Sub-processors.
The third parties we engage to help deliver Lab33 OS, what each one does, and where your data is processed.
Last updated: 17 August 2026.
When you use Lab33 OS, Lab33 Ltd acts as a processor of the personal data you put into the platform, and you remain the controller of it. To run the platform we rely on a small number of carefully selected third parties. Under Article 28 of the GDPR these are our sub-processors, and this page is the public register of them.
Every sub-processor is bound by a written contract imposing data-protection obligations no less protective than those in our own Data Processing Agreement, and Lab33 remains fully liable to you for their performance. We keep the list short on purpose.
The Register
Who we work with.
| Sub-processor |
Role in the service |
Personal data handled |
Entity and domicile |
Processing location and transfer mechanism |
| OVHcloud |
Cloud infrastructure: compute, managed PostgreSQL, managed Valkey, object storage, backups |
All customer personal data (hosting) |
OVH Hosting Ltd, Ireland (datacentres operated by the OVH group in France) |
EU - Paris, with backups in Gravelines and Strasbourg. No transfer outside the EU. |
| Cloudflare |
DNS, CDN and web application firewall at the network edge |
Request metadata. Caches only public, published media derivatives; never fronts private data. |
Cloudflare, Inc., United States (with EU presence) |
Global edge. EU Standard Contractual Clauses and EU-US Data Privacy Framework. |
| Brevo |
Transactional and automated email delivery, and inbound invoice intake for SIMS33 |
Recipient email addresses, names, message subjects and content. Supplier invoice attachments forwarded to the SIMS33 inbound invoice intake are held by Brevo. |
Brevo SAS, France |
EU - France. No transfer outside the EU. |
| Sentry |
Application error tracking |
Stack traces and runtime metadata only. PII sending is disabled: no request bodies, no user identifiers. |
Functional Software, Inc., United States |
EU region - Frankfurt. EU Standard Contractual Clauses. |
| BetterStack |
Log aggregation, uptime monitoring and status page |
Infrastructure and security logs, which include IP addresses, plus uptime data |
Better Stack, s.r.o., Czech Republic |
EU - logs in Germany; account and uptime data in Germany and Finland. No transfer outside the EU. |
| Anthropic |
AI processing for the Oracle, the Chatbot and AI Actions |
Content submitted to AI features, which may include personal data inside documents or conversations. Processed under our data processing agreement with Anthropic and EU Standard Contractual Clauses. Anthropic does not use submitted content to train its models, and API inputs and outputs are retained for a maximum of 30 days. |
Anthropic PBC, United States |
US-routed. EU Standard Contractual Clauses, with UK and Swiss addenda. |
Current register of authorised sub-processors.
Qualified Electronic Signatures (QES) in Contract33 are provided through Swisscom Trust Services, a qualified trust service provider under the eIDAS Regulation. As a qualified trust service provider, Swisscom acts as an independent data controller for signer identity verification and the issuance of qualified certificates, under its own statutory obligations, and is therefore not a sub-processor. When a signature is requested, Swisscom receives a cryptographic hash of the document (never the document itself), the contract reference, and the signer's mobile number where previously verified. Signer identity and signature evidence data is processed only within the EEA and Switzerland, which is covered by a European Commission adequacy decision (Article 45 GDPR), and is retained under the statutory retention periods that apply to qualified trust service providers. This processing is governed by Swisscom's own terms and privacy statements.
Data Residency
Where your data lives.
Customer data is hosted and processed in data centres inside the European Union by default. The primary region is Paris, France, across three availability zones, with encrypted geo-redundant backups and disaster-recovery replicas held in Gravelines and Strasbourg. The infrastructure is contracted through OVH Hosting Ltd, an Irish company, and the data centres are operated by the OVH group in France.
We do not transfer customer personal data outside the EU or EEA unless the transfer is to a country covered by an adequacy decision under Article 45 of the GDPR, is protected by appropriate safeguards under Article 46 (including the European Commission’s Standard Contractual Clauses, supplemented where a transfer impact assessment requires it), or is otherwise permitted by data protection law.
One category of transfer is worth calling out. Where you use our AI-powered capabilities, the content you submit to them is processed by our AI sub-processor in the United States, under our data processing agreement with that provider and the EU Standard Contractual Clauses (Article 46 safeguards).
Security
How the platform is protected.
-
EU-sovereign hosting
Infrastructure in Paris across three availability zones, operated by a provider certified to ISO 27001, 27017, 27018 and 27701, SOC 1/2/3, SecNumCloud, HDS and PCI-DSS. Physical security is inherited from the certified data-centre operator.
-
Encryption
TLS 1.2 or above for everything in transit. Encryption at rest for the database, object storage and backups. Application-level encryption for high-sensitivity fields, and per-tenant envelope encryption for media, with keys held in EU-resident, encrypted secrets custody under our own control.
-
Tenant isolation
Isolation is enforced at the data layer. Every tenant-scoped record carries its organisation identifier and every query passes through automatic tenant scoping, so one customer’s data is never commingled with another’s in application logic.
-
Access control
Role-based access with module-level roles, two-factor authentication, password hashing with breached-password checks, rate limiting and account lockout. Databases and caches are reachable only on private endpoints, and production deploys are gated by approval and 2FA.
-
Logging and monitoring
Structured, correlation-ID audit logging across the application, shipped to an EU-hosted, tamper-evident external store. Error tracking runs in the EU region with PII sending disabled, alongside uptime, metrics and SLO-driven alerting.
-
Resilience and response
High-availability database, encrypted geo-redundant backups in two secondary EU regions with point-in-time recovery, a 4-hour recovery time objective and a 1-hour recovery point objective, quarterly restore drills, and a documented breach-response plan with a maintained incident register.
Changes
How we notify you.
Before we add or replace a sub-processor, we give customers at least thirty days’ written notice, by email to your primary contact and by updating this register.
Within that period you may object in writing on reasonable, documented data-protection grounds. We will then work with you in good faith to find a solution, which may mean proposing an alternative provider or additional safeguards. If no solution is found, you may terminate the affected services under the terms of your agreement, and where your objection is sustained and no reasonable alternative exists, prepaid fees for the unused remainder of the subscription year are refunded pro rata.
Scope
What isn’t on this list.
This register covers only the third parties that process customer personal data on your behalf under Article 28 of the GDPR. Providers that touch only data Lab33 processes as an independent controller, such as payment processing for our own invoices, our own accounting, and our source-code hosting, are not sub-processors of your platform data. They are Lab33's own processors, they hold data-protection agreements with us in that capacity, and they are disclosed in our privacy policy rather than here.
Account data belonging to your authorised users, which we hold for platform administration, authentication and security, along with billing and subscription data, is processed by Lab33 as an independent controller and is covered by our privacy policy rather than this register.