Snack SEO — Sub-processors #

Effective date: 18 August 2026
Last updated: 18 August 2026

This page is the live list of sub-processors that Snack Prompt Corp engages to process personal data in connection with Snack SEO. It forms part of our Data Processing Agreement (as Annex III to the Standard Contractual Clauses) and of our Privacy Policy, and is incorporated into both by reference.


Table of contents #

  1. What a sub-processor is, and how we manage them
  2. Core infrastructure sub-processors
  3. SEO and search data sub-processors
  4. AI model and AI-search sub-processors
  5. Operational sub-processors
  6. Where data is processed, at a glance
  7. Transfer safeguards
  8. How to get notified of changes, and how to object
  9. Change log

1. What a sub-processor is, and how we manage them #

A sub-processor is a third party we engage that may process personal data contained in your Client Data on our behalf, in order to deliver part of the Service.

Before we engage a sub-processor we review its security posture, certifications, data-protection terms and transfer mechanisms. Every sub-processor is bound by a written contract imposing data-protection obligations no less protective than those in our DPA, including confidentiality, purpose limitation, security, assistance and international-transfer requirements. We remain fully liable to you for each sub-processor's performance.

Not every customer's data reaches every sub-processor. Which ones apply depends on the features you use — for example, if you never connect a Google property, no Google user data flows to Google's APIs on your behalf; if you disable AI features, no data flows to the AI providers.

We do not sell personal data to any of these parties, and none of them is permitted to use your data for their own purposes.


2. Core infrastructure sub-processors #

These are engaged for every customer.

Sub-processorLegal entity / HQService providedPersonal data processedProcessing locationTransfer safeguard
SupabaseSupabase, Inc. — United StatesManaged PostgreSQL database, authentication, storage and edge functionsAll Client Data stored in the platform; account records; authentication credentials and session data; encrypted OAuth tokensEU (Frankfurt, Germany) for primary data; United States for control-plane and support systemsSCCs + UK Addendum in the vendor DPA; EU data residency for the primary database
Hetzner Online GmbHHetzner Online GmbH — Gunzenhausen, GermanyDedicated and cloud servers running the application, workers, crawler and queuesAny Client Data in transit through or temporarily held by application processes; application and access logsGermany (Nuremberg) — EU onlyNo transfer out of the EEA; processing under German/EU law and the vendor's Art. 28 DPA
CloudflareCloudflare, Inc. — United StatesAuthoritative DNS, CDN, WAF, DDoS protection, TLS termination, R2 object storage for crawl artefacts, reports and exportsIP addresses and request metadata of users and crawled sites; files stored in R2, which may contain personal data present in crawled pages or exported reportsGlobal edge network; R2 buckets configured to an EU jurisdiction where available; United States for account and control planeSCCs + UK Addendum in Cloudflare's DPA; R2 jurisdictional restrictions

3. SEO and search data sub-processors #

Engaged where you use keyword research, rank tracking, SERP analysis, backlink data or competitor features.

Sub-processorLegal entity / HQService providedPersonal data processedProcessing locationTransfer safeguard
DataForSEODataForSEO LLC — United States (with EU operations)SEO datasets: SERP results, keyword volumes and difficulty, backlink and referring-domain records, on-page and content dataQuery strings you submit (which should not contain personal data); IP/request metadata. Returned datasets are about domains and pages, but may incidentally include personal names appearing in results, author profiles or backlink recordsUnited States and European UnionSCCs in the vendor DPA
SerpApiSerpApi, LLC — Austin, Texas, United StatesReal-time search engine results retrieval for rank tracking and SERP feature analysisQuery strings and location/device parameters you configure; IP/request metadata. Returned results may incidentally include personal namesUnited StatesSCCs in the vendor DPA
Google LLC (Search Console API, Analytics Data API, Business Profile API)Google LLC — Mountain View, California, United StatesRetrieval of your connected property dataSearch Console performance rows (queries, pages, countries, devices — Google anonymises rare queries at source); GA4 aggregated report rows; Business Profile locations, metrics, reviews and reviewer display names; OAuth identity of the connecting userGoogle's global infrastructure, including the United States and the European UnionSCCs + UK Addendum in Google's Cloud/API data processing terms; our use is additionally governed by the Google API Services User Data Policy, including the Limited Use requirements

4. AI model and AI-search sub-processors #

Engaged where you use content generation, AI recommendations or AI-search visibility monitoring. All are engaged under API/enterprise terms that prohibit training on our inputs and outputs.

