Skip to content

Sub-processors.

The third parties we engage to help deliver Lab33 OS, what each one does, and where your data is processed.

Last updated: 1 June 2026.

When you use Lab33 OS, Lab33 Ltd acts as a processor of the personal data you put into the platform, and you remain the controller of it. To run the platform we rely on a small number of carefully selected third parties. Under Article 28 of the GDPR these are our sub-processors, and this page is the public register of them.

Every sub-processor is bound by a written contract imposing data-protection obligations no less protective than those in our own Data Processing Agreement, and Lab33 remains fully liable to you for their performance. We keep the list short on purpose.

The Register

Who we work with.

Sub-processor Role in the service Personal data handled Entity and domicile Processing location and transfer mechanism
OVHcloud Cloud infrastructure: compute, managed PostgreSQL, managed Valkey, object storage, backups All customer personal data (hosting) OVH SAS, France EU — Paris, with backups in Gravelines and Strasbourg. No transfer outside the EU.
Cloudflare DNS, CDN and web application firewall at the network edge Request metadata. Caches only public, published media derivatives; never fronts private data. Cloudflare, Inc., United States (with EU presence) Global edge. EU Standard Contractual Clauses / EU-US Data Privacy Framework.
Brevo Transactional and automated email delivery Recipient email addresses, names, message subjects and content Brevo SAS, France EU — France. No transfer outside the EU.
Sentry Application error tracking Stack traces and runtime metadata only. PII sending is disabled: no request bodies, no user identifiers. Functional Software, Inc., United States EU region — Frankfurt. EU Standard Contractual Clauses.
BetterStack Log aggregation, uptime monitoring and status page Application logs (scrubbed of personal data at the shipping layer) and uptime data Better Stack, Czech Republic EU. No transfer outside the EU.
Anthropic AI processing for the Oracle, the Chatbot and AI Actions Content submitted to AI features, which may include personal data inside documents or conversations. Not used for model training against you. Anthropic PBC, United States US-routed. EU Standard Contractual Clauses / EU-US Data Privacy Framework.
Swisscom Trust Services Qualified Trust Service Provider for Qualified Electronic Signatures (QES) in Contract33 Signatory identity data required to issue a qualified certificate and validate a signature Swisscom IT Services Finance S.E., Austria (eIDAS qualified trust service provider), operated by Swisscom (Switzerland) Ltd Switzerland and the EU. European Commission adequacy decision for Switzerland (Article 45 GDPR).
Current register of authorised sub-processors.

Data Residency

Where your data lives.

Customer data is hosted and processed in data centres inside the European Union by default. The primary region is Paris, France, across three availability zones, with encrypted geo-redundant backups and disaster-recovery replicas held in Gravelines and Strasbourg. The infrastructure is operated by OVH SAS, a French company.

We do not transfer customer personal data outside the EU or EEA unless the transfer is to a country covered by an adequacy decision under Article 45 of the GDPR, is protected by appropriate safeguards under Article 46 (including the European Commission’s Standard Contractual Clauses, supplemented where a transfer impact assessment requires it), or is otherwise permitted by data protection law.

One category of transfer is worth calling out. Where you use our AI-powered capabilities, the content you submit to them is processed by our AI sub-processor under Article 46 safeguards. Your data is not used to train any model in a way that would compromise its confidentiality.

Security

How the platform is protected.

Changes

How we notify you.

Before we add or replace a sub-processor, we give customers at least thirty days’ written notice, by email to your primary contact and by updating this register.

Within that period you may object in writing on reasonable, documented data-protection grounds. We will then work with you in good faith to find a solution, which may mean proposing an alternative provider or additional safeguards. If no solution is found, you may terminate the affected services under the terms of your agreement, and where your objection is sustained and no reasonable alternative exists, prepaid fees for the unused remainder of the subscription year are refunded pro rata.

Scope

What isn’t on this list.

This register covers only the third parties that process customer personal data on your behalf. It does not include the providers Lab33 uses as an independent controller to run its own business, such as payment processing for our invoices, our internal accounting, and our source-code hosting. Those providers do not process your customer data.

Account data belonging to your authorised users, which we hold for platform administration, authentication and security, along with billing and subscription data, is processed by Lab33 as an independent controller and is covered by our privacy policy rather than this register.