Sub-Processors
Last updated: 24 June 2026
This page lists all sub-processors engaged by Ozvor that may process personal data submitted to or generated by the Service on behalf of our customers. Ozvor is operated by Ozvor (a company being incorporated in Brazil) and acts as a data processor with respect to personal data you submit through the Service. This list is maintained in accordance with Art. 28 GDPR, Art. 14 LGPD, and our Data Processing Agreement (DPA).
1. Our obligations under Art. 28 GDPR / LGPD
We engage sub-processors only on the basis of a written contract (DPA) that imposes data-protection obligations equivalent to those in our agreement with you. We remain liable for the performance of each sub-processor with respect to its data-protection obligations.
Before engaging any new sub-processor, or materially changing the role of an existing one, we will provide customers with at least 30 days' advance notice (see Section 3). You may object to a new sub-processor within the notice period by contacting dpo@ozvor.com. If we cannot accommodate the objection, either party may terminate the affected services on written notice.
2. Current sub-processors (11)
The following 11 sub-processors are currently authorised. Data processed is limited to what is necessary for the stated purpose; by design, our AI audit prompts are synthetic and contain no personal data, and competitor names are never transmitted to AI providers.
| Sub-processor | Purpose / role | Data categories processed | Region / location | Transfer mechanism (EEA/BR → third country) | Privacy / DPA notice |
|---|---|---|---|---|---|
| Supabase | Database (PostgreSQL) and authentication. Stores account data, brand profiles, audit records, and subscription state. | Account identifiers (email, Supabase user ID), brand/domain data, audit results, billing state, audit logs | EU users: eu-central-1 (Frankfurt, EU). US users: us-east-1 (US). | EU project: data stays in EU — no third-country transfer. US project: domestic US. | supabase.com/privacy · DPA |
| Anthropic | AI inference — processes synthetic audit prompts to generate citation and presence analysis. Per Anthropic API terms, prompts and responses are not used for training and are not retained beyond returning the result. | Synthetic prompt text (brand name + category question; no personal data by design). No competitor names transmitted. | Anthropic API (US-hosted). EU-region inference is on our roadmap; current transfers rely on SCCs (Module 2). | SCCs (Module 2); DPF certified. EU-region inference planned (roadmap); we disclose here when it ships. | anthropic.com/privacy |
| OpenAI | AI inference — processes synthetic audit prompts for ChatGPT citation and presence analysis. Per OpenAI API terms, prompts are not used for training by default. | Synthetic prompt text (brand name + category question; no personal data by design). | US-hosted (OpenAI API); EU-hosted path used for EU users where available. | SCCs (Module 2); DPF certified. | openai.com/privacy |
| Google (Gemini) | AI inference — processes synthetic audit prompts for Google AI Overview and Gemini citation analysis. | Synthetic prompt text (brand name + category question; no personal data by design). | EU-hosted paths preferred for EU users; US fallback otherwise. | SCCs; DPF certified; Google Cloud DPA covers Gemini API usage. | policies.google.com/privacy |
| Perplexity | AI inference — processes synthetic audit prompts for Perplexity citation analysis. Excluded for EU users pending confirmation of transfer safeguards. | Synthetic prompt text (brand name + category question; no personal data by design). US users only at this time. | US-hosted. | Transfer safeguards under review; EU users excluded until confirmed. | perplexity.ai/privacy |
| DataForSEO | Public off-site signal collection — fetches publicly available domain authority, backlink, and search-result data to support Ozvor AI Visibility Score calculation. | Brand domain / URL (publicly available). No personal data transmitted. | US / EU infrastructure. | No personal data transferred; no transfer mechanism required. | dataforseo.com/privacy |
| SerpAPI | Public search-result signal collection — fetches Google AI Overview and traditional SERP data to support Ozvor AI Visibility Score calculation. | Brand name / domain (publicly available). No personal data transmitted. | US-hosted. | No personal data transferred; no transfer mechanism required. | serpapi.com/privacy |
| Stripe | Payment processing and subscription management. Billing, invoicing, and subscription lifecycle. Card and payment data is Stripe-hosted; Ozvor never stores full card details. | Account name, email, Stripe customer ID (stored in our database); full payment/card data is held exclusively by Stripe. | US-hosted (Stripe global infrastructure). | SCCs (Module 2); DPF certified. | stripe.com/privacy · DPA |
| Resend | Transactional email delivery — account notifications, DSR acknowledgements, subscription confirmations, and service alerts. | Recipient email address, notification content (no sensitive personal data in email bodies by design). | EU infrastructure selected for EU users where available. | SCCs where applicable. | resend.com/privacy |
| Railway | Application hosting — runs the Next.js frontend and the API backend. Processes traffic data, environment variables (secrets), and application logs. | Traffic data, session tokens in transit, application logs (no persistent personal data logged by design). | Region selected per deployment; EU region preferred for EU users. | SCCs where non-EU region is used. | railway.app/privacy |
| Cloudflare | CDN, DNS, and network security (DDoS protection, TLS termination, edge caching for static assets). | IP addresses and HTTP request metadata (processed in transit; subject to Cloudflare's data retention limits). | Global edge network; EU traffic routed through EU PoPs. | SCCs; DPF certified. | cloudflare.com/privacy |
3. Change notification process
Ozvor will provide at least 30 days' advance notice before engaging a new sub-processor or materially changing the role of an existing one. Notification will be made by:
- Email to the primary contact on record for customers who have executed a DPA with Ozvor; and
- An update to this page (the "Last updated" date will reflect the change).
To object to a new sub-processor, contact dpo@ozvor.com within the 30-day notice period, stating the sub-processor and the reason for objection. If Ozvor cannot reasonably accommodate the objection without materially affecting the Service, either party may elect to terminate the affected services on written notice.
4. Data Processing Agreement (DPA)
This sub-processor list forms part of the Ozvor Data Processing Agreement, which governs our obligations as a processor under GDPR Art. 28 and LGPD Art. 14. By using the Service, customers who are themselves data controllers accept the DPA, which authorises Ozvor to engage the sub-processors listed above on the terms described therein.
For questions about sub-processors, data transfers, or to request a copy of a specific DPA, contact dpo@ozvor.com.
5. Related documents
- Privacy Policy — §4 contains an inline summary of sub-processors; §5 covers international transfer safeguards.
- Data Processing Agreement — the contract governing our obligations as processor.
- Data Subject Request — exercise your access, deletion, portability, or correction rights.