Zum Inhalt springen
Legal

Sub-processors

Last updated 2026-08-12

To run Gooreo we rely on a small number of companies that process data on our behalf. This page names every one of them, what we use it for, and which data reaches it. It is the same list we work from internally — nothing is left out to make it look shorter.

01What a sub-processor is

A sub-processor is a company we engage to handle part of the service — hosting, payments, email delivery, AI inference — and which therefore processes personal data on our instructions. Each one is bound by a contract that limits it to those instructions and requires it to protect what it handles.

02The current list

Some of these only enter the picture if you use the feature they power: a messaging channel receives nothing until you connect it, and the payment provider sees nothing until you buy something.

The current list
ProcessorPurposeData involved
SupabaseDatabase, authentication, and file storage — the platform's primary data layer.Account details, organisation and workspace data, and anything you store in the platform.
StripePayments, subscriptions, and invoices.Billing contact details and payment status. Card details go straight to Stripe and never reach Gooreo's servers.
Zoho (ZeptoMail and Zoho SMTP)Transactional email — invitations, notifications, and account mail.Recipient email address and name, and the contents of that message.
ResendLegacy fallback for transactional email, used only when the primary route is unavailable.The same as the primary route: recipient address, name, and message contents.
AnthropicAI model processing for the steps routed to its models.The prompt content of that step. Not used to train their models under the API terms.
OpenAIAI model processing for the steps routed to its models.The prompt content of that step. Not used to train their models under the API terms.
Google (Gemini)AI model processing for the steps routed to its models.The prompt content of that step. Not used to train their models under the API terms.
Hetzner Online (Germany)Hosting and infrastructure for the app, the brain, and the automation engine.Everything the platform processes passes through, and rests on, this infrastructure.
S3-compatible object storageStorage for the files you upload and the files your Goros produce.The files themselves and their metadata.
Meta (WhatsApp Business Platform)Delivers messages on a WhatsApp channel you connect yourself.Message contents and the channel and account identifiers for that channel.
TelegramDelivers messages on a Telegram channel you connect yourself.Message contents and the channel and account identifiers for that channel.
DiscordDelivers messages on a Discord channel you connect yourself.Message contents and the channel and account identifiers for that channel.
SlackDelivers messages on a Slack workspace you connect yourself.Message contents and the channel and account identifiers for that channel.
SentryError monitoring, so we see failures and fix them.Technical details of the error. Sending personal data along with it is switched off.
PlausibleOptional website analytics. Currently switched off.Aggregate page views only. Cookieless, with no personal identifiers and no cross-site tracking.

03Where data is processed

Gooreo's servers and database run in Germany. Some of the providers above operate outside the European Economic Area; where they do, transfers rest on the safeguards described in our Privacy Policy, such as standard contractual clauses.

04AI providers

When a step of your work needs a model, the content of that step is sent to the provider serving it and the result comes back. Under the API terms we use, none of these providers may take that content to train their models, and we do not use the contents of your workspace to train shared models either.

05Changes and contact

We update this page whenever a sub-processor is added, replaced, or dropped, and the "last updated" date above always reflects the current list. Questions, or want to hear when it changes? Email us at [email protected].