for their own ad platforms) and publish their own privacy notices governing that processing. This is the standard controller/processor analysis applied to advertising pixels under EDPB Guidelines 8/2020 (on the concepts of controller and processor). Keypra's role is limited to consent-gating the technologies and disclosing them here and in the Cookie Policy; it does not receive or process the data these providers collect through their own tags beyond aggregate campaign-performance reporting shown in each platform's ad dashboard.

    3. Sub-Processor Details

    Lovable Cloud (Supabase) Keypra's backend infrastructure is provided through Lovable Cloud, which is built on Supabase's foundation and provides database, authentication, storage, and related backend services. Keypra uses EU regional hosting in Lovable Cloud where configured, and data residency is intended to remain in the selected region by default. Data at rest is encrypted using AES-256; data in transit is encrypted via TLS 1.3. Data is retained for the duration of the user's account. Upon account deletion, all associated data is permanently erased within 30 days.

    Lovable AI Gateway Pass-through HTTPS proxy operated by Lovable AB that routes AI requests from the Keypra backend to the underlying model providers (Google, OpenAI). Keypra does not attach end-user IP, account email, or other end-user identifiers to outbound requests; only the model name, message contents, and standard generation parameters (e.g. temperature, max tokens) are transmitted. The Gateway does not persist message content beyond standard short-lived operational logs. Transfer safeguard: Standard Contractual Clauses (SCCs).

    Google (Gemini) Provides AI language model capabilities including Gemini 2.5 Pro, Gemini 2.5 Flash, Gemini 2.5 Flash Lite, Gemini 3 Pro, Gemini 3 Flash, and Gemini 3.1 Pro/Flash models. Google is a verified participant in the EU-US Data Privacy Framework. Under our API agreements, Google's data processing terms provide that customer data sent via the API is not used to train or improve Google's models.

    OpenAI OpenAI is used for AI language-model processing. It may process prompt text, response text, and limited technical metadata required to deliver the requested functionality. Under OpenAI's published API terms, API customer content is not used to train OpenAI models by default. OpenAI states that additional retention controls may be available only for eligible customers and only when approved and enabled. Keypra therefore does not state that zero data retention applies to every OpenAI request. OpenAI-related transfers are addressed through the transfer safeguard identified in this document.

    Perplexity AI, Inc. Used only when a user runs a Workflow that contains a search node. The user's query text is sent to Perplexity along with the configured model (e.g. sonar, sonar-pro). Per Perplexity's API terms, API content is not used to train consumer-facing models. Transfer safeguard: Standard Contractual Clauses (SCCs).

    Firecrawl (Mendable Labs, Inc.) Triggered when a Workflow contains a scrape or crawl node, or when Rafy Researcher fetches a URL. The URL is validated server-side (no internal/private IPs, no file:// or javascript: schemes) and Firecrawl returns markdown/HTML/screenshots which are processed in-memory and stored in the user's Workflow run record. Per Firecrawl's terms, scraped content is not used to train models. Transfer safeguard: Standard Contractual Clauses (SCCs).

    ElevenLabs Inc. Triggered only when a Workflow contains a voice node. The text the user has chosen to vocalise and the selected voice ID are sent over TLS; the returned audio is streamed back and stored in the user's Workflow run record. Per ElevenLabs' Enterprise/API terms, API customer content is not used to train ElevenLabs voice models. Transfer safeguard: Standard Contractual Clauses (SCCs).

    Resend Handles transactional email delivery including email verification, password resets, authentication notifications, and system alerts. Email delivery logs are retained by Resend for approximately 30 days for deliverability monitoring. Transfer safeguard is based on Standard Contractual Clauses (SCCs).

    Resend — inbound receiving (Keypra by Email). Resend also operates the MX records for the in.keypra.com subdomain (DKIM and SPF verified) and receives mail addressed to ask@in.keypra.com. Resend passes each message to Keypra over a signed webhook; the signature is verified before any content is parsed. In this role Resend processes the sender address, display name, subject, message body, attachments and CC addresses. Provider-side logs are retained by Resend for approximately 30 days. Keypra's own retention for this channel is described in the Privacy Policy §2b and the DPA §3. Replies sent through this channel carry no open or click tracking; Resend's domain-level tracking is disabled for it.

    AI sub-processors and the email channel. The AI providers listed above (Lovable AI Gateway, Google, OpenAI) also process the content of e-mail sent to ask@in.keypra.com, on exactly the terms that apply to prompts typed into the application, including the no-training posture set out in §4b.

