KabData logoKabData
Legal centre
Legal

Subprocessors

Infrastructure and service providers that may process Customer Personal Data when KabData delivers the Service.

Last updated: August 12, 2026Language: English

Draft — not yet effective

KabData's Cyprus company is still being incorporated. This document will become effective only after its full registered name, company number, registered office, and effective date are inserted and the stated operational controls are verified.

This page lists the service providers that KabData uses or has configured to process Customer Personal Data on KabData's behalf. It forms part of the Data Processing Addendum.

AppsFlyer and other services that a Customer contracts with and connects at its own direction are listed separately because they are ordinarily Customer-directed providers rather than KabData subprocessors.

Current and configured subprocessors

| Provider | Purpose | Personal data involved | Location / transfer information | Status | | -------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------- | | Hetzner Online GmbH and relevant affiliates | Application and worker compute; PostgreSQL hosting | Account data, Customer Data, credentials, configurations, and service logs | Servers are located in Germany | Confirmed | | Hetzner Online GmbH and relevant affiliates | Daily full-server Cloud Backups using seven rolling slots | Data stored on the backed-up server disk | European Union, linked to the German server location | Confirmed; customer-controlled encryption at rest is not yet verified | | Cloudflare, Inc. and relevant affiliates | DNS, CDN, network security, AppsFlyer onboarding email routing/queues, and R2 object storage | Network/request data, onboarding metadata, logos, exports, and raw-event archives | R2 currently uses an Eastern Europe (EEUR) location hint, not a guaranteed EU jurisdiction; applicable transfers rely on Cloudflare's DPA and transfer safeguards | Confirmed; KabData does not promise EU-only R2 storage | | Laravel Forge — applicable contracting entity | Server provisioning, deployments, privileged operations access, infrastructure metrics, health checks, and job heartbeats | Infrastructure metadata, metrics, limited log output, deployment information, and potential privileged server access | Contracting entity and processing locations to be verified before the legal documents become effective | Confirmed in use | | Zoho group entity shown in KabData's account and DPA | Hosted business email; planned transactional application email over SMTP | Sender/recipient names and addresses, message content, delivery metadata, and time-limited links | Account data centre, contracting entity, and processing locations to be verified before the legal documents become effective | Business email active; application SMTP migration planned | | SMTP2GO — applicable contracting entity | Transactional application email during migration to Zoho SMTP | Sender/recipient names and addresses, message content, delivery metadata, and time-limited links | The application uses an EU SMTP endpoint; additional processing locations and transfer safeguards must be verified from the account and DPA | Transitional; remove after migration and vendor data expiry/deletion | | Netlify, Inc. and relevant affiliates | Public-website hosting/form handling where the configured Netlify form is used | Contact name, business email, company, publisher-count range, message, IP/request metadata, and submission time | Processing locations and transfer safeguards under the applicable Netlify agreement and DPA | Configured in the public website; production account must be verified |

Planned billing provider

Stripe is not yet active. After KabData's Cyprus incorporation, the relevant Stripe contracting entity is expected to provide subscription checkout, recurring billing, invoices, payment recovery, and the billing portal. Stripe may process billing contacts, customer/subscription/invoice status, payment metadata, and payment-method details. KabData does not intend to receive or store full card numbers.

Stripe will be added to the active subprocessor list before it processes Customer Personal Data. Its contracting entity, account country, processing locations, and applicable transfer safeguards will be taken from the activated Cyprus Stripe account.

Optional and Customer-enabled providers

These providers receive data only when a Customer enables the relevant integration. Their role may depend on whether the Customer connects its own account or KabData supplies a shared service.

| Provider | Customer-enabled purpose | Data involved | | -------------------------------- | ------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | | Microsoft Corporation | Microsoft Teams authorisation, chat/channel discovery, and notifications | Tenant/client identifiers, sender details, tokens, chat/channel identifiers, and Customer-selected message content | | Salesforce, Inc. (Slack) | Workspace/channel discovery and notifications | Workspace/team identifiers, scopes, tokens, channel identifiers, and Customer-selected message content | | Telegram — relevant operator | Chat connection and notifications | Chat/user/thread identifiers and Customer-selected message content |

Customer-directed sources and services

| Provider | Purpose | | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ | | AppsFlyer Ltd. or relevant affiliate | Customer-authorised source of aggregate and raw attribution, in-app event, revenue, geographic, and Protect360 data through API or authorised browser access | | Apple Inc. | Public App Store metadata and app-icon lookups | | Google LLC | Public Google Play listing metadata and app-icon lookups |

Other vendors

KabData does not currently know of, and the reviewed codebase does not identify, a separate error-reporting, product-analytics, CRM, or customer-support-platform vendor. If one is enabled and processes Customer Personal Data on KabData's behalf, it will be assessed and added before use.

Changes and notifications

KabData will provide at least 30 days' notice before a new subprocessor begins processing Customer Personal Data, except where an urgent replacement is reasonably required for security, law, or service continuity. Customers may object on reasonable, documented data-protection grounds as described in the DPA.

To ask a question, report an inaccuracy, or request subprocessor-change notifications, email [email protected].