Why this page exists
When you use Ever Works Cloud to process personal data, we act as your processor and you are the controller. Article 28 GDPR says we may not bring in another processor without your authorisation, and that you must be told in advance when we intend to add or replace one so that you have a real chance to object.
This page is that disclosure. It names every provider we engage to process personal data for the hosted Service, says what each one does, where it does it, and what categories of data reach it. Our Data Processing Addendum refers to this page, and your general authorisation to the providers listed here is given through it.
It is also written for people who are not our customers — someone whose employer uses the Service, or whose data ends up here for some other reason — because "who else can see this" is a fair question and the answer should not be available only to the person paying the invoice.
What counts as a sub-processor
A sub-processor is a third party we engage that processes personal data on our behalf and on our instructions, under a written contract meeting Article 28 GDPR. A provider that keeps the servers running, delivers your email, catches our errors or answers your support chat is a sub-processor.
Three things are not sub-processors, and lumping them in would make this page less accurate rather than more complete:
- A provider that never touches personal data. A design tool or an accounting package we use internally is not in the path of your data.
- A company that decides its own purposes. A payment processor acting on its own regulated obligations — fraud prevention, anti-money-laundering, card-scheme rules — is a controller in its own right for that part, not our processor. Those recipients are described in the Privacy Policy instead.
- Something we run ourselves. Our databases, object storage, secrets manager and container platform are ours. There is no third party to disclose. The infrastructure section below explains what we operate and what genuinely sits in front of it.
What this page covers
The hosted Service we operate at ever.works, for Ever Works specifically. Other products in our range have their own list on their own domain, and the providers differ between them — do not read this one as covering a product it does not name.
It does not cover a deployment you run yourself. If you install our open-source software on your own infrastructure, you choose your own providers with your own credentials and contracts. The third tier below exists to make that distinction visible rather than to blur it.
This page is versioned and dated. The version in force, and the date it took effect, are at the end.
How to read this list
The three tables that follow mean genuinely different things, and reading them as one flat list will give you the wrong answer.
Here is why the split exists. Our products are open-source at their core and built to be connected to other things, so more than 160 distinct third-party providers appear somewhere in our source code across our whole range of products. The overwhelming majority of them are never engaged by us for anything. Some are optional integrations that do nothing until somebody switches them on. Many are reachable only in a deployment that somebody else runs, with their own account and their own credentials.
Publishing all of them as "our sub-processors" would be inaccurate, and inaccurate in the worst direction: it would tell you your data reaches companies it never touches, while burying the handful that it actually does. A list that is technically exhaustive and practically misleading is not a disclosure. So there are three tiers.
Tier 1 — always engaged
If you use the hosted Service, these providers are in the path. There is no setting that removes them, because they are part of how the Service is delivered to everyone.
This is the real Article 28 sub-processor list. It is the tier to use when you are completing a data protection impact assessment, mapping your transfers, or deciding whether you can use the Service at all. It is short, and it is short because we run our own infrastructure rather than renting someone else's.
Tier 2 — engaged only if you turn something on
A provider in this tier is engaged only when a specific feature, connector or integration is enabled. Enable nothing and it is never involved, and no data of yours ever reaches it.
Who does the enabling depends on the feature:
- You or your workspace administrator, by switching on a feature or connecting an account in the product's settings — a payment provider, an analytics tool, a chat widget, a calendar or repository connector.
- An individual user, by making a personal choice — signing in with a social account, for example, or connecting their own third-party tool.
The table names the feature or setting that activates each provider, so you can check your own configuration against it rather than take our word for the current state. If you want to know precisely which of these are live for your workspace today, ask us at [email protected] and we will tell you.
Enabling one of these is a decision to send your data somewhere else, and it is yours to make. The provider's own terms and privacy notice then apply to what it does, alongside our contract with it.
