Parascope Docs

Subprocessors

The third parties Parascope engages to run the service, the role each one plays, what it can see, where it sits, and the 30-day notice you get before that list changes.

A subprocessor is a third party we engage that processes tenant data on our behalf while running Parascope. The table below is the current list: each party, the job it does, what it can see, and where it sits. Adding a party to this list, or replacing one, means we email tenant administrators 30 days before the new party begins processing any of your data. You can object inside that window, and if we cannot resolve the objection between us, you can terminate the subscription. Questions and objections go to privacy@parascope.io.

Current subprocessors

SubprocessorRoleData accessedLocation
HetznerCloud hosting (compute, storage, network)All tenant data. Encryption states which of it is encrypted at rest, under which cipher, and where that protection stops.Helsinki, Finland (EU)
StripeBilling and payment processingTenant billing contact (email address, company name) and subscription details. No configuration-item data.USA (EU-US DPF + SCCs)
CloudflareCDN, WAF, DDoS protection, offsite backup storage (R2), bot verification (Turnstile)HTTP request metadata (IP addresses, headers) in transit. Tenant database backups and write-ahead log archives held persistently in R2 object storage, encrypted before upload. Turnstile additionally processes the IP address and browser characteristics of visitors who submit the contact, advisor or signup forms, for bot detection only.Global edge (EU-US DPF + SCCs)
AnthropicLanguage model provider for AI featuresNatural-language query prompts, including tenant configuration-item names and schema grounding, plus website advisor conversation content. AI Features and Your Data traces each surface.USA (processing) under SCCs via the commercial-terms DPA
PostmarkTransactional email (onboarding, dunning, security alerts)Recipient email addresses and email template content. No configuration-item data.USA (EU-US DPF + SCCs)

The contracting entities. Hetzner Online GmbH; Stripe, Inc.; Cloudflare, Inc.; Wildbit LLC (ActiveCampaign) for Postmark; and Anthropic Ireland, Limited. A data processing agreement is in force with each party that processes data today. For Anthropic that agreement is the Data Processing Addendum incorporated by its Commercial Terms of Service, which we verified on 2026-08-02.

What is not on this list

GitHub and GitHub Container Registry. Our source code and CI/CD run on GitHub, and container images publish to its registry. These are build-time supply-chain vendors, not runtime data processors: they hold source code and container artefacts, and no tenant personal data reaches them. Keeping them off this list is a deliberate decision, recorded as settled in our own inventory. GitHub, Inc. is a USA entity operating under the EU-US Data Privacy Framework and standard contractual clauses, and were it ever to hold customer personal data it would be added here under the 30-day notice. Software Supply Chain describes what that pipeline does.

A second language model provider. The platform carries a provider setting that can be pointed at OpenAI. That switch has never been flipped, so OpenAI processes no Parascope data and is not a subprocessor. Flipping it would mean adding a row to the table above first and serving the notice below.

How changes are notified

  1. We assess the new party's data protection practices and transfer mechanism.
  2. We update the published list.
  3. Tenant administrators are emailed 30 days before that party begins processing.
  4. You may object at any point inside those 30 days, by writing to privacy@parascope.io.
  5. If an objection cannot be resolved between us, you may terminate the subscription.

One thing about that commitment is worth stating plainly. It binds from the first paying customer onward: the two tenants running today are ours and hold synthetic data, so no notice cycle has been owed or served yet.

Where the surrounding detail lives