Snack SEO — Sub-processors #
Effective date: 18 August 2026
Last updated: 18 August 2026
This page is the live list of sub-processors that Snack Prompt Corp engages to process personal data in connection with Snack SEO. It forms part of our Data Processing Agreement (as Annex III to the Standard Contractual Clauses) and of our Privacy Policy, and is incorporated into both by reference.
Table of contents #
- What a sub-processor is, and how we manage them
- Core infrastructure sub-processors
- SEO and search data sub-processors
- AI model and AI-search sub-processors
- Operational sub-processors
- Where data is processed, at a glance
- Transfer safeguards
- How to get notified of changes, and how to object
- Change log
1. What a sub-processor is, and how we manage them #
A sub-processor is a third party we engage that may process personal data contained in your Client Data on our behalf, in order to deliver part of the Service.
Before we engage a sub-processor we review its security posture, certifications, data-protection terms and transfer mechanisms. Every sub-processor is bound by a written contract imposing data-protection obligations no less protective than those in our DPA, including confidentiality, purpose limitation, security, assistance and international-transfer requirements. We remain fully liable to you for each sub-processor's performance.
Not every customer's data reaches every sub-processor. Which ones apply depends on the features you use — for example, if you never connect a Google property, no Google user data flows to Google's APIs on your behalf; if you disable AI features, no data flows to the AI providers.
We do not sell personal data to any of these parties, and none of them is permitted to use your data for their own purposes.
2. Core infrastructure sub-processors #
These are engaged for every customer.
| Sub-processor | Legal entity / HQ | Service provided | Personal data processed | Processing location | Transfer safeguard |
|---|---|---|---|---|---|
| Supabase | Supabase, Inc. — United States | Managed PostgreSQL database, authentication, storage and edge functions | All Client Data stored in the platform; account records; authentication credentials and session data; encrypted OAuth tokens | EU (Frankfurt, Germany) for primary data; United States for control-plane and support systems | SCCs + UK Addendum in the vendor DPA; EU data residency for the primary database |
| Hetzner Online GmbH | Hetzner Online GmbH — Gunzenhausen, Germany | Dedicated and cloud servers running the application, workers, crawler and queues | Any Client Data in transit through or temporarily held by application processes; application and access logs | Germany (Nuremberg) — EU only | No transfer out of the EEA; processing under German/EU law and the vendor's Art. 28 DPA |
| Cloudflare | Cloudflare, Inc. — United States | Authoritative DNS, CDN, WAF, DDoS protection, TLS termination, R2 object storage for crawl artefacts, reports and exports | IP addresses and request metadata of users and crawled sites; files stored in R2, which may contain personal data present in crawled pages or exported reports | Global edge network; R2 buckets configured to an EU jurisdiction where available; United States for account and control plane | SCCs + UK Addendum in Cloudflare's DPA; R2 jurisdictional restrictions |
3. SEO and search data sub-processors #
Engaged where you use keyword research, rank tracking, SERP analysis, backlink data or competitor features.
| Sub-processor | Legal entity / HQ | Service provided | Personal data processed | Processing location | Transfer safeguard |
|---|---|---|---|---|---|
| DataForSEO | DataForSEO LLC — United States (with EU operations) | SEO datasets: SERP results, keyword volumes and difficulty, backlink and referring-domain records, on-page and content data | Query strings you submit (which should not contain personal data); IP/request metadata. Returned datasets are about domains and pages, but may incidentally include personal names appearing in results, author profiles or backlink records | United States and European Union | SCCs in the vendor DPA |
| SerpApi | SerpApi, LLC — Austin, Texas, United States | Real-time search engine results retrieval for rank tracking and SERP feature analysis | Query strings and location/device parameters you configure; IP/request metadata. Returned results may incidentally include personal names | United States | SCCs in the vendor DPA |
| Google LLC (Search Console API, Analytics Data API, Business Profile API) | Google LLC — Mountain View, California, United States | Retrieval of your connected property data | Search Console performance rows (queries, pages, countries, devices — Google anonymises rare queries at source); GA4 aggregated report rows; Business Profile locations, metrics, reviews and reviewer display names; OAuth identity of the connecting user | Google's global infrastructure, including the United States and the European Union | SCCs + UK Addendum in Google's Cloud/API data processing terms; our use is additionally governed by the Google API Services User Data Policy, including the Limited Use requirements |
4. AI model and AI-search sub-processors #
Engaged where you use content generation, AI recommendations or AI-search visibility monitoring. All are engaged under API/enterprise terms that prohibit training on our inputs and outputs.