    Stripe Processes all payment transactions including subscription billing, one-time credit purchases, invoice generation, and payment method management. Buyer billing details (legal company name, VAT/Tax ID, registered address, billing contact) are collected by Stripe Checkout and stored by Stripe — Keypra does not mirror these fields in its own database and retains only an opaque Stripe customer reference. Payment card details are tokenised; Keypra never receives or stores raw card numbers. Stripe is a verified participant in the EU-US Data Privacy Framework. Payment and invoice records are retained by Stripe in accordance with financial regulatory requirements (typically 7 years for tax and audit compliance). Customers can view and edit their billing details at any time via Settings → Billing → Manage in Stripe (Stripe Customer Portal).

    Linear Orbit, Inc. Issue-tracking system used internally by the Keypra engineering team. Only personal data that a user voluntarily types into the in-app "Report a bug" form (description, optional screenshots, plus the reporter's account email and ID for follow-up) is sent to Linear. No automatic telemetry, no analytics, no full-session capture. Used solely to track and resolve user-reported issues. Transfer safeguard: Standard Contractual Clauses (SCCs).

    Zoho Corporation Pvt. Ltd. (Zoho Mail) Provides inbound email infrastructure for all keypra.com addresses and internal company email for Keypra staff. Personal data processed includes email metadata (sender address, recipient, subject line, timestamps) and the content of email messages sent to or from keypra.com addresses. Any personal data a sender chooses to include in a message to Keypra is processed by Zoho for delivery and storage. Hosted in Zoho's EU region (Netherlands datacenter). Encryption in transit (TLS) and at rest. DPA available on request via privacy@keypra.com.

    Xolo OÜ Estonian e-residency business services provider used by Keypra for accounting, invoicing, and bookkeeping in compliance with Estonian tax and accounting law. Personal data processed includes customer billing information contained in invoices: company name, contact name, email address used for invoice delivery, VAT identification number where applicable, and transaction amounts. Payment processing itself is performed by Stripe; Xolo handles the accounting and record-keeping that follows. Financial records are retained for 7 years as required by the Estonian Accounting Act §12. Hosted in Estonia (EU). Encryption in transit (TLS) and at rest. DPA available on request via privacy@keypra.com.

    Server-Side Fetching (Workflow 'Your Context' node) When you supply a URL to a workflow's 'Your Context' node, Keypra's backend fetches that URL on your behalf using a dedicated User-Agent: Keypra-UserContext/1.0. The destination server will see Keypra's infrastructure IP, not yours. URLs are validated against an internal allow-list (no internal/private IPs, no file:// or javascript: schemes) before fetching. The fetched content is processed in-memory only and is not retained — no third-party sub-processor receives the URL or its contents beyond the destination server you chose to address.

    4. International Transfers

    Some of the providers listed on this page process personal data outside the European Economic Area (EEA).

    Where personal data is transferred outside the EEA, Keypra relies on an appropriate transfer mechanism under the GDPR, including the EU-US Data Privacy Framework where applicable and the European Commission's Standard Contractual Clauses where applicable.

    Keypra does not claim that all personal data always remains within the EU or the EEA. Primary application hosting is configured in the European Union, but certain AI, payment, and email-related processing may involve providers located in, or processing data from, other jurisdictions.

    Keypra applies contractual, organisational, and technical safeguards designed to protect personal data during cross-border processing, including encryption in transit, encryption at rest, access controls, and audit logging.

    4a. Transfer Impact Assessment (Schrems II)

    Where personal data is transferred from the EEA to a third country, Keypra has carried out a Transfer Impact Assessment (TIA) in line with the European Data Protection Board's Recommendations 01/2020 on supplementary measures (the post-Schrems II framework). The TIA covers each US-located sub-processor listed in Section 2 and is reviewed at least annually and on every material change to a sub-processor or to the relevant third-country surveillance regime.

    Supplementary technical and organisational measures already in place

    The following measures apply across all transfers covered by Standard Contractual Clauses or the EU-US Data Privacy Framework, in addition to the standard contractual safeguards:

    • Encryption in transit: TLS 1.2 or above for every API call to a sub-processor; TLS 1.3 between the browser and Keypra's edge.
    • Encryption at rest: AES-256 at the database and object-storage layer (Lovable Cloud / Supabase EU region).
    • Pseudonymisation of telemetry: behavioural-telemetry and consent-ledger rows are stored against a SHA-256 hash of the user id rather than the id itself, so a third-country compelled-disclosure request would not return a directly identifiable record from those tables.
    • No end-user identifiers on AI Gateway requests: Keypra does not attach the end-user's IP, account email, or other identifier to the request payload sent to the Lovable AI Gateway. Upstream model providers (Google, OpenAI) receive only the model name, message contents and standard generation parameters, forwarded from the Gateway's own infrastructure IP.
    • Short-lived sub-processor logs: Resend delivery logs ~30 days; AI provider operational logs are not retained beyond the providers' standard short windows; no end-user prompt or response content is mirrored back into Keypra's own database from those logs.
    • Enterprise BYOK option: Enterprise customers may activate Bring-Your-Own-Key, which routes AI traffic directly to their own model-provider account, removing both the Lovable AI Gateway and the upstream provider from Keypra's processing chain for that organisation.
    • Access controls and audit logging: least-privilege RLS at the database layer; access by Keypra staff is logged and reviewed.
    • Vendor-side commitments: the upstream AI providers (Google, OpenAI) state, in their public API terms, that API content is not used to train consumer-facing models by default; Stripe is a verified participant in the EU-US Data Privacy Framework; Google (Gemini API) is a verified participant in the EU-US Data Privacy Framework.

