# Sub-processor List

Last updated: September 21, 2026

This list names the third parties Dibbla AB engages to process Customer Personal Data on behalf of its customers (“Sub-processors”), as provided in Section 7 of the [Data Processing Agreement](/dpa). It is incorporated into the DPA by reference and is the current, authoritative version.

Not every Sub-processor applies to every customer. The list is arranged in tiers, and the “Applies when” column states the condition under which each one processes your data. Everything else the platform runs on — the console, deploy pipeline, container registry, managed Git, databases, object storage, logs and monitoring — is operated by Dibbla itself on the infrastructure tier below, inside the EU.

## Current Sub-processors

### Infrastructure — Always — every customer

- **Hetzner Online GmbH** — Purpose: Cloud servers, block storage and backup storage running the platform and the applications, databases and buckets you deploy. Location: Germany and Finland (EU). Safeguard: Data stays in the EU. Processor agreement under Art. 28 GDPR; ISO 27001-certified data centres. Applies when: Always
- **Cloudflare, Inc.** — Purpose: DNS, TLS termination, DDoS protection and edge network in front of dibbla.com, the console and hosted applications, including custom domains. Location: Global edge network; United States company. Safeguard: Traffic is encrypted in transit and not stored at the edge. EU Standard Contractual Clauses; EU-US Data Privacy Framework. Applies when: Always
- **Brevo (Sendinblue SAS)** — Purpose: Delivery of transactional e-mail: notifications, invitations and alerts sent by the platform. Location: France (EU). Safeguard: Data stays in the EU. Processor agreement under Art. 28 GDPR. Applies when: Always

### Sign-in — Only the provider you sign in with

- **Google LLC** — Purpose: “Continue with Google”: verifying your identity and returning your e-mail address and display name. Location: United States and EU. Safeguard: EU Standard Contractual Clauses; EU-US Data Privacy Framework. Only identity data is exchanged. Applies when: You sign in with Google
- **Microsoft Corporation** — Purpose: “Continue with Microsoft”: verifying your identity and returning your e-mail address and display name. Location: United States and EU. Safeguard: EU Standard Contractual Clauses; EU-US Data Privacy Framework. Only identity data is exchanged. Applies when: You sign in with Microsoft

### Payments — Paying customers

- **Stripe Payments Europe, Ltd.** — Purpose: Subscription billing, invoicing and card processing for paid plans. Location: Ireland (EU), with Stripe, Inc. (United States) as its own sub-processor. Safeguard: EU Standard Contractual Clauses; EU-US Data Privacy Framework. Card numbers never reach Dibbla. Applies when: You are on a paid plan

### AI model providers — Optional — only if you enable AI features, and only the provider you choose

- **Anthropic, PBC** — Purpose: Language models behind the optional AI features: the database insights agent, the maintenance agent and AI-assisted application checks. Location: United States. Safeguard: EU Standard Contractual Clauses. Commercial API terms: inputs and outputs are not used to train models. Applies when: You enable an AI feature and choose Anthropic
- **OpenAI, L.L.C.** — Purpose: Language models behind the optional AI features: the database insights agent, the maintenance agent and AI-assisted application checks. Location: United States. Safeguard: EU Standard Contractual Clauses. Commercial API terms: inputs and outputs are not used to train models. Applies when: You enable an AI feature and choose OpenAI

## AI features are optional

AI features are off by default; the customer selects the provider per organisation and can disable it at any time. Until an organisation admin enables an AI feature in the organisation’s settings, none of your data is sent to an AI model provider. When you enable one, only the provider you have chosen receives data, and only the data that feature needs — for example the database schema and query results the insights agent is asked about. Turning the feature off stops the processing immediately.

## What is not a Sub-processor

Integrations you connect yourself — a Slack workspace for notifications, an external Git host, a third-party API your application calls — receive data under your own agreement with that service, not under Dibbla’s DPA. The same applies to any AI provider your application calls directly with its own credentials.

The providers Dibbla uses for its own purposes as a controller — for its marketing website, support and bookkeeping — are described in the [Privacy Policy](/privacy).

## Changes and notice

Dibbla gives at least thirty (30) days’ notice before a new Sub-processor starts processing Customer Personal Data, by updating this page and e-mailing the organisation’s registered contact and everyone subscribed below. During the notice period you may object on reasonable data protection grounds by writing to [privacy@dibbla.com](mailto:privacy@dibbla.com); Section 7 of the DPA sets out what happens then. Removing a Sub-processor, or narrowing what one does, is announced on this page without a notice period.

### Change log

-   **September 21, 2026** — First published.

## Get notified of changes

We e-mail subscribers at least 30 days before a new Sub-processor starts processing customer data.

E-mail

Subscribe

Used only to send Sub-processor notices. Unsubscribe by replying to any notice, or write to privacy@dibbla.com.

Something went wrong. Please try again, or e-mail privacy@dibbla.com with the subject “Subscribe to Sub-processor notices”.

You're subscribed.

We'll e-mail you at least 30 days before any new Sub-processor is added.
