Legal
Subprocessors
Third-party services that process personal data on behalf of PAIQ, with their location and applicable safeguards.
PAIQ RAAS, S.L. ("PAIQ", "we", "us", or "our") engages a small number of carefully selected third-party providers ("subprocessors") that process personal data on our behalf to operate the PAIQ service. This page lists every active subprocessor, the purpose of processing, the location of processing, and the legal mechanism we rely on for any transfer of data outside the European Economic Area.
This list is maintained in line with our obligations under Article 28 GDPR and the transparency requirements of our Privacy Policy. We update this page whenever we add, replace, or remove a subprocessor.
1. Product Subprocessors
These providers process personal data of PAIQ account holders and Instagram message senders as part of delivering the core service.
| Subprocessor | Purpose | Data categories | Location | Transfer mechanism |
|---|---|---|---|---|
| Hetzner Online GmbH | Cloud hosting and infrastructure | All account, billing, message, and log data | Germany (EU) | Within EU — no transfer mechanism required |
| Scaleway, S.A.S. | Encrypted off-site database backups (object storage, fr-par region) | Backup copies of all account, billing, message, and log data | France (EU) | Within EU, no transfer mechanism required |
| Stripe Payments Europe, Ltd. | Subscription billing and payment processing | Name, email, billing address, payment tokens (card numbers are not stored by PAIQ) | Ireland (EU); processing may extend to United States | EU processing primary; SCCs (Module 2) for any US transfer |
| OpenAI Ireland Limited | AI inference (GPT-4o) used to draft replies to incoming DMs | DM content, sent via API to generate a reply. OpenAI may retain it for up to 30 days for abuse monitoring, or longer where its policies or the law require; PAIQ does not direct or extend that retention | Ireland (EU); processing may extend to United States | SCCs (Module 2). Customer data is not used to train OpenAI models. |
| Anthropic, PBC | AI inference (Claude) used to draft replies to incoming DMs | DM content, sent via API to generate a reply. Anthropic may retain it for up to 30 days for abuse monitoring, or longer where its policies or the law require; PAIQ does not direct or extend that retention | United States | SCCs (Module 2). Customer data is not used to train Anthropic models. |
Meta (independent controller): Meta Platforms Ireland Ltd., Instagram and the Meta Graph API. PAIQ connects to Meta on the Customer's instruction to send and receive the Customer's Instagram direct messages. Meta processes this data as an independent controller under its own terms, not as a PAIQ sub-processor.
2. Operational Subprocessors
These providers process personal data collected through our website and marketing channels — for example, contact form submissions, conversations with our website assistant, and lead intake. They do not process Instagram DM data.
| Subprocessor | Purpose | Data categories | Location | Transfer mechanism |
|---|---|---|---|---|
| OpenAI Ireland Limited | Website voice and chat assistant ("Kemi"), via the OpenAI Realtime API | Voice audio and text transcripts of the conversation, and any contact details the visitor provides | Ireland (EU); processing may extend to United States | SCCs (Module 2) and EU–US Data Privacy Framework where applicable. Customer data is not used to train OpenAI models. |
| Airtable, Inc. | Lead capture and CRM for website conversations | Name, email, conversation summary, lead status | United States | SCCs (Module 2) |
| Resend, Inc. | Transactional email delivery (account verification, billing receipts, security and product notifications) | Name, email address, message content | United States; EU sending region (Ireland) used where available | SCCs (Module 2) and EU–US Data Privacy Framework where applicable |
Service providers, PAIQ Access
For the PAIQ Access accessibility checker (access.paiq.io) PAIQ is the data controller and processes no personal data on behalf of its customers, so these are PAIQ's own service providers, not sub-processors engaged on behalf of a Customer.
| Service provider | Purpose | Data categories | Location | Transfer mechanism |
|---|---|---|---|---|
| Stripe Payments Europe, Ltd. | Payment processing for single reports and the Agency plan | Buyer email, billing details and payment data (card data never stored by PAIQ) | Ireland (EU); Stripe group entities worldwide | SCCs and EU-US Data Privacy Framework where applicable |
| Resend, Inc. | Delivery of unlock codes and reports by email | Recipient email address and the attached report; delivery data retained by the provider for up to 30 days | United States | SCCs, and EU-US Data Privacy Framework (with UK Extension) where applicable |
| Hostinger International Ltd. | Application hosting and server logs for access.paiq.io | IP address and connection data in server logs; scanned URLs processed transiently | Frankfurt, Germany (EU); provider established in Cyprus (EU) | EU hosting, no third-country transfer by PAIQ; the provider's own sub-processors are governed by its DPA |
3. International Data Transfers
Where a subprocessor is located outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (SCCs, Module 2 — Controller to Processor) as the lawful basis for transfer under Chapter V of the GDPR. Where the relevant US-based provider is certified under the EU–US Data Privacy Framework, that framework is also relied upon.
We assess each transfer on a case-by-case basis and, where appropriate, apply supplementary technical and organisational measures (encryption in transit and at rest, access controls, data minimisation, and limited retention windows).
4. Infrastructure and Internal Tooling
The following systems are used internally by PAIQ to operate the business but are not subprocessors of personal data of our customers' end users:
- Self-hosted services on Hetzner — application database (PostgreSQL), cache (Redis), automation runner (n8n). All are hosted within our EU infrastructure and are not separate subprocessors.
- Internal collaboration tools — used by the founding team for code, documentation, and project management. These do not store customer-end-user personal data.
5. Adding or Replacing a Subprocessor
We will update this page whenever we add, replace, or remove a subprocessor that processes personal data on behalf of PAIQ customers. Customers on a Data Processing Agreement may subscribe to advance notice of changes by emailing hello@paiq.io. Where a customer reasonably objects to a new subprocessor on data protection grounds, we will work in good faith to address the concern.
6. Contact
For any questions about our subprocessors or to request a copy of our Data Processing Agreement (DPA):
hello@paiq.io
PAIQ RAAS, S.L. — NIF B27677392 — Málaga, Spain