Tier 3 — self-hosted deployments only
Several of our products are published as open source and can be run on your own infrastructure. When you do that, you choose the database, the object storage, the email relay, the AI provider and everything else, using your own accounts and your own credentials.
The providers in this tier are listed only so that you can see what the software can be pointed at. They are not our sub-processors, and they never become ours by appearing here.
In a deployment you run: we process nothing, we have no access to it, we are not your processor for it, and nothing on this page or in our Data Processing Addendum describes it. You choose those providers, you contract with them, you hold the credentials, and the obligations to your own users are yours alone. The open-source section of our Terms of Service sets out the same split.
If you run a deployment yourself and need to publish a sub-processor list of your own, this tier is a useful starting inventory. It is not your list — only you know which of these you actually configured.
What the columns mean
- Sub-processor — the contracting legal entity, not the brand on the website. Where a provider has a separate European establishment that contracts with us, that is the one named.
- Purpose — what it does for the Service, specifically enough to be checked. Not "business operations".
- Location — where the processing takes place, or the provider's place of establishment where processing is distributed. Where that is outside the European Economic Area, the transfer mechanism we rely on for it is described in the international transfers section of our Privacy Policy, and we will give you a copy of the safeguards for a named provider on request.
- Personal data — the categories that reach that provider. Categories, not a promise about volume: a provider that receives email addresses receives them for the people who trigger the feature, not for everyone.
What is deliberately not in the tables
- Infrastructure we operate ourselves. Our databases, object storage, cache, secrets manager and container platform are not sub-processors, because there is no third party involved. The next section describes what we run and what really does sit in front of it.
- Recipients that are not processors — payment providers acting under their own regulatory obligations, professional advisers, public authorities, and an acquirer in a corporate transaction. Those are covered in the Privacy Policy.
- Sites you choose to visit by following a link out of the Service. Once you are on someone else's site, their notice applies.
Annex: Ever Works
Tier 1 — always engaged
| Sub-processor | Purpose | Location | Personal data |
|---|---|---|---|
| Cloudflare, Inc. | DNS, reverse proxy, TLS termination and content delivery for ever.works, for the platform, and for every site we provision, which reaches the internet through a Cloudflare tunnel. Also Turnstile, the anti-bot check on registration and onboarding. | United States, with traffic terminated at the edge location nearest the visitor | IP address, user agent and device signals, request metadata such as URL, referrer and cookies, anti-bot challenge signals |
| PostHog, Inc. | Product analytics for the platform and the marketing site — page views, interaction capture, feature flags, and session recording with form inputs masked. Signed-in users are identified to it. Our server-side application logs are forwarded to the same account. | United States (PostHog US Cloud) | account identifier, email address, name, IP address, page views and interface interactions, masked session recordings, server log lines and error messages |
| GitHub, Inc. (Microsoft Corporation) | Sign-in with GitHub and the platform GitHub App; the repositories that hold a Work's website and its content, which for a platform-managed Work are private repositories in an organisation we own; the container registry that holds the image of the platform and of each provisioned site; and our build pipeline. | United States | GitHub account identity and access token, avatar URL, commit author name and email address, repository contents, including whatever a Work's content contains, pull request and issue text |
| OpenRouter, Inc. | The model gateway every agent run and generation pipeline goes through by default, including the automated research that runs when an account is created. It selects an upstream model provider to serve each request. | United States | prompts and completions, which routinely contain account identity and user-generated content, name, email address, sign-in provider, avatar URL and social profile URLs at registration, search results about a named person |
| Tavily | The default provider for public web search and page extraction, used by agents researching a topic and by the automated research that runs when an account is created — where the search queries are built from the new account holder's name and email domain. | United States | search queries, including a person's name and their employer's domain, the addresses of pages retrieved |
