# Kaabist Sub-processors

*Last updated 10 October 2026. Changes are announced at least 30 days in advance, as the
[Data Processing Agreement](dpa.md) describes.*

Everything else runs on infrastructure Kaabist operates itself: the database, object storage, the
browsers, the queue, key management, logs and error tracking. The services below are used only as
described. Providers a customer connects itself (bring-your-own proxies, language models and
CAPTCHA solvers) are the customer's own processors, not Kaabist's sub-processors.

| Sub-processor | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Hetzner | Servers that run the whole platform (compute, storage, backups) | All Customer Data and account data | Germany (Falkenstein, Nuremberg) | Within the EU; from Türkiye: KVKK standard contract (Art. 9) |
| Cloudflare | DNS and the proxy in front of public endpoints (panel, API, docs, live view) | Traffic in transit: IP addresses, request metadata, TLS-terminated requests | Global edge network | KVKK standard contract (Art. 9); EU Standard Contractual Clauses and the EU-US Data Privacy Framework |
| Paddle | Merchant of record: checkout, subscriptions, invoices, tax | Billing contact, payment details (entered at Paddle), purchase history | United Kingdom | KVKK standard contract (Art. 9); EU adequacy decision for the United Kingdom |
| Brevo | Relays the e-mail Kaabist's own mail server sends: sign-in links, invitations, billing and security notices, export links, deletion confirmations | E-mail address, name, message content | France (EU) | Within the EU; from Türkiye: KVKK standard contract (Art. 9) |
| Proxy providers: Bright Data, Oxylabs, Decodo, IPRoyal, Webshare | Exit IP addresses for job traffic, **only when a job uses the platform's proxies** | Target URLs and the traffic of the job (encrypted end to end for HTTPS targets) | Global | KVKK standard contract (Art. 9) and EU Standard Contractual Clauses, with each vendor |
| Language-model providers: OpenAI, Anthropic, Google (Gemini) | Classifying unrecognised pages and suggesting locators while healing, **only when the organisation has switched the platform's model on** (`llm_enabled`) | Excerpts of the page being processed (at most 40 KB), never session state or secrets | United States | KVKK standard contract (Art. 9); EU Standard Contractual Clauses and the EU-US Data Privacy Framework |
| CAPTCHA solvers: 2Captcha, CapSolver | Solving a CAPTCHA a job meets, **only when the platform's solver key is used** | The CAPTCHA's site key, page URL and challenge | Outside the EU and Türkiye | KVKK standard contract (Art. 9) and EU Standard Contractual Clauses |

Source code and continuous integration are hosted by GitHub; it holds no Customer Data.

Questions: privacy@kaab.ist.
