Sub-processors
Last Updated: September 4, 2026
This page lists, by name, the third parties engaged by TONVI TECH S.L. (trading as Upload-Post) as Sub-processors to process Personal Data on behalf of our business customers, together with the country in which the processing takes place and the Article 46 GDPR safeguard that covers any transfer outside the EEA. It forms part of, and is incorporated by reference into, our Data Processing Agreement (DPA) under Article 28 GDPR.
Earlier versions of this page identified sub-processors by category only. That is no longer the case: Articles 13(1)(e) and 28 GDPR require recipients to be identified, and this list, the recipients section of our Privacy Policy and Annex III of the DPA are now generated from a single source and are therefore identical.
All Sub-processors listed below are subject to written agreements containing data protection obligations no less protective than those set out in our DPA, as required by Article 28(4) GDPR. Entries marked self-hosted run on infrastructure operated by TONVI TECH S.L. itself (Hetzner, Germany): no third-party company receives the data.
Current Sub-processors
| Provider | Service | Processing location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Cloud hosting and infrastructure: application servers, MongoDB and Redis databases, back-up staging, GPU/staging server (balrog) and every self-hosted service listed below. | Germany (EU) | Intra-EEA; no third-country transfer. |
| Cloudflare, Inc. | R2 object storage for media files uploaded for publication (media.upload-post.com and the scheduler bucket), plus CDN and DNS for our domains. | European Union (R2 EU jurisdictional restriction) / United States (corporate access) | EU-U.S. Data Privacy Framework (Cloudflare, Inc. is certified) and EU Standard Contractual Clauses (Decision (EU) 2021/914) for any transfer outside the EEA. |
| Google Cloud EMEA Limited / Google LLC (Google Cloud Storage) | Encrypted-at-rest object storage for database back-ups, compressed server logs, copied profile pictures and scheduler payloads (buckets mongodb-img2html, logs-back, pfp-social-pics-upload-post-eu3, upload-post-schedulers-eu3). | European Union (EU multi-region buckets) / United States (corporate access) | EU-U.S. Data Privacy Framework (Google LLC is certified) and EU Standard Contractual Clauses, under the Google Cloud Data Processing Addendum. |
| Google LLC (Gemini API, paid tier) | AI features: analysis of the full video you submit to the Shorts analyser (image and audio), generation of captions, titles, descriptions and hashtags, the support assistant and the documentation assistant. | United States | EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses. On the paid tier Google does not use the submitted content to train its models (Google APIs Terms of Service — Paid Services). |
| Google Ireland Limited / Google LLC (Google Ads) | Advertising measurement: the gtag conversion tag on the website (marketing cookies only, and only with your consent) and the Offline Conversions API, to which a SHA-256 hash of the buyer email address is sent when a subscription is paid. | Ireland (EU) / United States | EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses, under the Google Ads Data Processing Terms. |
| Reddit, Inc. | Advertising measurement for our Reddit campaigns: the Reddit advertising pixel (marketing cookies only, and only with your consent) and the Reddit Conversions API, to which a SHA-256 hash of the buyer email address is sent when a subscription is paid. | United States | EU Standard Contractual Clauses (Decision (EU) 2021/914) and supplementary measures. |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Hosted checkout, subscription billing, invoicing, automatic VAT calculation and VAT-number collection. Card data is entered on Stripe pages and never reaches our servers. | Ireland (EU) / United States | EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses. |
| Amazon Web Services EMEA SARL (Amazon SES) | Transactional email delivery: magic sign-in links, account and billing notifications. | France (eu-west-3) | Intra-EEA primary processing; EU Standard Contractual Clauses for incidental support access. |
| Namecheap, Inc. (PrivateEmail / Titan) | Hosted mailbox for [email protected] — receipt of customer correspondence and support requests — and fallback SMTP relay when Amazon SES is unavailable. | United States | EU Standard Contractual Clauses. |
| Listmonk (self-hosted by TONVI TECH SL) Self-hosted | Newsletter and product-marketing email list (churnkiller.upload-post.com). Only subscribers who opted in receive marketing email; every message carries a one-click unsubscribe link. | Germany (EU) — our own server at Hetzner | Intra-EEA; no third-party processor involved. |
| OpenPanel (self-hosted by TONVI TECH SL) Self-hosted | Product and website analytics (api.openpanel.fotoexamen.com). The browser SDK is served from www.upload-post.com itself, so no third-party host sees your IP address. Analytics only runs with your consent. | Germany (EU) — our own server at Hetzner | Intra-EEA; no third-party processor involved. |
| Upload-Post media processing service "balrog" (self-hosted by TONVI TECH SL) Self-hosted | Server-side video processing with ffmpeg (trimming, re-encoding, subtitles, format conversion) for the media you submit. Processed results are deleted after 24 hours. | Germany (EU) — our own server at Hetzner | Intra-EEA; no third-party processor involved. |
| Upload-Post affiliate platform (self-hosted by TONVI TECH SL) Self-hosted | affiliates.upload-post.com — attribution of affiliate clicks and commissions. Receives the affiliate code, landing page, referrer and any advertising click identifiers, and later the conversion, plus the payout details of affiliates who join the programme. | Germany (EU) — our own server at Hetzner | Intra-EEA; no third-party processor involved. |
| Aikount — TONVI TECH SL Self-hosted | Statutory invoicing and accounting for the invoices we are legally required to issue and keep (api.aikount.com). Receives the billing identifiers of the transaction (Stripe customer id, amounts, tax data). | Spain (EU) — operated by the controller itself | Intra-EEA; same corporate group as the controller. |
| Telegram Messenger Inc. | Internal operational and security alerts to the engineering channel (failed payments, sign-up abuse, platform restrictions). Being phased out; the alerts currently sent contain only pseudonymised identifiers (an 8-character hash plus the email domain) and a truncated IP address, never a full email address. | Outside the EEA (United Arab Emirates / United Kingdom) | EU Standard Contractual Clauses are not available for this channel; the transfer is minimised to pseudonymised identifiers and the channel is being replaced by an internal alerting system. |
AI processing: AI features are powered by the Google Gemini API on the paid tier, under which Google does not use submitted content to train its models. Upload-Post itself does not use customer User Content in identifiable form to train shared AI models; it uses User Content and associated analytics only in aggregated and/or de-identified form to develop and improve its own models, as described in our Privacy Policy. You can opt out of that use at any time from the account settings (Exclude my data from model training) or by emailing [email protected].