| Google LLC (Google Analytics 4 and Google Tag Manager) | Web analytics and tag delivery on the ever.works marketing site. Not used in the signed-in platform. | United States | IP address, analytics identifier, page views and events, device, browser and approximate location |
| Google LLC (reCAPTCHA) | Bot protection on the forms on the ever.works marketing site. | United States | IP address, browser and interaction signals |
| Google LLC (Google Fonts) | The documentation sites fetch a webfont from Google at the moment a page loads, so a visitor's browser contacts Google directly. The application and the site template do not — they build the font in and serve it themselves. | United States | IP address, user agent, the page being read |
| Intuit Inc. (Mailchimp) | Holds the newsletter list for the marketing site, and receives an address when someone subscribes. | United States | email address, subscription status and date, IP address |
| ActiveCampaign, LLC (Postmark) | Delivers the message when someone writes to us through the contact form on the marketing site. | United States | name, email address, the content of the message |
| jsDelivr | A public content delivery network that serves the WebAssembly file behind the animation on the sign-in and registration pages. The fetch happens before anyone has signed in or made a cookie choice, so it is listed rather than left implied. | Global anycast network | IP address, user agent, referring page |
| unpkg | The fallback for the same file, used when the primary content delivery network does not answer. | Global anycast network | IP address, user agent, referring page |
Tier 2 — engaged only when a feature, integration or consent brings them in
| Sub-processor | Purpose | Location | Personal data |
|---|---|---|---|
| Functional Software, Inc. (Sentry) | Error tracking and performance traces, where an account is configured with a Sentry project. On a provisioned site the template can additionally run Sentry in the visitor's browser, including its own session replay, if the Work Owner enables it. | United States | IP address, account identifier attached to an error, stack traces and request metadata, which can contain fragments of content, browser session replay on a Work site, where enabled |
| Resend, Inc. | Sends transactional email — verification, password reset, notifications — where it is selected as the mail provider, and outbound agent mail where it is selected as the agent mail provider. | United States | recipient name and email address, subject and body of the message |
| Stripe, Inc. | Checkout, subscriptions and invoicing for paid plans and credit packs, where billing is enabled on the account. Separately, a Work Owner can connect their own Stripe account to take payments from their own site's visitors. | United States | name and email address, billing address entered at checkout, customer and payment method references, purchase and invoice history, IP address collected by Stripe on its own pages |
| Google LLC (Google Identity) | Sign in with Google, where you choose it — on the platform, or on a Work site where the site owner has enabled it. | United States | Google account identifier, email address, name, profile photo URL |
| Meta Platforms, Inc. | Sign in with Facebook, where you choose it and where the site owner has enabled it. | United States | Facebook account identifier, email address, name, profile photo URL |
| LinkedIn Corporation (Microsoft Corporation) | Sign in with LinkedIn, where you choose it and where the site owner has enabled it. | United States | LinkedIn account identifier, email address, name, profile photo URL |
| Composio Inc. | Brokers an agent's access to third-party tools using accounts you have connected yourself, and receives the events those tools send back. | United States | access tokens for the accounts you connect, whatever those accounts return into an agent run |
| Novu Inc. | The in-application notification inbox and a delivery channel for notifications, where it is configured against Novu's hosted service rather than an instance you run. | United States | a hashed subscriber identifier, notification content, email address where used as a delivery channel |
| Twenty S.A.S. | Two-way sync of companies and people with a Twenty workspace, where you supply the workspace and an API key. Also available on a provisioned Work site. | France, unless you point it at a Twenty instance you run | contact name and email address, company and role, notes and activity records |
| Langfuse GmbH | Prompt versioning and model observability, where keys for it are supplied. | European Union, unless you point it at a Langfuse instance you run | prompt and completion text, which can contain account identity and user-generated content |
| Jitsu Labs, Inc. | Forwards activity-log events — who did what, to which Work, and whether it succeeded — to an analytics pipeline, where one is configured. Also available on a provisioned Work site. | United States, unless you point it at a Jitsu instance you run | account identifier and Work identifier, action, status and summary of an event, IP address, for the browser-side variant on a Work site |
