Sub-processors
Last updated: April 14, 2026
ChatSEO, operated by GROW IT, uses the following sub-processors to deliver its services. This page is maintained as a living document and updated whenever sub-processors are added, removed, or changed.
To be notified of changes to this list, enterprise customers with a Data Processing Agreement can subscribe to notifications by emailing [email protected].
Infrastructure & Hosting
| Sub-processor | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Hetzner Online GmbH | Server hosting | All service data | Germany (EU) | N/A (EU) |
AI & Machine Learning
| Sub-processor | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Anthropic | AI-powered SEO analysis (Claude Sonnet 4, Claude Haiku) | Conversation content, SEO data (transient, real-time inference only) | United States | EU-US DPF + SCCs |
| Voyage AI | Vector embeddings for cross-conversation memory | Text content for embedding generation | United States | SCCs |
Important: Under Anthropic's commercial API terms of service, data submitted via the API is not used for model training. Voyage AI processes data for embedding generation only with no retention. ChatSEO does not use any user data to train, fine-tune, or improve AI models.
Payment & Billing
| Sub-processor | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Stripe, Inc. | Payment processing | Billing details, payment information, subscription data | United States | EU-US DPF + SCCs (PCI-DSS compliant) |
Communication
| Sub-processor | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Resend | Transactional email delivery | Email address, name | United States | SCCs |
| Crisp IM SAS | Customer support chat | Name, email, chat conversations | France (EU) | N/A (EU) |
Analytics & Monitoring
| Sub-processor | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Mixpanel, Inc. | Product analytics | Usage events, email, name | United States (EU endpoint) | EU-US DPF + SCCs |
| Customer.io (Peaberry Software Inc.) | Marketing automation | Email, name, usage events | United States (EU endpoint) | EU-US DPF + SCCs |
| Sentry (Functional Software Inc.) | Error monitoring | Technical errors, IP address, browser info | United States | EU-US DPF + SCCs |
Note: Mixpanel and Customer.io only receive data after explicit user consent via our cookie banner (analytics category). They do not initialize without consent.
SEO Data Providers
| Sub-processor | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Google APIs (Google LLC) | OAuth authentication + Search Console API | OAuth tokens, GSC data (transient, never stored) | United States | EU-US DPF + SCCs |
| DataForSEO | SEO data (keyword research, SERP analysis, backlinks) | Public domain/URL data | United States | SCCs |
| Firecrawl | Web page content scraping | Public URLs, publicly accessible page content | Self-hosted (EU - Hetzner) | N/A (self-hosted, EU) |
Marketing & Attribution
| Sub-processor | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Tolt, Inc. | Affiliate tracking | Referral attribution data | United States | SCCs |
| Meta Platforms, Inc. | Marketing analytics (Facebook Pixel) | Page views, conversion events | United States | EU-US DPF + SCCs |
Note: Tolt and Meta Pixel only receive data after explicit user consent via our cookie banner (marketing category). They do not load without consent.
Feature Management
| Sub-processor | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Flagsmith | Feature flag management | User identifier | EU | N/A (EU) |
Important Notes
Consent-gated services
The following sub-processors only receive data after the user has given explicit consent via our cookie banner:
- Analytics (opt-in required): Mixpanel, Customer.io
- Marketing (opt-in required): Tolt, Meta Pixel
Without consent, these services do not initialize and receive no data.
Google Search Console data handling
Google Search Console data (queries, impressions, clicks, rankings, page performance) is fetched via the Google Search Console API in real-time using the read-only OAuth scope (webmasters.readonly). This data is returned directly to the user and is never stored in our database, cached in Redis, or persisted in any form. Only OAuth credentials (access token, refresh token) are stored to authenticate API requests on the user's behalf.
AI data handling
Anthropic and Voyage AI process data in real-time for inference and embedding generation respectively. Under their respective commercial API terms of service, data submitted via the API is not used for model training. No user data is retained by these providers beyond the duration of the API request.
Change Log
| Date | Change |
|---|---|
| April 14, 2026 | Initial publication |