Advertising recipients
Google (Google Ads) and Reddit appear in the table above because they receive a hashed email address through the offline/server-side conversion APIs when a subscription is paid, and — only where the visitor has consented — a browser identifier through their advertising tags. Their browser tags are blocked until consent is given; see our Cookie Policy for the exact cookies, durations and how to withdraw consent.
Social Media Platform Recipients
In addition to the Sub-processors listed above, Personal Data is transmitted to the social media platforms connected by the customer for the purpose of publishing content. These platforms act as independent controllers of the Personal Data once received and apply their own terms of service, privacy policies and international transfer mechanisms. Upload-Post acts merely as a technical conduit for these transmissions and is not a Sub-processor in respect of the platforms' subsequent Processing.
| Platform | Operator | Transfer basis (as published by the operator) |
|---|---|---|
| Instagram, Facebook, Threads | Meta Platforms Ireland Ltd. (EU) / Meta Platforms, Inc. (US) | EU-U.S. Data Privacy Framework; SCCs. |
| TikTok | TikTok Information Technologies UK Ltd. / TikTok Technology Ltd. (Ireland) | SCCs and supplementary measures (Project Clover for EU data). |
| YouTube | Google Ireland Ltd. / Google LLC (US) | EU-U.S. Data Privacy Framework; SCCs. |
| X (Twitter) | X Corp. (US) | SCCs. |
| LinkedIn Ireland Unlimited Company / LinkedIn Corporation (US) | EU-U.S. Data Privacy Framework; SCCs. | |
| Pinterest Europe Ltd. (Ireland) / Pinterest Inc. (US) | EU-U.S. Data Privacy Framework; SCCs. | |
| Reddit, Inc. (US) | SCCs. | |
| Bluesky | Bluesky PBLLC (US) | SCCs. |
| Google Business Profile | Google Ireland Ltd. / Google LLC (US) | EU-U.S. Data Privacy Framework; SCCs. |
| Telegram, Discord, Slack, WordPress, Whop and other destinations you connect | The respective operator | As published by each operator. |
Infrastructure Locations (EU Data Act, Article 28)
Pursuant to Article 28 of Regulation (EU) 2023/2854 (the Data Act), the ICT infrastructure used to provide the Services is located as follows: application servers, databases, media processing, the affiliate platform, the analytics server and the mailing server in the European Union (Germany, Hetzner); object storage for media files with an EU jurisdictional restriction at Cloudflare R2; back-ups and log archives in EU regions of Google Cloud Storage; transactional email from Amazon SES in France (eu-west-3). Transfers to the United States are limited to payment processing (Stripe), the corporate mailbox (Namecheap), advertising measurement (Google Ads, Reddit) and the Gemini API, in each case under the safeguards stated in the table. We protect customer data against unlawful third-country governmental access through EU data residency for primary storage, encryption in transit and at rest, encryption of stored OAuth tokens, strict access controls and, where a transfer occurs, EU Standard Contractual Clauses with supplementary measures.
Notification of Changes
We will provide notice of any intended addition or replacement of Sub-processors at least thirty (30) days before the change takes effect, by updating this page and, for customers who have signed a DPA, by email. Customers under a signed DPA may object to a change on reasonable data protection grounds within fifteen (15) days of notice, in accordance with the procedure set out in our DPA.
Contact
Questions about our Sub-processors, data residency, or the applicable transfer mechanisms can be sent to [email protected] or [email protected].
For the full GDPR Article 28 framework governing our Processing on behalf of business customers, see our Data Processing Agreement. For an overview of how we handle Personal Data more broadly, see our Privacy Policy and our Cookie Policy.