| Trigger.dev Inc. | Runs background jobs for agent work, where an account is pointed at Trigger.dev's hosted service rather than the instance we run ourselves. | United States | job payloads, which can contain identifiers, email addresses and user-generated content |
| Vercel Inc. | An alternative place to deploy a Work site, chosen by the Work Owner and connected with their own account and token. The site template can also run Vercel's analytics and performance measurement if the Work Owner switches them on. | United States | deployment metadata, the account token the Work Owner supplies, site visitor IP address and page views, where its analytics are enabled |
| ScreenshotOne | Captures a screenshot of a website so that a directory entry has a thumbnail. | European Union | the address of the page to be captured, whatever that page displays |
| Algolia SAS | Search on the documentation sites, where search keys are configured. | European Union and United States | search queries, IP address |
| OpenAI, L.L.C. | An upstream model provider. Our default pipelines are routed to an OpenAI model through the gateway above. Where you instead supply your own OpenAI key, OpenAI is your provider under your own agreement with it and not our sub-processor. | United States | prompt and completion text, which can contain account identity and user-generated content |
| Anthropic, PBC | A model provider for the Claude-based agent pipelines, engaged where those are enabled or where you supply your own key. | United States | prompt and completion text, which can contain account identity and user-generated content |
| Google LLC (Gemini) | A model provider, engaged only where you select it and supply your own key. | United States | prompt and completion text |
| Amazon Web Services, Inc. | Object storage for uploads, where you point storage at an S3 bucket of your own instead of ours. | The region of the bucket you choose | uploads and attachments |
| Plausible Insights OÜ | Cookieless site analytics on a Work site, where the Work Owner enables it. | European Union | page views and referrer, coarse device and country |
| Twilio Inc. (Segment) | Event collection and routing on a Work site, where the Work Owner enables it. | United States | IP address, visitor identifier and traits where the visitor is identified, events and page views |
| DataFast | Product and marketing analytics on a Work site, where the Work Owner enables it. | United States | IP address, page views and events, campaign attribution |
| Google LLC (Google Maps Platform) | Renders maps and clusters markers for location-based listings on a Work site, where the Work Owner enables it. | United States | IP address, the area of the map being viewed and locations searched |
| Mapbox, Inc. | The alternative map renderer for the same purpose on a Work site. | United States | IP address, the area of the map being viewed and locations searched |
| Lemon Squeezy, LLC | Takes payments from a Work site's own visitors as merchant of record, where the Work Owner connects it. The Work Owner contracts with it directly. | United States | name and email address, billing address and tax location, payment identifiers and purchase history |
| Polar Software Inc. | An alternative payment and subscription provider for a Work site's own visitors. | United States | name and email address, billing and tax location, payment identifiers and subscription history |
| SolidGate | A further card payment option for a Work site's own visitors. | European Union | cardholder name, email address, billing address, payment identifiers |
Tier 3 — self-hosted deployments only
If you run Ever Works on your own infrastructure, you choose these providers and hold the credentials. We are not a processor for anything in a deployment you run: we do not receive that data, we cannot reach it, and we have no relationship with the providers you configure.
| Sub-processor | Purpose | Location | Personal data |
|---|---|---|---|
| Supabase, Inc. | An authentication and database adapter that ships in the directory site template and can be used instead of a PostgreSQL server. No site we host uses it — every site we provision runs on the PostgreSQL cluster we operate. It is here so that a self-hoster can see the option exists. | The region you choose when you create the project | site visitor account records, if you configure it |
| Ollama, LM Studio or a vLLM server you run yourself | Local model runtimes the software can be pointed at instead of a hosted model provider. Listed because it is the one configuration in which no third party sees a prompt at all. | Your own infrastructure | nothing leaves your deployment |
Sites we provision for you
Where we provision and host a directory site for you, that site's visitors are your data subjects, not ours. You are the controller for what the site collects from them; we are your processor for hosting it.
