Sub-processors
Last updated: 2 August 2026
This page lists (1) subprocessors engaged by Tellagen to provide the core service and (2) customer-directed integrations that may receive personal data when enabled by a Customer.
1. Tellagen-appointed subprocessors
Hetzner Online GmbH
- Purpose
- Core hosting and infrastructure
- Data categories
- Customer Data, account data, operational metadata
- Primary region
- Germany (EU)
- Transfer safeguards
- EU-hosted
Resend Inc.
- Purpose
- Transactional email delivery
- Data categories
- Email addresses, message metadata, email content
- Primary region
- United States
- Transfer safeguards
- SCCs and/or other lawful safeguards
Cloudflare, Inc. (Turnstile)
- Purpose
- Bot and abuse protection
- Data categories
- Verification token, IP, request metadata
- Primary region
- Global
- Transfer safeguards
- SCCs and/or other lawful safeguards
PostHog EU Cloud
- Purpose
- Optional website and product analytics with consented session replay
- Data categories
- Pseudonymous identifiers, sanitized page paths, device/browser metadata, bounded interaction events, and masked session replay data
- Primary region
- Germany (European Union)
- Transfer safeguards
- EU-hosted
OpenAI, LLC (optional)
- Purpose
- AI processing when OpenAI provider is enabled
- Data categories
- AI prompt/response content chosen by Customer users
- Primary region
- United States
- Transfer safeguards
- SCCs and/or other lawful safeguards
Google LLC (Gemini optional)
- Purpose
- AI processing when Gemini provider is enabled
- Data categories
- AI prompt/response content chosen by Customer users
- Primary region
- United States
- Transfer safeguards
- SCCs and/or other lawful safeguards
| Provider | Purpose | Data categories | Primary region | Transfer safeguards |
|---|---|---|---|---|
| Hetzner Online GmbH | Core hosting and infrastructure | Customer Data, account data, operational metadata | Germany (EU) | EU-hosted |
| Resend Inc. | Transactional email delivery | Email addresses, message metadata, email content | United States | SCCs and/or other lawful safeguards |
| Cloudflare, Inc. (Turnstile) | Bot and abuse protection | Verification token, IP, request metadata | Global | SCCs and/or other lawful safeguards |
| PostHog EU Cloud | Optional website and product analytics with consented session replay | Pseudonymous identifiers, sanitized page paths, device/browser metadata, bounded interaction events, and masked session replay data | Germany (European Union) | EU-hosted |
| OpenAI, LLC (optional) | AI processing when OpenAI provider is enabled | AI prompt/response content chosen by Customer users | United States | SCCs and/or other lawful safeguards |
| Google LLC (Gemini optional) | AI processing when Gemini provider is enabled | AI prompt/response content chosen by Customer users | United States | SCCs and/or other lawful safeguards |
Website and product analytics use Umami and PostHog only after analytics consent is granted. PostHog processing uses its European Union cloud region.
2. Customer-directed integrations
The following services are activated only when configured by the Customer. In these cases, the Customer controls whether data is sent and under what legal basis.
Slack
- Purpose
- Incident channels and response messaging
- Typical data shared
- User profile and incident communication data
Google Meet
- Purpose
- Incident meeting creation and coordination
- Typical data shared
- Meeting metadata and OAuth-linked account data
Intercom
- Purpose
- Link customer conversations to incidents
- Typical data shared
- Conversation content and contact metadata
PagerDuty / Opsgenie / Rootly
- Purpose
- Alert context and escalation links
- Typical data shared
- Alert and responder metadata
Stripe / Recurly
- Purpose
- Billing-related customer enrichment features
- Typical data shared
- Customer/account metadata queried by Customer config
Customer resolver endpoint
- Purpose
- Customer-owned enrichment API integration
- Typical data shared
- Data fields configured by the Customer
| Service | Purpose | Typical data shared |
|---|---|---|
| Slack | Incident channels and response messaging | User profile and incident communication data |
| Google Meet | Incident meeting creation and coordination | Meeting metadata and OAuth-linked account data |
| Intercom | Link customer conversations to incidents | Conversation content and contact metadata |
| PagerDuty / Opsgenie / Rootly | Alert context and escalation links | Alert and responder metadata |
| Stripe / Recurly | Billing-related customer enrichment features | Customer/account metadata queried by Customer config |
| Customer resolver endpoint | Customer-owned enrichment API integration | Data fields configured by the Customer |
3. Change management
We will update this list before new Tellagen-appointed subprocessors begin processing personal data and provide Customer notice as required by our DPA.