Skip to main content

LEGAL

Sub-processors

Last updated:

Version

  • Version: 1.2
  • Notice published: 2026-07-23
  • Earliest intended Plaid use: 2026-08-22, after the contractual 30-day notice period
  • Owner: Kotao GmbH, Cologne, Germany
  • Counsel review: role-classification and transfer-basis wording through v1.1 was legally reviewed and approved on 2026-07-03. The v1.2 Plaid entry is published as advance notice and does not claim a new counsel approval. This page is the operational publication used with the Data Processing Agreement and does not replace legal advice for customer-specific transfer assessments.

Scope

This page lists third-party providers that may process personal data for Kotao when we operate the platform, marketing site, email delivery, payments, observability, analytics, and optional AI features. It consolidates the sub-processor information referenced from the Privacy Policy and Data Processing Agreement.

Sub-processor list

Sub-processor Role Purpose Data categories Processing region Transfer basis
Cloudflare Processor. DNS, CDN, WAF, edge security, image delivery, cache, and traffic routing for public and application surfaces. Network, request, account, security, and public-media data. Global edge network; account and support access may occur from the United States. EU-U.S. Data Privacy Framework (DPF) for certified U.S. transfers and Standard Contractual Clauses (SCC) as required under Cloudflare’s DPA.
Neon Processor. Managed Postgres databases, connection pooling, backups, and database operations for application data. Platform account, customer, commerce, finance, and operational data stored by Kotao. Selected EU database regions for production workloads where configured; support and service operations may involve the United States and vendor subprocessors. Neon DPA/SCC for transfers outside the EEA; DPF/SCC may apply to Neon’s certified downstream U.S. providers where available.
Kotao Payments processors Processor or independent controller according to the applicable payment service. Payment processing, billing, checkout, fraud controls, tax/payment records, and payout-related processing. Payment-method, payer, transaction, fraud, tax, and settlement data. EEA/United Kingdom and the applicable processor network, depending on payment method, merchant, and end-customer location. DPF, SCC, or equivalent transfer controls where required for the applicable processor.
Resend Processor. Transactional and product email delivery, including newsletter double opt-in and operational notifications. Recipient, sender, message, delivery, and suppression data. United States. Resend DPF certification and Resend DPA/SCC.
Amazon SES Sub-processor for email relay. Email relay infrastructure and delivery logs used directly or through email providers. Sender, recipient, message-routing, and delivery-log data. AWS regions selected for service delivery and global email routing; U.S. access may occur for support and operations. AWS DPF certification and AWS GDPR DPA/SCC.
PostHog Processor. Consent-gated product analytics, event funnels, feature usage analysis, and product telemetry. Pseudonymous usage, device, campaign, and consent-state data. PostHog Cloud EU, hosted in Frankfurt, Germany; PostHog subprocessors may process support or service data outside the EEA. EU hosting for primary analytics data; SCC/DPF controls for third-country access by PostHog or its subprocessors where applicable.
Sentry Processor. Error monitoring, release health, stack traces, performance telemetry, and source-map processing. Technical error, release, device, browser, and minimised request data. United States and service locations used by Sentry for its hosted observability platform. Sentry Data Privacy Framework (DPF) and SCC/UK Addendum as set out in Sentry’s DPA.
OpenAI Processor for customer-enabled AI features. Optional AI features, prompt/completion processing, embeddings, and safety/abuse monitoring when AI modules are enabled. Customer-submitted prompts, selected platform context, generated output, and safety metadata. OpenAI Ireland for EEA and Swiss customer data under OpenAI’s DPA; transfers to OpenAI affiliates or third parties outside the EEA may occur to provide the services. OpenAI DPA with SCC or adequacy decision for transfers outside the EEA/Switzerland.
Plaid — planned; not used before 2026-08-22 Processor or sub-processor when acting on Kotao’s instructions; Plaid may separately act as controller for regulated end-user services under its own terms. Optional connection of selected business bank accounts, synchronisation of incoming payments, and invoice reconciliation. Financial institution and country, provider and account identifiers, account name/masked details/type/currency, incoming transaction amounts/dates/references/descriptions/counterparty labels, and connection/consent metadata. International; Plaid states that EEA and UK data may be transferred to the United States and stored in AWS regions in the United States. Plaid’s applicable data terms and approved transfer mechanisms, including SCC where required and adequacy decisions where applicable.

Change notice and objections

Kotao will give at least 30 days prior notice before adding a new sub-processor or making a material change to the purpose, region, or transfer basis of an existing sub-processor. Notice may be sent to the account contact, published on this page, or provided through another contractual notice channel. Customers may object during the 30-day notice period under the Data Processing Agreement.

To subscribe to change notices or raise an objection, contact legal@kotao.com with the subject line Sub-processor notice.

Plaid is currently a planned sub-processor. This v1.2 publication starts the notice period on 2026-07-23. Kotao will not activate Plaid processing for customer production data before 2026-08-22 and before completing the applicable vendor and customer-objection process.

Changelog

  • 2026-07-23 — v1.2: advance notice of the planned Plaid bank-connectivity sub-processor, including role, purpose, data categories, processing region, transfer basis, and earliest intended use on 2026-08-22.
  • 2026-07-03 — v1.1: Counsel review completed and approval documented; review marker removed. No substantive changes to the list.
  • 2026-06-25 — v1.0: Initial publication of named sub-processors, purposes, processing regions, transfer bases, 30-day change-notice procedure, and counsel-review marker.