The providers above are the ones in the path for the platform. A site you have us provision may bring in further providers because you configured them — an analytics tool, a form handler, a payment provider, a comment system. Those are yours: you choose them, you contract with them, and they belong in the privacy notice you publish on that site, not in ours.
If you are unsure which of your site's providers we engage and which you do, ask at [email protected] and we will tell you exactly what the platform touches.
Hosting and infrastructure
The tables above are short for a reason, and the reason is worth stating plainly: we run our own infrastructure. The Service is not a tenancy in a public cloud account. It runs on physical servers we own, in facilities we control, inside the European Union, on a virtualisation and container platform we operate ourselves.
The database, the object storage that holds your files, the cache and queue layers, the secrets manager and the deployment system are all components we run. None of them is a third party, so none of them appears as a sub-processor — there is nobody else to disclose. What we do with them is described on our Security page.
Where processing actually happens
- Your data at rest, and the applications that process it, sit on our own hardware in the European Union. That is the primary location for accounts, content, files and the databases behind them.
- Requests reach us through a global content delivery and security network. Traffic is terminated at the edge location nearest to whoever is making the request, which can be anywhere in the world, before being carried to our infrastructure in Europe. That provider is in the always-engaged tier above, and the transfer mechanism for it is described in our Privacy Policy.
- Off-site backup copies are held with an external object storage provider, encrypted by us before they leave our network. That provider holds ciphertext and no key, and cannot read what it stores.
- Our source code, build pipeline and container images are hosted with a third-party provider. That is how the Service is built and deployed rather than where your data lives day to day, but it is a genuine third party and it is disclosed as one.
Where a product does something different
A small number of products use a third-party managed database, managed storage or hosted platform for a specific function instead of our own infrastructure. Where that is the case for Ever Works, the provider appears in the always-engaged tier above and the product annex says which data goes there.
We are explicit about this because "self-hosted" is exactly the sort of claim that gets made once and then stops being true for one product in the range. If your data for a given feature sits with someone else, the table says so.
The regions you should design around
If you are completing a transfer mapping or a data protection impact assessment, the honest summary is: primary processing in the European Union on infrastructure we operate; edge termination worldwide; a small number of named providers established outside the European Economic Area, each with its own transfer mechanism. Every one of those providers is in the tables above, and the mechanism for each is in the international transfers section of the Privacy Policy.
If you need a copy of the safeguards for a named provider — the Standard Contractual Clauses and which modules apply — write to [email protected] and we will send them.
When this list changes
The notice period
We give at least 30 days' notice before a new or replacement sub-processor starts processing personal data for the hosted Service. The 30 days run from the date the notice is published or sent, whichever comes first, and they exist so that your objection right is a real one rather than a formality you learn about afterwards.
How you find out
- This page changes first. It carries the date it took effect and a dated record of what changed, so the page itself is the notice.
- By email, if you ask for it. Write to [email protected] and we will add your address to the notification list. We then email you before each change, at the same time the page is updated. We recommend a role address rather than an individual's — a notice sent to someone who has left your organisation has been sent and not received.
- In the product, for changes that affect a feature you are using, through a notice to workspace administrators.
What the notice tells you
The provider's legal name, what it will do, where it is established, the categories of personal data it will receive, the transfer mechanism if it is outside the European Economic Area, the date it takes effect, and whether it is a new provider or replaces one already on the list. If it replaces one, we say which.
Urgent replacements
Sometimes we have to move faster than 30 days — a provider suffers a security incident, terminates its service, loses the legal basis it relied on, or fails in a way that makes staying with it worse than leaving.
Where that happens we may engage the replacement sooner, and we will notify you as quickly as we can with the reason we could not wait. Your right to object is not affected: it simply runs from the notice instead of before the change. We do not use this route as a convenience, and a notice sent under it says plainly why the normal period was not followed.
