Effective date: August 13, 2026
ProductLift uses a small number of trusted third-party service providers ("subprocessors") to help deliver our service. These subprocessors may process limited personal data on our behalf for the specific purposes listed below.
We carefully evaluate each provider's security, privacy, and compliance posture. Where applicable, we enter into Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs) or other appropriate safeguards.
This page is the authoritative list of ProductLift's sub-processors. It is referenced from, and should be read together with, our Data Processing Agreement.
| Subprocessor | Purpose | Data Categories | Processing Location | Notes |
|---|---|---|---|---|
| Hetzner Online GmbH | Primary application hosting & infrastructure | Account data, content you submit in the app, logs, encrypted backups | Falkenstein, Germany (EEA) | Main hosting provider for ProductLift |
| Amazon Web Services EMEA SARL (AWS S3) | Storage of static assets | File uploads (e.g., images, attachments) | EU-West, Ireland (EEA) | Used for file uploads |
| BunnyWay d.o.o. (Bunny.net) | CDN for static assets (JS, CSS, images) via origin pull | Visitor IP, User-Agent, requested asset URL | Slovenia (EU) | Covered by Bunny.net DPA |
| Mailgun Technologies, Inc. | Transactional email delivery | Recipient email, sender name, message metadata | Frankfurt, Germany (EU) | EU region. Can be replaced by SMTP or another email provider upon request |
| Stripe, Inc. | Payment processing & billing | Billing name, email, payment method details | USA / EU | Processes payments and subscription lifecycle events |
| OpenAI, Inc. | AI language model processing (optional, configurable per customer) | Prompts submitted to AI features and generated outputs | USA | Only used when AI features are enabled. API terms exclude use of input/output for model training. |
| Anthropic, Inc. | AI language model processing (optional, configurable per customer) | Prompts submitted to AI features and generated outputs | USA | Only used when AI features are enabled. API terms exclude use of input/output for model training. |
| Google LLC | AI language model processing via Gemini (optional, configurable per customer) | Prompts submitted to AI features and generated outputs | USA | Only used when AI features are enabled. API terms exclude use of input/output for model training. |
| Boei | Customer support chat (admin area only) | Name, email, chat messages | Nuremberg, Germany (EEA) | Loaded in the admin area for support communications. Operated by Ruby Foundry B.V., the same legal entity as ProductLift; listed for transparency. |
Services you connect to your portal with your own account and credentials (for example Slack, Jira, Azure DevOps, HubSpot, outgoing webhooks, your own Stripe account, or your own email provider) receive data on your instruction. They are not sub-processors of ProductLift and are not listed above; you remain responsible for your agreement with those providers.
Likewise, when an admin asks ProductLift to import a public web page (knowledge-base URL import, or website-based setup), a third-party fetch service receives only that URL and the page's public content. Nothing from your portal, your account or your end-users is sent, so no personal data is processed and the service is not a sub-processor.
We may add or replace subprocessors as our service evolves. When we do, we will update this page. If you have a DPA with ProductLift, we will provide notice in accordance with that agreement.
If you have questions about our subprocessors or need a signed DPA, contact us at [email protected].