Sub-processors

Totalum, Inc.

Effective: · Version 2.0 · Binds users registered before that date from

1. About this list

A sub-processor is a third party that Totalum, Inc. engages to process personal data on behalf of its customers as part of providing the Service. This page is Annex III of our Data Processing Addendum and is referenced by our Privacy Policy. Under the Data Processing Addendum you give us general written authorization to use the sub-processors listed here, and we remain responsible to you for their performance.

The page has two lists. The first covers providers that may process Customer Project Data: the code, database contents, files, prompts and end-user personal data inside the Projects you build, for which you are the controller or business and we are the processor or service provider. The second covers providers that process only Account data about you as our customer (identity, billing, support, marketing), for which we are the controller; they are listed here for transparency, and the Privacy Policy is the governing document for that processing.

Locations refer to where the provider is established and where processing principally occurs. Where a provider is established in the United States, transfers from the European Economic Area, the United Kingdom and Switzerland rest on that provider's certification under the EU-US Data Privacy Framework (and its UK and Swiss extensions) where it holds one, and otherwise on the Standard Contractual Clauses of Commission Decision 2021/914 with the UK Addendum and Swiss amendments. Certification status can change; the authoritative record is the Data Privacy Framework list.

2. Sub-processors of Customer Project Data

These providers may receive data from inside your Projects. Several of them are engaged only when you enable the corresponding feature; the table says so.

Sub-processors that may process Customer Project Data. GitHub and Figma are engaged only for Projects where you connect them; Resend only when your app uses the email integration.
ProviderEntity and locationPurposeData involvedTransfer mechanism
AnthropicAnthropic, PBC, San Francisco, United StatesAI code generation: the coding agent that builds and modifies your Project runs on Claude modelsPrompts, instructions, the Project's source code and file tree, the agent conversation, attachments you add to prompts, error output. Not used to train models under our commercial agreement.EU-US Data Privacy Framework (verify on the DPF list); Standard Contractual Clauses as fallback
OpenAIOpenAI, L.L.C., San Francisco, United StatesSpeech-to-text (Whisper) when you dictate a prompt; drafting assistance on support-conversation textAudio you record in the composer and its transcript; the text of support conversations. Not used to train models under the API terms.Standard Contractual Clauses (Decision 2021/914) with UK Addendum and Swiss amendments
EU infrastructure providerInfrastructure-as-a-service provider established in the European Union, datacenters in the European Union (identity disclosed to customers on request under the DPA)Virtual machines for build sandboxes, API nodes and the MongoDB database nodes that hold Project databasesThe complete Project: source code, database contents, files, environment variables, build artefacts, agent working filesNo international transfer: processing within the EU
CloudflareCloudflare, Inc., San Francisco, United States; global edge networkHosting and delivery of published apps (Workers for Platforms), of totalum.app and of platform.totalum.app; TLS, DDoS protection, CDN; screenshots of published apps (Browser Rendering)The published app bundle and its static assets, request metadata of the app's visitors (IP address, headers, request logs), custom-domain configuration, page screenshotsEU-US Data Privacy Framework (verify on the DPF list); Standard Contractual Clauses as fallback
Google Cloud StorageGoogle LLC, Mountain View, United States; Google Cloud EMEA Limited, Dublin, Ireland for EEA/UK customersObject storage for files uploaded through the Service, project archives, agent execution logs, screenshots and support attachmentsUploaded files and attachments, source-code archives, agent run logs (which contain prompts and generated code), screenshotsEU-US Data Privacy Framework (verify on the DPF list); Standard Contractual Clauses as fallback
ResendResend, Inc., Wilmington, Delaware, United StatesOutbound email sent by published apps that use the built-in email integration (only if your app sends email through it)Recipient addresses, subject and body of emails your app sends, delivery metadataStandard Contractual Clauses (Decision 2021/914) with UK Addendum and Swiss amendments
ScrapflyScrapfly SAS, Paris, France (European Union)Fallback provider for the thumbnail screenshot of your published app when Cloudflare Browser Rendering is unavailableThe public URL of your published app and the rendered page imageNo international transfer: processing within the EU
GitHubGitHub, Inc. (a Microsoft company), San Francisco, United StatesTwo-way repository synchronization, only when you connect a GitHub repository to a ProjectThe Project's source code and commit history, your GitHub identity and access tokenEU-US Data Privacy Framework (Microsoft Corporation certification) (verify on the DPF list); Standard Contractual Clauses as fallback
FigmaFigma, Inc., San Francisco, United StatesImport of designs, only when you connect a Figma fileThe design file contents and assets you import; your Figma access token is validated and not storedStandard Contractual Clauses (Decision 2021/914) with UK Addendum and Swiss amendments

We do not use any other provider to process Customer Project Data. Support staff of Totalum, Inc. may access a Project when you ask for help or when abuse or a security incident requires it; that access is by our own personnel under confidentiality obligations, not by a sub-processor.

3. Providers that process only Account data

These providers never receive the contents of your Projects. They process data about you as our customer, in our capacity as controller, for the purposes described in the Privacy Policy.