    TIA conclusion (US transfers, Section 702 FISA / EO 12333)

    Taking the above measures together with the categories of data transferred (no special-category data, pseudonymised telemetry, no end-user IP on AI requests, payment data held by Stripe under DPF rather than mirrored into Keypra), Keypra concludes that the residual risk of access to identifiable personal data by US authorities under Section 702 FISA or Executive Order 12333 is not such as to undermine the essence of the rights of EEA data subjects in the meaning of Schrems II. The supplementary measures listed above are accordingly relied on as adequate for the transfers in scope.

    This conclusion is a Keypra assessment and does not bind any supervisory authority. EEA-based Enterprise customers may request the underlying TIA worksheet, including the per-provider analysis, by writing to privacy@keypra.com.

    No transfer to Russia, China, or other jurisdictions outside the EEA / DPF perimeter

    Keypra does not currently use sub-processors located in Russia, China, India (for AI inference), or any other jurisdiction that would require a separate TIA outside the framework above. If that changes, this page will be updated under the 30-day advance notice in Section 5.

    4b. AI Sub-Processor Training-Data Posture

    Keypra does not use Customer Content to train any AI or machine-learning model. Where Keypra forwards prompts to a third-party AI sub-processor to fulfil a user request, we rely on each provider's enterprise/API terms which state that customer API content is not used to train the provider's foundation models by default. The current posture of each AI sub-processor is recorded below and reviewed at least annually and promptly upon a material change.

    AI Sub-ProcessorTraining-Data Posture (default, on Keypra's enterprise/API tier)Last Reviewed
    Google (Gemini via Gemini API / Vertex AI)Customer API content not used to train Google's foundation models.May 2026
    OpenAI (GPT via API)Customer API content not used to train OpenAI's foundation models (default since 1 March 2023).May 2026
    Anthropic (Claude — used only in Deep Workflows behind Enterprise BYOK)Customer API content not used to train Anthropic models (commercial API default).May 2026
    Lovable AI Gateway (Lovable AB)Routing layer only; holds no Customer Content at rest and runs no training on customer traffic.May 2026
    Perplexity AI (search node)Search queries not used to train Perplexity models (Enterprise API default).May 2026
    ElevenLabs (TTS)Customer audio prompts not used to train ElevenLabs models (commercial API default).May 2026

    Change-notice trigger. Where a sub-processor announces a material change to its training-data posture that would affect Customer Content sent via Keypra, Keypra will (i) update this section within 14 days, (ii) post the change to the changelog in Section 5, and (iii) for Enterprise customers, notify the Customer's nominated contact under the 30-day sub-processor change notice in §6 of the DPA (/legal/dpa).

    No Customer Content used by Keypra itself. Keypra's own analytics and product-improvement work uses only aggregated, anonymised usage statistics (counts, error rates, feature-popularity tallies). No prompt text, response text, uploaded file content, or Behavioural Telemetry is used for model training of any kind. The same commitment is mirrored in Privacy Policy §6b and DPA §4a.

    5. Changes to This List

    We will provide a minimum of 30 days' advance notice before engaging any new sub-processor or making material changes to how an existing sub-processor handles personal data. Notice will be provided via:

    • Email notification to registered users
    • An update to this page with the revised effective date

    Right to Object: If you object to a new sub-processor, you may contact us at privacy@keypra.com within the 30-day notice period. We will work with you to find a resolution, which may include alternative processing arrangements or, if no resolution is possible, the option to terminate your account with a pro-rata refund for any prepaid period.

