Sub-processors
Last updated 9 September 2026
SeoWrite (DEVITGROUP LTD) uses the sub-processors below to help deliver its Services. This list is referenced by our Data Processing Agreement and forms part of Annex 2 of that agreement. Where a sub-processor processes personal data on behalf of a business customer, it is bound by materially equivalent data-protection obligations, and we remain liable for its processing.
Some entries are marked below as receiving text from which personal data is removed or redacted before sending. We hold no data-processing agreement with those, and none is required: an automated step strips the personal data before the text leaves our systems, and the request is refused rather than sent if that step cannot run. For those entries the technical control (not a contract with them) is what protects you, and we remain liable to you for it. We list them anyway so you can see every service your content touches.
We will give affected customers at least 30 days’ notice, by email, before adding or replacing a sub-processor, so they may object on reasonable data-protection grounds (clause 3(d) of the DPA).
| Sub-processor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Hetzner | Hosting, database and backups | All application data at rest | EU (Nuremberg) | N/A — EU |
| Cloudflare | CDN / WAF / object storage | IP addresses in transit; stored images (may embed personal data if prompted) | EU-pinned | SCCs + Data Privacy Framework (incl. UK Extension) |
| Anthropic | AI text generation (Claude) | Prompt text (may contain customer-supplied personal data); not used for training | USA | Data Privacy Framework (incl. UK Extension) + SCCs |
| OpenAI | AI text (GPT-4o) and image generation | Prompt and image-prompt text (may contain personal data); not used for training | USA | EU SCCs + UK Addendum (also DPF-certified) |
| SMTP2GO | Transactional email delivery | Recipient email address and name | US / EU (Amsterdam) / AU (Sydney) | EU SCCs + UK IDTA (US/AU legs); Amsterdam leg intra-EEA |
| Sentry (Functional Software, Inc.) | Error monitoring / APM | User id, IP address and request context in error events | EU data residency | Data Privacy Framework (UK Extension) + SCCs + UK IDTA |
| Grafana Cloud | Application performance monitoring (traces / metrics) | Request traces and spans (user id + request context) | EU/EEA (Europe West) | Data Privacy Framework (UK Extension) + SCCs |
| Analytics (GA4, via Google Tag Manager) and OAuth login | Pseudonymous analytics ids (no IP stored); OAuth profile + IP at login | USA | Data Privacy Framework (incl. UK Extension) + SCCs | |
| DataForSEO (DataForSEO OÜ) | SEO keyword research | Keywords — usually non-personal, but customer-controlled (may contain personal data) | EU (Estonia) | Intra-EEA (adequate) |
| Tavily (AlphaAI Technologies Inc. d/b/a Tavily) | Web-research grounding (optional per generation) | A constructed search query only — never your raw prompt. Both the prompt and your target keywords are automatically screened and any personal data removed before the query is sent | USA | No personal data transferred: the query is screened and any personal data removed before it is sent, so no restricted transfer of personal data arises. We hold no data-processing agreement with Tavily; the screening is the safeguard |
| Copyscape (Indigo Stream Technologies Ltd) | Plagiarism checks | Generated content text, with personal data automatically redacted before sending. We hold no data-processing agreement with Copyscape; the redaction is the safeguard | Gibraltar / Israel | UK adequacy regulations (Gibraltar and Israel are both listed) — no additional transfer safeguards required |
| Polar (merchant of record) / Stripe (fallback) | Payment and tax processing | Billing metadata (billing email, plan, customer id) | USA | Polar: EU SCCs Module 2 (Sweden) + UK IDTA; Stripe: DPF + SCCs |
Notes
- Intra-group logging. Application logs are processed within DEVITGROUP LTD (same legal entity, EU-hosted) — internal processing, not a third-party sub-processor.
- Customer-configured callbacks. Where a customer configures a webhook or callback URL, SeoWrite sends job-status data to that customer’s own endpoint. This is an onward transfer to the customer, under the customer’s control — not a sub-processor.
- Website analytics and cookie consent. The vendors that operate on SeoWrite’s own website visitors (e.g. our analytics and consent-management tools) are used by SeoWrite as an independent controller of its site visitors’ data, not as a sub-processor of customer content. These are described in our Privacy Policy and Cookie Policy.
- Google. Google is listed above for transparency as a recipient of data, but for these functions SeoWrite does not act as your processor: Google Analytics (GA4) processes SeoWrite’s own website-visitor data, for which SeoWrite is the controller, and “Sign in with Google” is a controller-to-controller login in which Google is an independent controller. Both are covered by our Privacy Policy and Cookie Policy rather than by the Data Processing Agreement.
Questions about this list or a sub-processor change can be sent to [email protected].