Providers engaged for Totalum's own account, billing, security and marketing processing.
ProviderEntity and locationPurposeData involvedTransfer mechanism
StripeStripe, Inc., San Francisco, United States; Stripe Payments Europe, Ltd., Dublin, IrelandPayment processing, subscriptions, invoices, saved payment methods, tax calculationName, email, billing address and country, tax id, payment-method details (entered directly on Stripe; we never see full card numbers), transaction historyEU-US Data Privacy Framework (verify on the DPF list); Standard Contractual Clauses as fallback
Twilio SendGridTwilio Inc., San Francisco, United StatesTransactional and account email (verification codes, receipts, renewal reminders, credit alerts, referral notices, support replies)Email address, name, the content of the message, delivery and open eventsEU-US Data Privacy Framework (verify on the DPF list); Standard Contractual Clauses as fallback
Google reCAPTCHAGoogle LLC, Mountain View, United States; Google Ireland Limited for EEA/UKBot and fraud detection on the sign-up form (reCAPTCHA v3)IP address, browser and device signals, interaction data on the sign-up pageEU-US Data Privacy Framework (verify on the DPF list); Standard Contractual Clauses as fallback
Google Sign-InGoogle LLC / Google Ireland LimitedAuthentication when you choose to sign in with GoogleYour Google account id, email, name and avatarEU-US Data Privacy Framework (verify on the DPF list); Standard Contractual Clauses as fallback
Google Analytics 4 and Google AdsGoogle LLC / Google Ireland LimitedMeasurement of platform usage and of advertising conversions (server-side sign-up events; offline conversion import for ads), subject to your cookie choicesAnalytics client id, country, sign-up method, hashed email or phone, click identifiers (gclid), IP address and user agent at registration, purchase valueEU-US Data Privacy Framework (verify on the DPF list); Standard Contractual Clauses as fallback
MetaMeta Platforms, Inc., Menlo Park, United States; Meta Platforms Ireland LimitedAdvertising measurement through the Meta Pixel (website) and the Conversions API (server-side), subject to your cookie choicesHashed email and phone, browser identifiers (_fbp, _fbc), click identifier (fbclid), IP address and user agent, event type (Lead, Purchase) and valueEU-US Data Privacy Framework (verify on the DPF list); Standard Contractual Clauses as fallback
RedditReddit, Inc., San Francisco, United StatesAdvertising measurement through the Reddit Pixel (website) and the Conversions API (server-side), subject to your cookie choicesHashed email, Reddit click and browser identifiers (rdt_cid, rdt_uuid), IP address and user agent, event typeStandard Contractual Clauses (Decision 2021/914) with UK Addendum and Swiss amendments
CalendlyCalendly LLC, Atlanta, United StatesScheduling, only if you book a call with us through the booking link on our websiteName, email, chosen time, any notes you enterStandard Contractual Clauses (Decision 2021/914) with UK Addendum and Swiss amendments

Sentry (error monitoring) and Mixpanel (product analytics) are used only by the legacy account panel and legacy project back-office for customers who have not migrated to the current platform; they receive error traces and interaction events with a pseudonymous user identifier, under Standard Contractual Clauses. Our source-code hosting provider for internal templates holds no customer data.

4. Infrastructure locations and government-access safeguards

This section provides the information required by Article 28 of Regulation (EU) 2023/2854 (the Data Act) about the jurisdiction of our ICT infrastructure and the measures we take against unlawful access by third-country authorities.

4.1 Where the infrastructure is

  • European Union. Build sandboxes, API nodes and the MongoDB database nodes that hold every Project database, on virtual machines from an infrastructure-as-a-service provider established in the EU. Totalum's own account and platform databases run on the same provider.
  • Cloudflare global edge (established in the United States). Published apps, the marketing website and the platform front end are deployed to Cloudflare Workers and served from the Cloudflare data center nearest each visitor, worldwide. Request logs are processed by Cloudflare under its own regional controls.
  • Google Cloud Storage (Google LLC, United States, with EU-based service entities). Uploaded files, archives, agent logs and screenshots.
  • United States. AI model providers (Anthropic, OpenAI), payment processing (Stripe), transactional email (SendGrid), advertising measurement providers and the other US providers listed above.

Data formats, export procedures and the switching terms that apply to customers in the European Union are described in Section 14 of the Terms of Service and in our documentation.

4.2 Measures against unlawful third-country government access

  • All data is encrypted in transit (TLS) and at rest on our database and storage providers; access to production systems is restricted to named personnel with multi-factor authentication and is logged.
  • Each organization's Project data lives in its own database; internal services authenticate to one another with signed, single-use requests, and no credential is ever sent to the browser.
  • We disclose Customer Project Data to a public authority only when legally compelled by a request that is valid and enforceable against us. We review every request, challenge requests that are overbroad, unlawful or that seek data outside the requesting authority's jurisdiction, and provide the minimum data necessary to comply.
  • Unless legally prohibited, we notify the affected customer before disclosing their data, or as soon as the prohibition is lifted, so that the customer can seek protective remedies.
  • We assess each US-based sub-processor's exposure to government-access laws (a transfer impact assessment) and rely on the Data Privacy Framework or the Standard Contractual Clauses with supplementary measures as appropriate. A summary of the assessment is available to customers on request at contacto@totalum.app.
  • Our Model Providers process prompts and code for the duration of the request and any retention permitted by their commercial terms; they are contractually barred from using them to train models.

5. Notice of changes and how to object

Before we add a new sub-processor of Customer Project Data or change the purpose for which an existing one is used, we will send an email to the address on your Account at least 30 days before the change takes effect and update this page. If you have a reasonable, documented data-protection objection to the new sub-processor, write to contacto@totalum.app before the change takes effect. We will work with you to address the objection; if we cannot, you may terminate the affected Project or your Account without penalty and receive a pro-rata refund of any prepaid subscription period, and the export rights in the Terms apply. Removal of a sub-processor, or a change of a provider's legal entity or address, does not require notice, but we update this page.

Providers in the second list (Account data) may change without individual notice; changes are reflected here and, where material, in the Privacy Policy.

6. Change log

DateChange
September 7, 2026Initial publication of the sub-processor list with the Data Processing Addendum version 2.0.

Related documents

This document can be printed or saved as a PDF from your browser.

© 2026 Totalum, Inc.