Sub-processors
The third parties Eddytor ApS engages to run Eddytor Cloud, what each one processes, and where it sits.
This page lists the sub-processors Eddytor ApS (CVR DK42920673) engages to process personal data on your behalf and to deliver Eddytor Cloud, as defined in the Data Processing Addendum (DPA). Which entries apply to you depends on the features you turn on - the AI providers below are engaged only if you supply a key for them.
The contractual register is the one published at eddytor.com/subprocessors, which the DPA incorporates by reference. This page is the same list with the operational detail an engineer wants.
Good to know
Infrastructure
Every Eddytor-developed service - REST API, engine, MCP endpoint, Flight SQL, web UI, and the metadata database - runs on one provider, in the EU.
| Sub-processor | Applicable services | Processing activities | Location |
|---|---|---|---|
| Hetzner Online GmbH | All services | Hosting of application nodes, the PostgreSQL metadata database, load balancing, and DNS. Processes everything Eddytor Cloud stores: accounts, organisations, table registrations, policies, audit log, and encrypted storage credentials. | Falkenstein, Germany (EU) |
Eddytor Cloud stores metadata, not table data. Your Delta tables stay in the object store you connect, under your own cloud account - see How it works. The object store you choose (Amazon S3, Azure Blob / ADLS Gen2, Google Cloud Storage, or an S3-compatible endpoint) is your processor, not ours: you pick the provider and the region.
| Sub-processor | Applicable services | Processing activities | Location |
|---|---|---|---|
| Intuit Inc. - Mailchimp Transactional (Mandrill) | All services | Delivery of transactional email: magic-link sign-in, workspace invitations, and service notices. Processes email addresses and message contents. | US, under Standard Contractual Clauses |
Analytics
| Sub-processor | Applicable services | Processing activities | Location |
|---|---|---|---|
| InnoCraft Ltd - Matomo Cloud | Web UI (app.eddytor.com), website (eddytor.com) | Product and website analytics through Matomo Tag Manager: pages viewed, clicks, referrer, browser and device type. IP addresses are anonymised before storage. No data is sold, and the tag container carries no advertising or third-party tags. | Data hosted on AWS Europe in Germany, backups in Ireland. InnoCraft Ltd is based in New Zealand, which the European Commission recognises under an adequacy decision. |
Eddytor's documentation site carries no analytics and sets no tracking cookies.
AI providers
AI Actions ("magic dust") are off until you store an API key for a provider. The key is yours, encrypted at rest with AEAD, and scoped to your user - Eddytor holds no model credentials of its own. When you invoke an AI Action, the prompt and the column or table context it needs are sent to the provider you selected; your agreement with that provider governs retention and any training opt-out.
| Sub-processor | Applicable services | Processing activities | Location |
|---|---|---|---|
| Anthropic PBC (Claude) | AI Actions, when selected by you | Model inference over the prompt and table context you submit | US / EU regions, per your provider configuration |
| OpenAI, L.L.C. | AI Actions, when selected by you | Model inference over the prompt and table context you submit | US / global |
| Google LLC (Gemini) | AI Actions, when selected by you | Model inference over the prompt and table context you submit | US / EU regions, per your provider configuration |
| Mistral AI SAS | AI Actions, when selected by you | Model inference over the prompt and table context you submit | EU (France) |
Selecting Ollama engages no sub-processor: inference runs on hardware you point
Eddytor at, over the base_url you configure.
Self-hosted installations
Good to know
One exception is worth knowing before you deploy: the bundled web UI image loads
Matomo Tag Manager from cdn.matomo.cloud at runtime, so a browser opening a
self-hosted UI reports page views to Eddytor's Matomo instance. The API, engine, MCP,
and Flight SQL endpoints send nothing. If you need the UI to be silent, block
cdn.matomo.cloud and *.matomo.cloud at your egress or in your Content-Security-Policy.
Your runtime images come from ghcr.io/nordalf/eddytor-ce-server and
eddytor-ce-engine, so GitHub hosts the artefacts your cluster pulls - it processes no
customer data, and it is your registry to verify: pin and check the image digest rather
than a floating tag. See Move to self-hosting.
Data location summary
- All Eddytor-developed services, and all metadata they store, run in the EU on Hetzner hardware in Falkenstein, Germany.
- Where a sub-processor processes personal data outside the EU/EEA, we rely on Standard Contractual Clauses, an adequacy decision, or another safeguard the GDPR provides for.
- Your table data is never in this list - it stays in your own bucket, in the region you chose for it.
Revision history
- 2026-08-26 - First publication of the register in the help center. Amazon Web Services removed: the Eddytor-hosted sandbox bucket it backed no longer exists (2026-06-04).
- 2026-06-11 - Stripe Payments Europe, Ltd. removed. Eddytor Cloud is free and carries no billing, so no payment data is processed.
- 2026-05-26 - Supabase removed. Authentication, the metadata database, and credential encryption now run in Eddytor's own services on Hetzner hardware.
Questions
Sub-processor and DPA questions go to privacy@eddytor.com; GDPR requests to
dpo@eddytor.com.
Related
- How it works - tenancy, isolation, and platform security
- What is Eddytor Cloud? - what the hosted environment stores
- Open-source licenses - the libraries Eddytor is built on