Skip to main content

Sub-processors

Last Updated: September 11, 2026

This page lists every third party that processes data on our behalf in connection with the Platform. It is the sub-processor list referred to in our Data Processing Agreement and our Privacy Policy, and it is maintained from the code rather than from memory — if a provider is not called by the running system, it is not on this list.

Notice of changes

We give at least 30 days' notice before a new sub-processor begins processing customer personal data. Notice is given by updating this page and by email to account holders. If you object to a new sub-processor on reasonable data-protection grounds, tell us within that period at privacy@theartofcto.com and we will work with you on an alternative; if none is workable, you may terminate the affected subscription and we will refund the unused portion.

To be notified automatically of changes to this page, email privacy@theartofcto.com asking to be added to the sub-processor notification list.

International transfers

Several providers above are established outside the EEA and the UK. Where personal data is transferred out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) as incorporated into each provider's data processing terms, together with the supplementary measures those providers document. Copies of the relevant terms are available on request from privacy@theartofcto.com.

Entries marked [TO CONFIRM] are hosting regions we have not yet verified against the provider's console. We would rather show the gap than publish a region we cannot evidence.

Infrastructure and hosting

Everything the Platform runs on. These see data by necessity rather than by feature.

ProviderWhy we use itWhat it receivesWhere
Cloudflare, Inc. (USA)Edge delivery, DNS, DDoS protection, the Workers runtime that runs the site and API, R2 object storage (uploads, hero images, audio), KV (sessions, rate limits, AI assistant history), D1 (cache tags), Hyperdrive (database connection pooling), and the container that runs our malware scanner.All request traffic, including IP addresses, request headers and page paths; uploaded files; generated images and audio; session records; every database query passes through Hyperdrive.Global edge network. R2 buckets are configured without a jurisdiction restriction, so object placement is automatic rather than region-pinned.
Cloudflare Turnstile (Cloudflare, Inc.)Bot protection on public forms — contact, CTO Office inquiries, waitlist, invitations.The challenge token and your IP address, which is sent to Cloudflare for verification.Global edge network.
Cloudflare Zaraz (Cloudflare, Inc.)Consent-gated loading of third-party analytics and advertising scripts. Zaraz decides which of the tools below are allowed to load, based on your consent choices.Page and event metadata forwarded to the tools you have consented to; consent state.Global edge network.
Neon, Inc. (USA)Managed PostgreSQL hosting for all application databases.All account and user-created data: profiles, subscriptions, Command Center entities and incidents, Foundry plans, SplitCause graphs, 1:1 notes, bookmarks, preferences, consent records.[TO CONFIRM: Neon project region — not pinned in repository configuration]

Identity, payments and email

Providers that hold account, billing or contact data.

ProviderWhy we use itWhat it receivesWhere
Okta, Inc. / Auth0 (USA)Identity provider — sign-in, sign-up, multi-factor authentication, passkeys.Email address, name, profile picture, authentication credentials, MFA enrolment, OAuth tokens.[TO CONFIRM: Auth0 tenant region — repository configuration comments indicate an Australian tenant (*.au.auth0.com)]
Stripe, Inc. (USA)Payment processing, subscription management and the customer billing portal.Email address, display name, our internal user ID, billing address, payment card details and transaction history. Card details are collected by Stripe directly and never reach our servers.Global (US-headquartered, EU entity for EEA customers).
Brevo (Sendinblue SAS, France)Transactional email and newsletter delivery.Email address, first and last name, list membership, topic preferences, send and open history.European Union.
Google LLC — Firebase Cloud Messaging, and Apple Inc. — APNsDelivery of web and mobile push notifications.Device push token, device platform and label, and the content of the notification itself.Global (Google, USA / Apple, USA).

Analytics and advertising

All of these except PostHog’s cookieless page counting are gated behind your consent choices and load only after you opt in.