Sub-processorLegal entity / HQService providedPersonal data processedProcessing locationTransfer safeguard
OpenAIOpenAI, L.L.C. — San Francisco, California, United StatesLarge language model inference for content generation, analysis, summarisation and AI-visibility monitoringPrompt content and context you submit, which may contain personal data if you include it; generated outputsUnited States (EU/regional processing where the relevant endpoint offers it)SCCs + UK Addendum in OpenAI's DPA; API terms: no training on API inputs/outputs; limited abuse-monitoring retention (typically ≤30 days)
AnthropicAnthropic, PBC — San Francisco, California, United StatesLarge language model inference for content generation, analysis and summarisationPrompt content and context you submit; generated outputsUnited StatesSCCs + UK Addendum in Anthropic's DPA; commercial terms: no training on inputs/outputs; limited abuse-monitoring retention
Google LLC (Gemini API)Google LLC — United StatesLarge language model inference and AI-search visibility measurementPrompt content and context; generated outputsUnited States and other Google regionsSCCs + UK Addendum in Google's data processing terms; paid API terms: no training on submitted data
OpenRouterOpenRouter, Inc. — United StatesRouting layer providing access to multiple third-party modelsPrompt content and context; generated outputs; routing metadata. Data is passed through to the downstream model provider selected for the requestUnited States, plus the location of the downstream providerSCCs in the vendor terms; we configure routing to providers with no-training and limited-retention policies
PerplexityPerplexity AI, Inc. — San Francisco, California, United StatesAI answer engine queried to measure brand visibility and citation in AI-generated answersMonitoring prompts you configure; returned answers and citations, which may name individualsUnited StatesSCCs in the vendor's API terms

Please note: monitoring prompts you configure are sent to these providers as ordinary API requests. Do not place personal data or confidential information in a monitoring prompt. See section 15 of the DPA.


5. Operational sub-processors #

Sub-processorLegal entity / HQService providedPersonal data processedProcessing locationTransfer safeguard
ResendResend (Plus Five Five, Inc.) — United StatesTransactional and product email delivery: sign-up, verification, password reset, security alerts, crawl and report notifications, billing noticesRecipient name and email address; email subject and body; delivery, bounce and open metadataUnited States (EU sending region where available)SCCs in the vendor DPA
SentryFunctional Software, Inc. d/b/a Sentry — San Francisco, California, United StatesApplication error monitoring, performance tracing and diagnosticsUser identifier and account/workspace identifier attached to events; IP address; URL being viewed; stack traces and breadcrumbs, which may incidentally contain fragments of Client DataUnited States; EU (Frankfurt) region where enabledSCCs + UK Addendum in Sentry's DPA; we enable data-scrubbing of sensitive fields and, where available, the EU data region
AirtableFormagrid, Inc. d/b/a Airtable — San Francisco, California, United StatesInternal business operations: customer records, onboarding and support tracking, waitlist and pipeline management, internal reportingCustomer contact details and company information; support and onboarding notes; subscription and account status. Client Data is not synchronised to Airtable.United StatesSCCs + UK Addendum in Airtable's DPA

6. Where data is processed, at a glance #

RegionSub-processors with processing in that region
European Union (Germany)Hetzner (Nuremberg — application servers), Supabase (Frankfurt — primary database), Cloudflare (EU edge and EU-jurisdiction R2), Sentry (EU region where enabled), Google (EU regions), DataForSEO (EU operations)
United StatesSupabase (control plane), Cloudflare, Google, OpenAI, Anthropic, OpenRouter, Perplexity, DataForSEO, SerpApi, Resend, Sentry, Airtable
Global / otherCloudflare's edge network serves requests from the point of presence nearest the visitor

Snack Prompt Corp itself is established in the United States, and our personnel access production systems from the United States. This means that even where data is stored in the EU, it is accessible from the US for support, operations and security purposes. That access is covered by the SCCs in Annex C of the DPA.


7. Transfer safeguards #

For every transfer of personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, we rely on:

We do not currently rely on the EU-US Data Privacy Framework, because Snack Prompt Corp is not certified under it. Some of our sub-processors are separately DPF-certified; where they are, that certification operates in addition to, not instead of, the SCCs we have with them.

You may request a copy of the relevant transfer mechanism, with commercially sensitive terms redacted, by emailing hello@snackseo.com.


8. How to get notified of changes, and how to object #

Notification. We will give at least 30 days' prior notice before adding or replacing a sub-processor. To receive those notices, email hello@snackseo.com with the subject line "Subscribe: Sub-processor changes" and the email address that should receive them. We will also update this page and its change log.

Right to object. Under section 7.4 of the DPA, you may object to a new sub-processor on reasonable, documented data-protection grounds within 30 days of the notice, by emailing hello@snackseo.com. We will work with you in good faith on an alternative or workaround. If none is available, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused remainder of the term.

Emergency changes. Where a change is needed urgently to protect the security or availability of the Service, we may make it immediately and notify you as soon as practicable; your objection right then applies retrospectively.


9. Change log #

DateChange
18 August 2026Initial published list, effective at launch.

See also our Privacy Policy, Terms of Service, Data Processing Agreement and Acceptable Use Policy. Questions: hello@snackseo.com.