cosend Legal
Draft — pending legal review. This page states what Cosend does and is accurate to our specification. It has not yet been reviewed by counsel and is not a final agreement.

Sub-processors

Last updated · v0.1

These are the third parties Cosend uses to process customer data. The list is part of our Data Processing Addendum, and adding to it is governed by the 30 days' notice in §6 of that document.

1. The list

Sub-processor Purpose Data Processing location
Meta Platforms WhatsApp message delivery Message content, phone numbers Global
Supabase Database and dashboard authentication All customer data Germany (EU)
Render API hosting All customer data, in transit and in memory Germany (EU)
Hetzner Online GmbH Automation execution — Windmill, from module 9 Automation run data Germany (EU)
Cloudflare DNS, frontend hosting, object storage Media, exports, traffic metadata Global (object storage configurable to the EU)
Stripe Payments Billing details USA and EU
OpenAI AI generation Message content, only when the customer enables AI USA
Anthropic AI generation fallback Message content, only when the customer enables AI USA
OpenRouter AI model gateway, when a non-primary model is selected Message content, only when the customer enables AI USA
Google Sheets, Calendar and Forms connectors Only what the customer's automation sends Global
Resend Transactional email Email addresses USA
Sentry Error tracking Metadata and identifiers only — never message content USA and EU
Better Stack Uptime monitoring Endpoint availability only USA

13 sub-processors, as of 2026-08-23.

2. Where data is processed

Your database, your API hosting and your automation execution are in Germany. That is the single jurisdiction the core of the service runs in, and it is deliberate.

Some sub-processors above are outside the EEA. Where personal data is transferred out of the EEA or the UK, the Standard Contractual Clauses apply and are incorporated into our DPA.

3. Conditional sub-processors

Three rows above only ever see data if you turn something on, and that is worth stating plainly rather than leaving you to infer it from the Data column:

4. Notice of changes

We give at least 30 days' notice by email to your account's administrative contact before adding or replacing a sub-processor, and you may object on data-protection grounds — the procedure is in §6 of the DPA.

To be added to the notification list without being a customer, email privacy@cosend.app with "subscribe" in the subject. There is no form here on purpose: we have nothing to receive it with yet, and a form that silently discards a submission is worse than an email address.

5. Machine-readable

The same list is published at /subprocessors.json, generated from the same source file as the table above. It exists so that this page can be checked against what the service actually calls, rather than being kept in step by memory.