1.Current list
| Provider | Purpose | Data | Data location | Transfer safeguard |
|---|---|---|---|---|
| Amazon Web Services (US) | Application infrastructure (compute, database and storage) and email sending (Amazon SES) | All service data | EU (Ireland, eu-west-1 region) | EU-US Data Privacy Framework (Amazon.com, Inc. certification, which covers AWS) |
| Cloudflare (US) | DNS, delivery network and protection (proxy) for the service's domains; hosting of this website | Technical request data (IP address, headers) and the traffic that passes through its network | Global network; per the provider's terms | EU-US Data Privacy Framework (Cloudflare is certified) |
| Google (Gemini API) | AI processing: drafting replies, checking them and searching the customer's knowledge | Conversation content, customer knowledge and the order data needed to reply | Per the provider's terms | EU-US Data Privacy Framework (Google LLC is certified) |
| Meta Platforms (WhatsApp, Instagram, Messenger) | Messaging channels, when the customer connects them | Contact identifiers and message content | Per the provider's terms | Meta contracts in the EU from Ireland; transfers to its US parent rely on the EU-US Data Privacy Framework |
| 360dialog (Germany) | WhatsApp Business Solution Provider, when used | Phone numbers and WhatsApp message content | Per the provider's terms | Provider established in the EU; onward transfers per its terms |
| Telnyx (US) | Voice calls, only when the customer enables voice | Phone numbers, call audio, and recordings and transcripts if enabled | Per the provider's terms | EU-US Data Privacy Framework (Telnyx is certified) |
| Stripe | Billing for Kanesh accounts and the prepaid balance | Our customers' billing and payment data (not their end customers') | Per the provider's terms | Stripe contracts in the EU from Ireland; transfers to its US parent rely on the EU-US Data Privacy Framework |
The regions shown are the documented ones. Where it says “per the provider's terms”, the provider doesn't commit to a specific region for that processing.
2.International transfers
Amazon Web Services, Cloudflare, Google, Meta, Telnyx and Stripe are based in the United States or have a US parent. 360dialog is established in Germany. Even when data is stored in the EU, a US provider may access it from outside, so we treat all those cases as international transfers.
- Providers certified under the EU-US Data Privacy Framework (today, all the US providers on this list): the transfer relies on the European Commission's adequacy decision, Implementing Decision (EU) 2023/1795 of 10 July 2023 (GDPR article 45).
- If a provider isn't certified or its certification lapses: the transfer relies on the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (GDPR article 46), incorporated in its data processing agreement.
Each provider's certification status comes from its own public statements, reviewed on 30 September 2026. We check it against the official list (dataprivacyframework.gov) before onboarding a provider and periodically afterwards.
Where a transfer relies on standard contractual clauses, we document a transfer impact assessment and, where needed, supplementary measures. You can ask us about any provider's safeguard at info@nexau.es.
3.What isn't on this list
Services each customer connects and authorises itself, such as its Shopify store, its Klaviyo account, its Google Workspace or Microsoft 365 mailbox, or its marketplaces and carriers, are not our sub-processors: the customer deals with them directly, under their terms, and data flows because it decides so.
Providers we use for our own processing as a controller (for example, our company email) are listed in the privacy policy.
4.Changes to this list: prior notice and objection
- 30 days' notice. Before a new or replacement sub-processor processes a customer's data, we will email the customer's account administrator and publish the change on this page, at least 30 days in advance.
- Subscribing to changes. Anyone can receive these notices by email: write to info@nexau.es with the subject “Suscripción subencargados”.
- Right to object. Within those 30 days, the customer may object on reasonable data protection grounds, explained in writing. We will look in good faith for a solution, such as not using that provider for its data or an alternative configuration.
- If there is no solution. The customer may terminate the contract for the affected service without penalty, and we will refund the pro-rata part of any fees it prepaid for the unused period.
- Urgent replacement. If a sub-processor has to be replaced urgently for security or service-continuity reasons, we will give notice as soon as possible, explain why, and the right to object applies in the same way from that notice.
This list and this procedure are part of the general authorisation in the data processing agreement (GDPR article 28.2).
5.Change log
| Date | Change |
|---|---|
| October 2026 | Initial publication of the list. |