| Sub-processor | Legal entity / HQ | Service provided | Personal data processed | Processing location | Transfer safeguard |
|---|---|---|---|---|---|
| OpenAI | OpenAI, L.L.C. — San Francisco, California, United States | Large language model inference for content generation, analysis, summarisation and AI-visibility monitoring | Prompt content and context you submit, which may contain personal data if you include it; generated outputs | United States (EU/regional processing where the relevant endpoint offers it) | SCCs + UK Addendum in OpenAI's DPA; API terms: no training on API inputs/outputs; limited abuse-monitoring retention (typically ≤30 days) |
| Anthropic | Anthropic, PBC — San Francisco, California, United States | Large language model inference for content generation, analysis and summarisation | Prompt content and context you submit; generated outputs | United States | SCCs + UK Addendum in Anthropic's DPA; commercial terms: no training on inputs/outputs; limited abuse-monitoring retention |
| Google LLC (Gemini API) | Google LLC — United States | Large language model inference and AI-search visibility measurement | Prompt content and context; generated outputs | United States and other Google regions | SCCs + UK Addendum in Google's data processing terms; paid API terms: no training on submitted data |
| OpenRouter | OpenRouter, Inc. — United States | Routing layer providing access to multiple third-party models | Prompt content and context; generated outputs; routing metadata. Data is passed through to the downstream model provider selected for the request | United States, plus the location of the downstream provider | SCCs in the vendor terms; we configure routing to providers with no-training and limited-retention policies |
| Perplexity | Perplexity AI, Inc. — San Francisco, California, United States | AI answer engine queried to measure brand visibility and citation in AI-generated answers | Monitoring prompts you configure; returned answers and citations, which may name individuals | United States | SCCs in the vendor's API terms |
Please note: monitoring prompts you configure are sent to these providers as ordinary API requests. Do not place personal data or confidential information in a monitoring prompt. See section 15 of the DPA.
5. Operational sub-processors #
| Sub-processor | Legal entity / HQ | Service provided | Personal data processed | Processing location | Transfer safeguard |
|---|---|---|---|---|---|
| Resend | Resend (Plus Five Five, Inc.) — United States | Transactional and product email delivery: sign-up, verification, password reset, security alerts, crawl and report notifications, billing notices | Recipient name and email address; email subject and body; delivery, bounce and open metadata | United States (EU sending region where available) | SCCs in the vendor DPA |
| Sentry | Functional Software, Inc. d/b/a Sentry — San Francisco, California, United States | Application error monitoring, performance tracing and diagnostics | User identifier and account/workspace identifier attached to events; IP address; URL being viewed; stack traces and breadcrumbs, which may incidentally contain fragments of Client Data | United States; EU (Frankfurt) region where enabled | SCCs + UK Addendum in Sentry's DPA; we enable data-scrubbing of sensitive fields and, where available, the EU data region |
| Airtable | Formagrid, Inc. d/b/a Airtable — San Francisco, California, United States | Internal business operations: customer records, onboarding and support tracking, waitlist and pipeline management, internal reporting | Customer contact details and company information; support and onboarding notes; subscription and account status. Client Data is not synchronised to Airtable. | United States | SCCs + UK Addendum in Airtable's DPA |
6. Where data is processed, at a glance #
| Region | Sub-processors with processing in that region |
|---|---|
| European Union (Germany) | Hetzner (Nuremberg — application servers), Supabase (Frankfurt — primary database), Cloudflare (EU edge and EU-jurisdiction R2), Sentry (EU region where enabled), Google (EU regions), DataForSEO (EU operations) |
| United States | Supabase (control plane), Cloudflare, Google, OpenAI, Anthropic, OpenRouter, Perplexity, DataForSEO, SerpApi, Resend, Sentry, Airtable |
| Global / other | Cloudflare's edge network serves requests from the point of presence nearest the visitor |
Snack Prompt Corp itself is established in the United States, and our personnel access production systems from the United States. This means that even where data is stored in the EU, it is accessible from the US for support, operations and security purposes. That access is covered by the SCCs in Annex C of the DPA.
7. Transfer safeguards #
For every transfer of personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, we rely on:
- the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), in the module appropriate to each relationship;
- the UK International Data Transfer Addendum (version B1.0) for UK transfers;
- the SCCs with the Swiss adaptations recognised by the FDPIC for Swiss transfers;
- supplementary technical measures, including TLS 1.2+ in transit, AES-256 at rest, strict least-privilege access controls, data minimisation, and a policy of challenging unlawful government access requests; and
- a transfer impact assessment for each material transfer.
We do not currently rely on the EU-US Data Privacy Framework, because Snack Prompt Corp is not certified under it. Some of our sub-processors are separately DPF-certified; where they are, that certification operates in addition to, not instead of, the SCCs we have with them.
You may request a copy of the relevant transfer mechanism, with commercially sensitive terms redacted, by emailing hello@snackseo.com.
8. How to get notified of changes, and how to object #
Notification. We will give at least 30 days' prior notice before adding or replacing a sub-processor. To receive those notices, email hello@snackseo.com with the subject line "Subscribe: Sub-processor changes" and the email address that should receive them. We will also update this page and its change log.
Right to object. Under section 7.4 of the DPA, you may object to a new sub-processor on reasonable, documented data-protection grounds within 30 days of the notice, by emailing hello@snackseo.com. We will work with you in good faith on an alternative or workaround. If none is available, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused remainder of the term.
Emergency changes. Where a change is needed urgently to protect the security or availability of the Service, we may make it immediately and notify you as soon as practicable; your objection right then applies retrospectively.
9. Change log #
| Date | Change |
|---|---|
| 18 August 2026 | Initial published list, effective at launch. |
See also our Privacy Policy, Terms of Service, Data Processing Agreement and Acceptable Use Policy. Questions: hello@snackseo.com.