ProviderWhy we use itWhat it receivesWhere
PostHog, Inc.Product analytics, funnels, retention, session recording on public pages, and application error tracking. Also the destination for our Workers runtime logs.Without analytics consent: page-view counts keyed to a daily-rotating hash, plus the IP address used to derive approximate location at ingest. With consent: product events, autocaptured interactions, session recordings with inputs masked, error and exception details, device information, and your user ID once signed in.PostHog Cloud EU (eu.i.posthog.com). Browser traffic is proxied through p.theartofcto.com before reaching PostHog.
Google LLC — Google Analytics 4Website analytics. Loaded through Cloudflare Zaraz only after you grant analytics consent.Page views, events, session data, engagement metrics, GA client and session identifiers.Global.
Microsoft Corporation — ClarityBehavioural analytics, heatmaps and session recording. Loaded through Cloudflare Zaraz, and only after you grant analytics consent. Unlike PostHog, it is not currently limited to public pages.Click and scroll behaviour, session recordings, device information.Global.
Google LLC — Google Ads and AdSenseAdvertising and conversion tracking. Loaded only after you grant marketing consent.Conversion events, advertising identifiers and cookies.Global.
Google LLC — Search ConsoleNo personal dataSearch performance data for our own domain, used by the SEO tooling.Aggregate search query and ranking data for theartofcto.com. No visitor-level data.Global.

AI and content generation

Providers involved in generating content or answering AI-feature prompts.

ProviderWhy we use itWhat it receivesWhere
Cloudflare AI Gateway (Cloudflare, Inc.)Proxy in front of our AI providers, used for routing, caching and cost control. Because it sits in the path, it observes and logs the prompts and completions that pass through it.Prompt and completion text for every AI feature routed through it.Global edge network.
OpenAI, L.L.C. (USA)AI inference for the AI Assistant, Foundry, 1:1 suggestions, article and briefing generation, image generation, and outage analysis. Routed via Cloudflare AI Gateway.The prompts you submit to AI features, plus content and topic material generated by our own pipelines. OpenAI does not use API inputs to train its models.United States.
Cloudflare Workers AI (Cloudflare, Inc.)No personal dataSecond-opinion inference pass on generated content — the PosterBot refine step, the admin "Refine with AI" action, and the Daily Sync voice pass.Article and briefing text submitted for rewriting. No account data is sent.Cloudflare edge network.
ElevenLabs, Inc. (USA)No personal dataText-to-dialogue audio generation for the Daily Sync briefing and short-form video.Script text for synthesis. No user data is sent.United States.
TavilyNo personal dataWeb search for content research and source verification in our content pipelines.Search queries derived from article topics or admin-supplied prompts. No visitor data is sent.[TO CONFIRM: processing region]
DataForSEONo personal dataSearch-engine ranking and AI-visibility data for the SEO Command Center.Keywords, target domains and location preferences entered by users of that tool. No name, email or IP address is sent.[TO CONFIRM: processing region]

Operational tooling

Used to run the business. Listed for completeness — most receive no customer personal data at all.

ProviderWhy we use itWhat it receivesWhere
Slack Technologies (Salesforce, Inc.)Internal operational alerting to our own private workspace.System alerts, and the content of CTO Office inquiry submissions — which can include the name, email address and message you provided. Not shared beyond our own operators.Global.
GitHub, Inc. (Microsoft)No personal dataSource code hosting, CI/CD, and build/deployment metadata read by our admin tooling.Source code and repository metadata. No customer personal data is sent to GitHub.Global.
Google LLC — YouTube Data APINo personal dataPublishing our own short-form video content.Video files and metadata we produce, plus our own operator OAuth tokens. No customer data.Global.
Have I Been Pwned (Superlative Enterprises Pty Ltd, Australia)Breach-exposure monitoring for our own operator accounts, shown on the internal security dashboard.Operator account email addresses. Customer account addresses are not submitted.Australia.

Providers we do not use

Named here because they are commonly assumed, or have appeared in our own older documentation:

  • SentryNot used. Application error tracking is PostHog, and server-side observability is Cloudflare Workers Observability forwarding to PostHog.
  • AnthropicNot currently called by any running worker. Earlier versions of our security and privacy pages listed it; that was inaccurate and is being corrected.
  • Microsoft AdvertisingNot integrated. No conversion tag is present on the site.
  • ClamAVOur malware scanning uses ClamAV, but we run it ourselves inside a Cloudflare container. No file leaves our infrastructure for scanning, and ClamAV’s maintainers are not a sub-processor.

Questions

For a countersigned DPA, a completed security questionnaire, or evidence supporting any entry above, email privacy@theartofcto.com or security@theartofcto.com. We respond to procurement and security questionnaires within one business day.