Eddytor Cloud

Sub-processors

The third parties Eddytor ApS engages to run Eddytor Cloud, what each one processes, and where it sits.

This page lists the sub-processors Eddytor ApS (CVR DK42920673) engages to process personal data on your behalf and to deliver Eddytor Cloud, as defined in the Data Processing Addendum (DPA). Which entries apply to you depends on the features you turn on - the AI providers below are engaged only if you supply a key for them.

The contractual register is the one published at eddytor.com/subprocessors, which the DPA incorporates by reference. This page is the same list with the operational detail an engineer wants.

Good to know

We give at least 30 days' notice by email or in-app before we add a new sub-processor or replace an existing one. Changes are recorded in Revision history at the bottom of this page.

Infrastructure

Every Eddytor-developed service - REST API, engine, MCP endpoint, Flight SQL, web UI, and the metadata database - runs on one provider, in the EU.

Sub-processorApplicable servicesProcessing activitiesLocation
Hetzner Online GmbHAll servicesHosting of application nodes, the PostgreSQL metadata database, load balancing, and DNS. Processes everything Eddytor Cloud stores: accounts, organisations, table registrations, policies, audit log, and encrypted storage credentials.Falkenstein, Germany (EU)

Eddytor Cloud stores metadata, not table data. Your Delta tables stay in the object store you connect, under your own cloud account - see How it works. The object store you choose (Amazon S3, Azure Blob / ADLS Gen2, Google Cloud Storage, or an S3-compatible endpoint) is your processor, not ours: you pick the provider and the region.

Email

Sub-processorApplicable servicesProcessing activitiesLocation
Intuit Inc. - Mailchimp Transactional (Mandrill)All servicesDelivery of transactional email: magic-link sign-in, workspace invitations, and service notices. Processes email addresses and message contents.US, under Standard Contractual Clauses

Analytics

Sub-processorApplicable servicesProcessing activitiesLocation
InnoCraft Ltd - Matomo CloudWeb UI (app.eddytor.com), website (eddytor.com)Product and website analytics through Matomo Tag Manager: pages viewed, clicks, referrer, browser and device type. IP addresses are anonymised before storage. No data is sold, and the tag container carries no advertising or third-party tags.Data hosted on AWS Europe in Germany, backups in Ireland. InnoCraft Ltd is based in New Zealand, which the European Commission recognises under an adequacy decision.

Eddytor's documentation site carries no analytics and sets no tracking cookies.

AI providers

AI Actions ("magic dust") are off until you store an API key for a provider. The key is yours, encrypted at rest with AEAD, and scoped to your user - Eddytor holds no model credentials of its own. When you invoke an AI Action, the prompt and the column or table context it needs are sent to the provider you selected; your agreement with that provider governs retention and any training opt-out.

Sub-processorApplicable servicesProcessing activitiesLocation
Anthropic PBC (Claude)AI Actions, when selected by youModel inference over the prompt and table context you submitUS / EU regions, per your provider configuration
OpenAI, L.L.C.AI Actions, when selected by youModel inference over the prompt and table context you submitUS / global
Google LLC (Gemini)AI Actions, when selected by youModel inference over the prompt and table context you submitUS / EU regions, per your provider configuration
Mistral AI SASAI Actions, when selected by youModel inference over the prompt and table context you submitEU (France)

Selecting Ollama engages no sub-processor: inference runs on hardware you point Eddytor at, over the base_url you configure.

Self-hosted installations

Good to know

A self-hosted Eddytor engages none of the sub-processors above. You choose the host, the database, the SMTP relay, and the object store, and no telemetry is sent to Eddytor ApS.

One exception is worth knowing before you deploy: the bundled web UI image loads Matomo Tag Manager from cdn.matomo.cloud at runtime, so a browser opening a self-hosted UI reports page views to Eddytor's Matomo instance. The API, engine, MCP, and Flight SQL endpoints send nothing. If you need the UI to be silent, block cdn.matomo.cloud and *.matomo.cloud at your egress or in your Content-Security-Policy.

Your runtime images come from ghcr.io/nordalf/eddytor-ce-server and eddytor-ce-engine, so GitHub hosts the artefacts your cluster pulls - it processes no customer data, and it is your registry to verify: pin and check the image digest rather than a floating tag. See Move to self-hosting.

Data location summary

  • All Eddytor-developed services, and all metadata they store, run in the EU on Hetzner hardware in Falkenstein, Germany.
  • Where a sub-processor processes personal data outside the EU/EEA, we rely on Standard Contractual Clauses, an adequacy decision, or another safeguard the GDPR provides for.
  • Your table data is never in this list - it stays in your own bucket, in the region you chose for it.

Revision history

  • 2026-08-26 - First publication of the register in the help center. Amazon Web Services removed: the Eddytor-hosted sandbox bucket it backed no longer exists (2026-06-04).
  • 2026-06-11 - Stripe Payments Europe, Ltd. removed. Eddytor Cloud is free and carries no billing, so no payment data is processed.
  • 2026-05-26 - Supabase removed. Authentication, the metadata database, and credential encryption now run in Eddytor's own services on Hetzner hardware.

Questions

Sub-processor and DPA questions go to privacy@eddytor.com; GDPR requests to dpo@eddytor.com.

On this page