Sub-processors.
The third parties we engage to help deliver Lab33 OS, what each one does, and where your data is processed.
Last updated: 1 June 2026.
When you use Lab33 OS, Lab33 Ltd acts as a processor of the personal data you put into the platform, and you remain the controller of it. To run the platform we rely on a small number of carefully selected third parties. Under Article 28 of the GDPR these are our sub-processors, and this page is the public register of them.
Every sub-processor is bound by a written contract imposing data-protection obligations no less protective than those in our own Data Processing Agreement, and Lab33 remains fully liable to you for their performance. We keep the list short on purpose.
The Register
Who we work with.
| Sub-processor |
Role in the service |
Personal data handled |
Entity and domicile |
Processing location and transfer mechanism |
| OVHcloud |
Cloud infrastructure: compute, managed PostgreSQL, managed Valkey, object storage, backups |
All customer personal data (hosting) |
OVH SAS, France |
EU — Paris, with backups in Gravelines and Strasbourg. No transfer outside the EU. |
| Cloudflare |
DNS, CDN and web application firewall at the network edge |
Request metadata. Caches only public, published media derivatives; never fronts private data. |
Cloudflare, Inc., United States (with EU presence) |
Global edge. EU Standard Contractual Clauses / EU-US Data Privacy Framework. |
| Brevo |
Transactional and automated email delivery |
Recipient email addresses, names, message subjects and content |
Brevo SAS, France |
EU — France. No transfer outside the EU. |
| Sentry |
Application error tracking |
Stack traces and runtime metadata only. PII sending is disabled: no request bodies, no user identifiers. |
Functional Software, Inc., United States |
EU region — Frankfurt. EU Standard Contractual Clauses. |
| BetterStack |
Log aggregation, uptime monitoring and status page |
Application logs (scrubbed of personal data at the shipping layer) and uptime data |
Better Stack, Czech Republic |
EU. No transfer outside the EU. |
| Anthropic |
AI processing for the Oracle, the Chatbot and AI Actions |
Content submitted to AI features, which may include personal data inside documents or conversations. Not used for model training against you. |
Anthropic PBC, United States |
US-routed. EU Standard Contractual Clauses / EU-US Data Privacy Framework. |
| Swisscom Trust Services |
Qualified Trust Service Provider for Qualified Electronic Signatures (QES) in Contract33 |
Signatory identity data required to issue a qualified certificate and validate a signature |
Swisscom IT Services Finance S.E., Austria (eIDAS qualified trust service provider), operated by Swisscom (Switzerland) Ltd |
Switzerland and the EU. European Commission adequacy decision for Switzerland (Article 45 GDPR). |
Current register of authorised sub-processors.
Data Residency
Where your data lives.
Customer data is hosted and processed in data centres inside the European Union by default. The primary region is Paris, France, across three availability zones, with encrypted geo-redundant backups and disaster-recovery replicas held in Gravelines and Strasbourg. The infrastructure is operated by OVH SAS, a French company.
We do not transfer customer personal data outside the EU or EEA unless the transfer is to a country covered by an adequacy decision under Article 45 of the GDPR, is protected by appropriate safeguards under Article 46 (including the European Commission’s Standard Contractual Clauses, supplemented where a transfer impact assessment requires it), or is otherwise permitted by data protection law.
One category of transfer is worth calling out. Where you use our AI-powered capabilities, the content you submit to them is processed by our AI sub-processor under Article 46 safeguards. Your data is not used to train any model in a way that would compromise its confidentiality.
Security
How the platform is protected.
-
EU-sovereign hosting
Infrastructure in Paris across three availability zones, operated by a provider certified to ISO 27001, 27017, 27018 and 27701, SOC 1/2/3, SecNumCloud, HDS and PCI-DSS. Physical security is inherited from the certified data-centre operator.
-
Encryption
TLS 1.2 or above for everything in transit. Encryption at rest for the database, object storage and backups. Application-level encryption for high-sensitivity fields, and per-tenant envelope encryption for media, with keys held in a self-hosted, EU-resident secrets manager.
-
Tenant isolation
Isolation is enforced at the data layer. Every tenant-scoped record carries its organisation identifier and every query passes through automatic tenant scoping, so one customer’s data is never commingled with another’s in application logic.
-
Access control
Role-based access with module-level roles, two-factor authentication, password hashing with breached-password checks, rate limiting and account lockout. Databases and caches are reachable only on private endpoints, and production deploys are gated by approval and 2FA.
-
Logging and monitoring
Structured, correlation-ID audit logging across the application, shipped to an external tamper-evident store with personal data scrubbed at the shipping layer. Error tracking runs in the EU region with PII sending disabled, alongside uptime, metrics and SLO-driven alerting.
-
Resilience and response
High-availability database, encrypted geo-redundant backups in two secondary EU regions with point-in-time recovery, a 4-hour recovery time objective and a 1-hour recovery point objective, quarterly restore drills, and a documented breach-response plan with a maintained incident register.
Changes
How we notify you.
Before we add or replace a sub-processor, we give customers at least thirty days’ written notice, by email to your primary contact and by updating this register.
Within that period you may object in writing on reasonable, documented data-protection grounds. We will then work with you in good faith to find a solution, which may mean proposing an alternative provider or additional safeguards. If no solution is found, you may terminate the affected services under the terms of your agreement, and where your objection is sustained and no reasonable alternative exists, prepaid fees for the unused remainder of the subscription year are refunded pro rata.
Scope
What isn’t on this list.
This register covers only the third parties that process customer personal data on your behalf. It does not include the providers Lab33 uses as an independent controller to run its own business, such as payment processing for our invoices, our internal accounting, and our source-code hosting. Those providers do not process your customer data.
Account data belonging to your authorised users, which we hold for platform administration, authentication and security, along with billing and subscription data, is processed by Lab33 as an independent controller and is covered by our privacy policy rather than this register.