    Change Log

    DateChange
    September 7, 2026Broadened the Resend entry to cover inbound receiving for the in.keypra.com subdomain (ask@in.keypra.com), which powers the "Keypra by Email" channel: MX, DKIM and SPF for that subdomain, signed inbound webhook delivery, and the sender address, subject, body, attachments and CC addresses processed in that role. Recorded that the AI sub-processors already listed also process e-mail content on the same no-training terms, and that concierge replies carry no open or click tracking. Privacy Policy §2b, §2c, §6a, §8a, §9, §11, §17, DPA §3, §3a, §5, §8, Terms §21 and the §203 StGB addendum were updated in the same revision. Transparency disclosure of an existing channel — no new sub-processor engaged.
    August 4, 2026Added Google Analytics 4 (measurement ID G-Y8FE3QV5RG, property 548361453, Google Ireland Ltd / Google LLC) to Section 2a as a consent-gated analytics technology, together with its data categories, the _ga / _ga_* cookies, the 2-month event/user-data retention configured on the property, and confirmation that Google Signals and ads personalisation are switched off. The Privacy Policy (§7, §8, §10, §16.3), Cookie Policy (§1, §2, §4) and Terms §18.3 were updated in the same revision; the previous statement that Keypra ran no separate GA4 property was removed. Also records the read-only Google Analytics Data API access used by Keypra's internal admin analytics dashboard.
    July 21, 2026Added Section 2a — Marketing & Advertising Technologies, naming Google Ads (AW-18144700120), the LinkedIn Insight Tag (Partner ID 10229937), and the X Pixel (rcjxd) as consent-gated advertising technologies already live in the codebase, with their legal entities, data categories, and transfer safeguards. Prompted by German court and regulator reporting (June–July 2026, incl. the Stuttgart Higher Regional Court loss-of-control ruling) on liability for undisclosed third-party tracking tools. This is a transparency correction — the technologies were already consent-gated in code; this page and the Privacy/Cookie Policies previously did not name them. No new processing activities introduced.
    May 16, 2026Added Section 4a — public Transfer Impact Assessment statement (Schrems II), enumerating the supplementary technical/organisational measures already applied to US transfers (encryption, pseudonymisation, no end-user identifiers on AI Gateway requests, Enterprise BYOK option) and recording Keypra's Section 702 / EO 12333 residual-risk conclusion. No new processing activities introduced; this is a transparency disclosure.
    May 16, 2026Aligned Terms of Service §8.3 with this page — Terms now incorporates the Sub-Processor list by reference rather than duplicating a partial table that had drifted out of date. No new processing activities introduced; this is a transparency correction.
    May 10, 2026Data minimisation: removed local storage of B2B invoicing fields (legal company name, VAT ID, billing address, billing contact) from Keypra's database. Stripe is now the sole source of truth for buyer billing data; Keypra retains only an opaque Stripe customer reference. Customers manage their billing details via the Stripe Customer Portal. Privacy Policy Section 2a and Terms Section 5.10 updated accordingly.
    May 9, 2026Clarified that the Stripe sub-processor entry now also covers B2B invoicing data (legal company name, VAT/Tax ID, registered billing address, billing contact) supplied via the new "Buying as → Company" checkout flow. This is a transparency update — Stripe was already an authorised sub-processor; the categories of data forwarded have been broadened to support compliant invoices. See Privacy Policy Section 2a.
    May 7, 2026Added explicit transparency note clarifying that OpenRouter is not a sub-processor: it is only queried by internal admin tooling for its public model catalogue, with no personal data transmitted. No change to processing activities.
    April 23, 2026Added Perplexity AI, Firecrawl, ElevenLabs, Linear, and Lovable AI Gateway to the published sub-processor list to reflect providers already in active use. No new processing activities introduced; this is a transparency correction.
    April 18, 2026Added Xolo OÜ as sub-processor for accounting and financial record-keeping (Estonian Accounting Act §12 compliance)
    April 18, 2026Added Zoho Mail as sub-processor for inbound and internal company email
    March 20, 2026Updated sub-processor list with accurate transfer safeguards; removed unsupported claims; aligned with updated Privacy Policy and Terms
    March 15, 2026Previous version published
    March 1, 2026Initial sub-processor list published

    6. Data Processing Agreements

    Copies of our Data Processing Agreements (DPAs) with each sub-processor listed on this page are available upon request.

    To request a copy, contact us at privacy@keypra.com with the subject line "DPA Request."

    Enterprise DPA: Enterprise customers may request a dedicated Data Processing Agreement covering the full scope of data processing by Keypra and its sub-processors, including annexes detailing specific data categories, processing activities, technical and organisational security measures (TOMs), and data breach notification procedures.

    Subscribing to sub-processor change notifications. Organisation administrators are automatically subscribed to sub-processor change notifications at the organisation's billing-contact address on file. To subscribe an additional procurement, security, or DPO mailbox, email enterprise@keypra.com with subject tag [SUBPROCESSOR-NOTICE] and the address(es) to add. Personal-plan customers are notified via the email address on the account.

    7. Contact

    For any questions regarding sub-processors, data processing, or the exercise of your GDPR rights:

    • Privacy inquiries: privacy@keypra.com
    • Entity: Keypra OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia, Tallinn, Estonia
    • Registry code: 17502390
    • Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), https://www.aki.ee/en