Article 28 of Regulation (EU) 2016/679 (the "GDPR") requires a controller to use only processors providing sufficient guarantees, and to keep that information available. This page lists the providers the KATABUMP Association relies on to deliver its services, and which may process personal data on its behalf.
It supplements Article 6 of the privacy policy, which describes the categories of recipients, and Article 3 of the legal notice, which identifies our hosting providers.
1. Hosting and infrastructure
| Subprocessor | Role | Data location | Transfer safeguards |
|---|---|---|---|
| OVHcloud SAS 2 rue Kellermann, 59100 Roubaix, France |
Customer servers and nodes (Gravelines data centre), pma.katabump.fr, signalement.kdns.fr |
France (EEA) | Not applicable — processing within the EEA |
| Clever Cloud SAS 4 rue Voltaire, 44000 Nantes, France |
dashboard.katabump.com and control.katabump.com |
France (EEA) | Not applicable — processing within the EEA |
| Hetzner Online GmbH Industriestr. 25, 91710 Gunzenhausen, Germany |
status.katabump.fr — service status page |
Germany (EEA) | Not applicable — processing within the EEA |
| BunnyWay d.o.o. (bunny.net) Dunajska cesta 165, 1000 Ljubljana, Slovenia |
altcha.katabump.fr, cdn.katabump.fr, cdn.katabump.eu and this site |
Registered in the EEA; delivery from a global network of points of presence (global mode) | bunny.net data processing agreement (DPA) |
| Cloudflare, Inc. 101 Townsend St, San Francisco, CA 94107, United States |
katabump.com and docs.katabump.com; DNS and denial-of-service protection |
Global network, including outside the EEA | EU-US Data Privacy Framework and standard contractual clauses approved by the European Commission |
In accordance with Article 10 of the privacy policy, primary data hosting is located in France. The data that transits through Cloudflare is limited to technical data (IP address, session cookies, browsing data), used solely for caching, security and network performance purposes, and retained only for as long as strictly necessary.
2. AI Assistant
| Subprocessor | Role | Data location | Transfer safeguards |
|---|---|---|---|
| OpenRouter | Routing of requests to language model providers, to operate the AI Assistant | European Union | Not applicable — processing within the European Union |
| Model providers selected by OpenRouter | Generation of the AI Assistant's answers | European Union | Not applicable — processing within the European Union |
As stated in Article 13 of the privacy policy, the routing service is configured to select only model providers that undertake not to retain or store the content of exchanges (zero data retention). It is further configured to select only providers whose inference runs within the European Union: conversations with the AI Assistant therefore do not leave the Union. Exposure of your conversations to those third parties is limited to the technical processing time needed to generate an answer. Conversations do, however, remain stored on the Association's own systems for as long as the account is active.
3. Payment
| Provider | Role | Data location | Transfer safeguards |
|---|---|---|---|
| PayPal (Europe) S.à r.l. et Cie, S.C.A. 22-24 Boulevard Royal, L-2449 Luxembourg |
Processing of payments for the purchase of Credits | Luxembourg (EEA) | Determined by PayPal as controller (see its privacy policy) |
PayPal is not a processor of the Association: as a payment institution it determines the purposes and means of processing payment data itself, in order to meet its own regulatory obligations. It appears on this page for transparency. As Article 3 of the privacy policy states, payment details (card number, bank details) are processed directly by PayPal and are never stored on the Association's servers.
3.1 Analytics
The Association uses no analytics tool, no advertising network and no statistical tracker on its sites. No subprocessor is therefore involved on that basis.
4. Safeguards applying to all our subprocessors
Each subprocessor is contractually required:
- to process data only on the Association's documented instructions;
- to ensure the confidentiality of the data and to grant access only to those who need it;
- to implement appropriate technical and organisational measures within the meaning of Article 32 of the GDPR;
- to assist the Association in handling data subject requests and in notifying personal data breaches;
- to delete or return the data at the end of the engagement.
The terms that apply where you, rather than the Association, determine the purposes of a processing operation carried out through our services are set out in the data processing agreement.
5. Changes to this list
We update this page whenever a subprocessor changes. If you wish to be notified in advance of the addition or replacement of a subprocessor, write to us at privacy@katabump.com: we will maintain a mailing list for that purpose.
6. Contact
For any question about this list or the applicable safeguards: privacy@katabump.com.