Skip to content

Sub-processors

Last updated: September 10, 2026

Eyevinn Technology AB (organization number 556919-9952), which operates the Open Source Cloud platform at osaas.io, engages the third-party sub-processors below to help deliver the Services. Where you use the Services to process personal data, you are the controller and we act as your processor under GDPR Article 28; these sub-processors process personal data on our behalf and on your documented instructions. This page is maintained as the canonical, current list and is also the mechanism by which we notify customers of sub-processor changes (see "Changes to this list" below).

For our standard Data Processing Agreement, contact privacy@eyevinn.se. For how we process data as an independent controller (account, billing, platform operations), see our Privacy Policy.

Where your data is processed

Our primary processing infrastructure is located in Sweden (EU/EEA). Data processed via the Services is hosted in the EU/EEA on this primary infrastructure. Since 25 August 2026 the platform, its API layer and its backend services run on Elastx, a Swedish infrastructure provider. Some sub-processors that provide ancillary functions (authentication, payment, and the AI features) operate from outside the EU/EEA; for those, we rely on the safeguards in the table below.

Current sub-processors

This list covers sub-processors engaged in the delivery of the Services under our Terms of Service, including the platform, the workloads you deploy on it, and the account, billing and support functions that support them. Providers used only to publish this public website and our documentation are not part of that processing and are not listed here.

Infrastructure and hosting

Sub-processorPurposeLocationSafeguards for any non-EU transfer
Elastx ABCompute, storage, networking, and managed Kubernetes for the Services. Where your application and its data are hosted.Stockholm, Sweden (EU/EEA)EU/EEA-resident; no Chapter V transfer arises. Data Processing Agreement in place.

Payment processing

Sub-processorPurposeLocationSafeguards
Stripe (Stripe Payments Europe, Ltd. and affiliates)Processes subscription payments. Stripe acts as an independent controller for payment data under its own privacy policy, so this falls outside our Article 28 processor chain, listed here for transparency.EU (Ireland) with US operationsStripe's Data Processing Agreement and EU Standard Contractual Clauses where applicable. PCI-DSS Level 1.

Authentication (only where you choose that sign-in method)

Sub-processorPurposeLocationSafeguards
GitHub, Inc. (Microsoft)OAuth sign-in when you sign in with GitHub. Minimal data (token, user ID, email).US with EU data centersEU Standard Contractual Clauses (2021/914); Microsoft EU Data Boundary.
Google LLCOAuth sign-in when you sign in with Google. Minimal data (token, user ID, email).US with EU data centersEU Standard Contractual Clauses (2021/914) and a transfer impact assessment are the operative safeguard for this transfer. Google additionally holds an active EU-US Data Privacy Framework certification (verified 2026-08-19); we do not rely on the Framework for this transfer.
Apple Inc."Sign in with Apple" when you choose it. Minimal data (token, user ID, relay email).US with global operationsEU Standard Contractual Clauses (2021/914) and Apple's data-processing terms are the operative safeguard for this transfer. Apple is not certified under the EU-US Data Privacy Framework (verified against the Framework participant list 2026-08-19); we do not rely on the Framework for this transfer.

Email magic-link and passkey (WebAuthn) sign-in involve no third-party identity sub-processor.

Analytics (self-hosted on our EU infrastructure)

ToolPurposeLocationNote
Umami AnalyticsPrivacy-focused, cookieless web analytics. No cookies and no personal identifiers.Self-hosted on our Stockholm (EU/EEA) infrastructureSelf-hosted; no third party has access, so not a separate sub-processor.

AI model providers (the OSC AI assistant and the ask-osc-architect MCP tool)

OSC's AI features send prompt and operational content to a third-party AI model provider. These are the AI assistant in the web console and the ask-osc-architect tool, which is available to any connected MCP client and needs no separate activation. We enforce a 7-day retention limit and pseudonymize user identifiers; the providers do not use this content to train their models under their commercial API terms.

Sub-processorPurposeLocationSafeguards
Anthropic, PBCAI model provider (Claude API) for OSC's AI features.United StatesEU Standard Contractual Clauses (2021/914), Module 3 (processor-to-processor), together with a transfer impact assessment and the supplementary measures described above, are the operative safeguard for this transfer. Data Processing Agreement in place. This recipient is not certified under the EU-US Data Privacy Framework (verified against the Framework participant list 2026-08-19); we do not rely on the Framework for this transfer.
OpenAI, L.L.C. (OpenAI Ireland Ltd. for the EEA)AI model provider (GPT API) for OSC's AI features.United StatesEU Standard Contractual Clauses (2021/914), Module 3 (processor-to-processor), together with a transfer impact assessment and the supplementary measures described above, are the operative safeguard for this transfer. Data Processing Agreement in place (effective January 1, 2026). This recipient is not certified under the EU-US Data Privacy Framework (verified against the Framework participant list 2026-08-19); we do not rely on the Framework for this transfer.

Changes to this list

Update of 10 September 2026. Akamai Technologies, Inc. has been removed. Eyevinn no longer uses Akamai for any part of the Services, and Elastx AB is the sole infrastructure provider for the Services.

Update of 28 August 2026. Elastx AB is the infrastructure provider for the Services, and the Akamai entry has been narrowed to components that have not yet migrated. Cloudflare, Inc. has been removed because it is not engaged in the delivery of the Services as scoped above.

We will notify customers at least 30 calendar days before a material change to this list, by which we mean adding a new sub-processor, or replacing one in a way that introduces a new international transfer or a new category of processing. Notification is by:

  1. updating this page (the canonical, current list); and
  2. emailing the account contact on record.

A change of role among sub-processors already listed here, where no new international transfer and no new category of processing arises, is published on this page rather than notified in advance.

If you object to a new sub-processor on reasonable data-protection grounds within 30 days, we will discuss it in good faith; if unresolved, you may terminate the affected Services without penalty. This applies to all customers, whether or not a separate Data Processing Agreement has been signed.

Questions