Subprocessors

The providers that process data on our behalf, their role and their location.

In force Last updated:

The French version of this document is the official and legally binding version. This English translation is provided for convenience only.

Article 28 of Regulation (EU) 2016/679 (the "GDPR") requires a controller to use only processors providing sufficient guarantees, and to keep that information available. This page lists the providers the KATABUMP Association relies on to deliver its services, and which may process personal data on its behalf.

It supplements Article 6 of the privacy policy, which describes the categories of recipients, and Article 3 of the legal notice, which identifies our hosting providers.

1. Hosting and infrastructure

Subprocessor Role Data location Transfer safeguards
OVHcloud SAS
2 rue Kellermann, 59100 Roubaix, France
Customer servers and nodes (Gravelines data centre), pma.katabump.fr, signalement.kdns.fr France (EEA) Not applicable — processing within the EEA
Clever Cloud SAS
4 rue Voltaire, 44000 Nantes, France
dashboard.katabump.com and control.katabump.com France (EEA) Not applicable — processing within the EEA
Hetzner Online GmbH
Industriestr. 25, 91710 Gunzenhausen, Germany
status.katabump.fr — service status page Germany (EEA) Not applicable — processing within the EEA
BunnyWay d.o.o. (bunny.net)
Dunajska cesta 165, 1000 Ljubljana, Slovenia
altcha.katabump.fr, cdn.katabump.fr, cdn.katabump.eu and this site Registered in the EEA; delivery from a global network of points of presence (global mode) bunny.net data processing agreement (DPA)
Cloudflare, Inc.
101 Townsend St, San Francisco, CA 94107, United States
katabump.com and docs.katabump.com; DNS and denial-of-service protection Global network, including outside the EEA EU-US Data Privacy Framework and standard contractual clauses approved by the European Commission

In accordance with Article 10 of the privacy policy, primary data hosting is located in France. The data that transits through Cloudflare is limited to technical data (IP address, session cookies, browsing data), used solely for caching, security and network performance purposes, and retained only for as long as strictly necessary.

2. AI Assistant

Subprocessor Role Data location Transfer safeguards
OpenRouter Routing of requests to language model providers, to operate the AI Assistant European Union Not applicable — processing within the European Union
Model providers selected by OpenRouter Generation of the AI Assistant's answers European Union Not applicable — processing within the European Union

As stated in Article 13 of the privacy policy, the routing service is configured to select only model providers that undertake not to retain or store the content of exchanges (zero data retention). It is further configured to select only providers whose inference runs within the European Union: conversations with the AI Assistant therefore do not leave the Union. Exposure of your conversations to those third parties is limited to the technical processing time needed to generate an answer. Conversations do, however, remain stored on the Association's own systems for as long as the account is active.

3. Payment

Provider Role Data location Transfer safeguards
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22-24 Boulevard Royal, L-2449 Luxembourg
Processing of payments for the purchase of Credits Luxembourg (EEA) Determined by PayPal as controller (see its privacy policy)
PayPal acts as a controller

PayPal is not a processor of the Association: as a payment institution it determines the purposes and means of processing payment data itself, in order to meet its own regulatory obligations. It appears on this page for transparency. As Article 3 of the privacy policy states, payment details (card number, bank details) are processed directly by PayPal and are never stored on the Association's servers.

3.1 Analytics

The Association uses no analytics tool, no advertising network and no statistical tracker on its sites. No subprocessor is therefore involved on that basis.

4. Safeguards applying to all our subprocessors

Each subprocessor is contractually required:

  • to process data only on the Association's documented instructions;
  • to ensure the confidentiality of the data and to grant access only to those who need it;
  • to implement appropriate technical and organisational measures within the meaning of Article 32 of the GDPR;
  • to assist the Association in handling data subject requests and in notifying personal data breaches;
  • to delete or return the data at the end of the engagement.

The terms that apply where you, rather than the Association, determine the purposes of a processing operation carried out through our services are set out in the data processing agreement.

5. Changes to this list

We update this page whenever a subprocessor changes. If you wish to be notified in advance of the addition or replacement of a subprocessor, write to us at privacy@katabump.com: we will maintain a mailing list for that purpose.

6. Contact

For any question about this list or the applicable safeguards: privacy@katabump.com.

Esc
Type to search…