Changes that do not need notice
Removing a provider does not need a notice period — it reduces the number of people handling your data. A provider changing its own name, or the group entity that contracts with us changing without a change in where or how the processing happens, is recorded here as an administrative update rather than announced as a new engagement. A provider moving its processing to a different country is not administrative, and gets the full notice.
The record
We keep the change history for this page so that you can reconstruct who was engaged during a given period. That matters if you are updating your own records of processing, refreshing an impact assessment, or answering a question about a period in the past. Ask [email protected] if you need the state of the list as it stood on a particular date.
Objecting to a sub-processor
Who can object
The customer — the organisation or person who contracts with us and acts as controller for the data in the workspace. If you are an individual whose data we hold, this is not your route: your rights are in the Privacy Policy, and if your data sits in an employer's workspace, your employer is the controller and the request goes to them.
How to object
Write to [email protected] within 30 days of the notice, and tell us:
- which provider you are objecting to;
- your reasons, on data protection grounds — a transfer you cannot justify, a conflict with a commitment you have given your own users, a regulator's position that applies to you, a documented security concern;
- which of your workspaces or environments the objection covers.
The reasons matter. This is a right to object on data protection grounds, not a veto over our choice of suppliers, and an objection with no stated ground gives us nothing to work with. Tell us what the problem is and we can usually solve it.
What we do next
We acknowledge your objection within five business days and respond substantively within 30 days. In between we look for a way to make the objection unnecessary:
- A different provider for your workspace, where one exists that does the job.
- A different configuration — narrowing what is sent, changing a region, or turning off the feature that needs the provider at all, if you can live without it.
- Excluding your workspace from the provider, where that is technically possible.
- Additional safeguards or contractual terms where your concern is about a specific risk rather than the provider as a whole.
Where it is technically possible to hold off, we will not start using the provider you have objected to for your data while the objection is open. Where it is not possible — because the provider is part of how the Service is delivered to everyone — we will tell you that plainly and quickly, rather than letting the clock run out on you.
If we cannot resolve it
If we cannot offer you a solution you can accept, you may terminate the affected subscription by written notice, without penalty, and we will refund the fees you have prepaid for the period after termination. That is the remedy: neither of us owes the other damages for a good-faith disagreement about a supplier.
Give us notice within 30 days of our final response, and we will keep your data available for export for the usual 30-day window described in the Terms of Service so that leaving does not cost you the data.
If you are on a free tier there is nothing to refund, and the same route is simply to stop using the Service and export your data.
Objecting to a provider already on the list
You do not have to wait for a change. You can raise a concern about a provider already listed at any time, using the same address and the same process, without the 30-day deadline. The realistic outcome differs by tier: a tier 2 provider can usually be switched off for you; a tier 1 provider generally cannot, because it is part of how the Service works — and if the answer is going to be no, you will get it as a straight no with the reason.
How to reach us about this list
- Questions about a provider, a request for the safeguards behind a transfer, or a request to join the change notification list — [email protected].
- An objection to a sub-processor — [email protected], as set out above.
- The Data Processing Addendum, a due diligence request, or a security questionnaire — [email protected].
We are Ever Technologies LTD, registered in Bulgaria under company number 204599535, with its registered office at Mladost 2, bl. 211, ent. A, Sofia 1799, Bulgaria. We are the controller for our own processing and your processor for the data in your workspace. By post, write to the registered office and mark the letter for the attention of the privacy team. We correspond in English.
You may also complain to a data protection supervisory authority. Ours is the Commission for Personal Data Protection (Комисия за защита на личните данни), the CPDP, at https://www.cpdp.bg/. You may instead complain to the authority for the country where you live or work.
This document is version 1.0.0 of the sub-processor list for ever.works, in force from 2026-08-02. It lists the providers engaged as at that date. Earlier versions, with the dates they applied, are at https://ever.works/subprocessors.