Sub-processors
Sub-processors
The providers involved when we process data on a client’s behalf. Updated 14 August 2026.
Why we publish this list
When we build an assistant or an automation for a client, we process personal data on their behalf: we are the processor and they remain the controller. The providers we need in order to deliver that service are, in turn, sub-processors.
Article 28 of the GDPR gives clients the right to know who they are. Most agencies hand the list over only on request; we would rather have it public so anyone can review it before signing.
This page does not replace our privacy policy, which covers the data we process as controllers: that of anyone who writes to us through the form or the chat.
Sub-processors in every project
These are involved in practically every engagement, whatever the service.
Sub-processors depending on the project
These only appear if the contracted service requires them. Each client contract states which ones apply.
What is not a sub-processor
We spell this out because it often causes confusion:
- GitHub hosts our source code, not personal data belonging to end clients.
- Proton Mail is our corporate email: it processes contact details as its own controller, not on anyone’s behalf. Switzerland holds an adequacy decision from the European Commission.
- n8n, NocoDB and Umami are programs we run on the infrastructure already listed. Their vendors receive no data at all.
Changes to this list
We notify every client at least 30 days before adding or replacing a sub-processor. Within that window they may object on reasonable grounds; if the objection makes the service impossible to deliver, either party may terminate the contract without penalty.
Questions about any provider on this list? Write to parker@byparkerai.com and we will explain it before you sign anything.
Last updated: 14 August 2026
← Back to home