Last updated: September 13, 2026  ·  Governing law: Spain (GDPR + LOPDGDD)
13 September 2026: Meta relabelled as an independent controller, Web3Forms removed, PAIQ Access service providers added, Resend listed with the Data Privacy Framework.
17 September 2026: editorial, Meta role label and footer wording, no change to content.

PAIQ RAAS, S.L. ("PAIQ", "we", "us", or "our") engages a small number of carefully selected third-party providers ("subprocessors") that process personal data on our behalf to operate the PAIQ service. This page lists every active subprocessor, the purpose of processing, the location of processing, and the legal mechanism we rely on for any transfer of data outside the European Economic Area.

This list is maintained in line with our obligations under Article 28 GDPR and the transparency requirements of our Privacy Policy. We update this page whenever we add, replace, or remove a subprocessor.

1. Product Subprocessors

These providers process personal data of PAIQ account holders and Instagram message senders as part of delivering the core service.

Subprocessor Purpose Data categories Location Transfer mechanism
Hetzner Online GmbH Cloud hosting and infrastructure All account, billing, message, and log data Germany (EU) Within EU — no transfer mechanism required
Scaleway, S.A.S. Encrypted off-site database backups (object storage, fr-par region) Backup copies of all account, billing, message, and log data France (EU) Within EU, no transfer mechanism required
Stripe Payments Europe, Ltd. Subscription billing and payment processing Name, email, billing address, payment tokens (card numbers are not stored by PAIQ) Ireland (EU); processing may extend to United States EU processing primary; SCCs (Module 2) for any US transfer
OpenAI Ireland Limited AI inference (GPT-4o) used to draft replies to incoming DMs DM content, sent via API to generate a reply. OpenAI may retain it for up to 30 days for abuse monitoring, or longer where its policies or the law require; PAIQ does not direct or extend that retention Ireland (EU); processing may extend to United States SCCs (Module 2). Customer data is not used to train OpenAI models.
Anthropic, PBC AI inference (Claude) used to draft replies to incoming DMs DM content, sent via API to generate a reply. Anthropic may retain it for up to 30 days for abuse monitoring, or longer where its policies or the law require; PAIQ does not direct or extend that retention United States SCCs (Module 2). Customer data is not used to train Anthropic models.

Meta (independent controller): Meta Platforms Ireland Ltd., Instagram and the Meta Graph API. PAIQ connects to Meta on the Customer's instruction to send and receive the Customer's Instagram direct messages. Meta processes this data as an independent controller under its own terms, not as a PAIQ sub-processor.

2. Operational Subprocessors

These providers process personal data collected through our website and marketing channels — for example, contact form submissions, conversations with our website assistant, and lead intake. They do not process Instagram DM data.

Subprocessor Purpose Data categories Location Transfer mechanism
OpenAI Ireland Limited Website voice and chat assistant ("Kemi"), via the OpenAI Realtime API Voice audio and text transcripts of the conversation, and any contact details the visitor provides Ireland (EU); processing may extend to United States SCCs (Module 2) and EU–US Data Privacy Framework where applicable. Customer data is not used to train OpenAI models.
Airtable, Inc. Lead capture and CRM for website conversations Name, email, conversation summary, lead status United States SCCs (Module 2)
Resend, Inc. Transactional email delivery (account verification, billing receipts, security and product notifications) Name, email address, message content United States; EU sending region (Ireland) used where available SCCs (Module 2) and EU–US Data Privacy Framework where applicable

Service providers, PAIQ Access

For the PAIQ Access accessibility checker (access.paiq.io) PAIQ is the data controller and processes no personal data on behalf of its customers, so these are PAIQ's own service providers, not sub-processors engaged on behalf of a Customer.

Service providerPurposeData categoriesLocationTransfer mechanism
Stripe Payments Europe, Ltd.Payment processing for single reports and the Agency planBuyer email, billing details and payment data (card data never stored by PAIQ)Ireland (EU); Stripe group entities worldwideSCCs and EU-US Data Privacy Framework where applicable
Resend, Inc.Delivery of unlock codes and reports by emailRecipient email address and the attached report; delivery data retained by the provider for up to 30 daysUnited StatesSCCs, and EU-US Data Privacy Framework (with UK Extension) where applicable
Hostinger International Ltd.Application hosting and server logs for access.paiq.ioIP address and connection data in server logs; scanned URLs processed transientlyFrankfurt, Germany (EU); provider established in Cyprus (EU)EU hosting, no third-country transfer by PAIQ; the provider's own sub-processors are governed by its DPA

3. International Data Transfers

Where a subprocessor is located outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (SCCs, Module 2 — Controller to Processor) as the lawful basis for transfer under Chapter V of the GDPR. Where the relevant US-based provider is certified under the EU–US Data Privacy Framework, that framework is also relied upon.

We assess each transfer on a case-by-case basis and, where appropriate, apply supplementary technical and organisational measures (encryption in transit and at rest, access controls, data minimisation, and limited retention windows).

4. Infrastructure and Internal Tooling

The following systems are used internally by PAIQ to operate the business but are not subprocessors of personal data of our customers' end users:

5. Adding or Replacing a Subprocessor

We will update this page whenever we add, replace, or remove a subprocessor that processes personal data on behalf of PAIQ customers. Customers on a Data Processing Agreement may subscribe to advance notice of changes by emailing hello@paiq.io. Where a customer reasonably objects to a new subprocessor on data protection grounds, we will work in good faith to address the concern.

6. Contact

For any questions about our subprocessors or to request a copy of our Data Processing Agreement (DPA):

hello@paiq.io
PAIQ RAAS, S.L. — NIF B27677392 — Málaga, Spain