For consumers in Romania the Romanian version prevails.Versiunea in limba romana

Subprocessors

This page lists every third party that may process personal data on behalf of TRIIVON S.R.L. in connection with GPTpostLLM at https://app.oraglegpt.org. It is published under GDPR art. 28 alin. (2) and (4), and it is the list referred to in Data Processing Addendum.

The list is short, and that is the point. GPTpostLLM is built so that most of what a comparable product outsources is either self-hosted or does not exist at all. Section 6 sets out the categories we have deliberately not engaged, and it is longer than the list of vendors we use.


1. How to read this page

A subprocessor is a third party that processes personal data on our instructions, in order for us to provide the Service to you. It is not the same thing as a company you send data to yourself using our product.

Three distinct categories appear below and confusing them is the usual source of error:

CategoryWho decidesWhere it is listed
Our subprocessorsWe do. They are engaged by us, under our contract, to run the ServiceSection 2
Customer-elected integrationsYou do, with your own credentials, off by defaultSection 4
Destination social platformsYou do, every time you publishSection 5

Only the first category are subprocessors. The other two are third parties you choose, and for those you are the one instructing them.


2. Current subprocessors

VendorRoleWhat it processesLocationTransfer mechanism
Contabo GmbHInfrastructure hosting. Rents us the two physical servers on which everything runsAll data stored or processed by the Service: account records, workspace content, media files, logs and the company mailbox. Contabo does not access it in the ordinary course; it operates the machines and the facilityApplication, database, object storage and media processing on a server in Lauterbourg, France. This legal site and the company mailbox on a server in GermanyNone required. Both locations are inside the EU, so no transfer outside the EEA occurs and no art. 46 mechanism applies
CloudflareAuthoritative DNS for the oraglegpt.org zone, and reverse proxy in front of this siteDNS queries for names in the zone, plus, because this hostname is proxied, the traffic itself: your IP address, the URL requested, your user agent, request timing and the content in transit. Cloudflare terminates TLS for this siteAnycast infrastructure, global. Vendor established in the United States. Our verification request was served from a Paris edgeCloudflare's published data processing addendum incorporates the EU Standard Contractual Clauses, which is the mechanism relied on. See the open point in section 3
Let's Encrypt (Internet Security Research Group)Issues the TLS certificates that protect connections to our hostnames, over the ACME protocolThe domain names being certified and the ACME account key. The ACME account belongs to the company, not to any customer. No customer personal data is disclosed. Issued certificates are published in public Certificate Transparency logs, as all publicly trusted certificates areVendor established in the United StatesNo customer personal data is transferred, so no art. 46 mechanism is engaged for customer data

That is the complete list. There is no fourth entry.


3. What these three actually do, and what they do not see

Contabo GmbH is the only vendor with the theoretical ability to reach customer content, because the content sits on disks in machines it owns. That is true of any hosting arrangement and it is why hosting is the entry that matters most on this page. What reduces it in practice is that there is nothing else in the path: object storage is served from our own server rather than a cloud storage product, media transcoding runs as a local ffmpeg subprocess rather than being sent to a vendor, and the queue is a table in our own database rather than a hosted broker. Data that never leaves the machine cannot be processed by a third party.

Cloudflare provides authoritative DNS for the zone and acts as a reverse proxy in front of this site. We state the second part explicitly because it is the more significant of the two and it is easy to under-describe.

Open point for the operator, disclosed rather than glossed over. Cloudflare publishes a data processing addendum incorporating the EU Standard Contractual Clauses, and that is the mechanism relied on above. Which Cloudflare contracting entity applies to this account, and confirmation that the addendum has been accepted for it, is an administrative matter we are settling. Ask at contact@oraglegpt.org for the current position. We would rather record this as unfinished than imply paperwork we have not verified.

Let's Encrypt issues certificates. It never sees a request to the application, only the ACME exchange that proves we control the domain name.


4. Customer-elected integrations

The application contains optional integrations that a workspace administrator can switch on using that workspace's own credentials. These are not our subprocessors, because we do not engage them, do not hold an account with them for your data, and do not instruct them. When you enable one, you are the party sending your data to a company you have chosen.

IntegrationDefault stateWhose credentials
HubSpotOffThe customer's own
SlackOffThe customer's own
Google Analytics Measurement ProtocolOffThe customer's own
ZendeskOffThe customer's own
ShopifyOffThe customer's own
An AI or large language model providerOffThe customer's own API key, per workspace

Points that follow from this, and that we would rather you read here than infer:


5. Destination social platforms are not subprocessors

When you publish through GPTpostLLM to Facebook, Instagram, Threads, TikTok, Bluesky, Telegram, Discord, WordPress or any other destination, that platform is an independent controller, not our subprocessor.

The reason is not a formality. A subprocessor processes data on our instructions, for our purpose, under our contract. A destination platform does none of those things: it receives content because you told our product to send it, it then processes that content for its own purposes under its own terms with you, and your relationship with it exists independently of us. Your account there is yours, and it survives you deleting your account here.

The narrowness of our connection makes this concrete. Every connector on this deployment is publish-only. The product cannot read comments, mentions, direct messages, replies or any inbox from any platform. It cannot fetch analytics or insights from any platform. It cannot like, repost, edit, delete or moderate anything. It sends your content out and that is the whole of it. One provider connection, Snapchat, performs identity only and publishes nothing.

Only four platforms can be connected here by OAuth: facebook, instagram, threads and tiktok. Four more can be connected with a credential you paste in: bluesky, telegram, discord and wordpress. The rest cannot be connected on this deployment at all.

Analytics deserves a specific note, because it is the place where a reader might assume a platform relationship exists. The only route by which analytics data enters this platform is your own authenticated request to POST /api/v1/analytics/observations. Nothing is fetched, scraped or received from any provider, and the code actively refuses a collection method of provider_api, webhook, scrape or crawl. If a number appears in your analytics, you put it there.

The one exception on the inbound side is not analytics and is not a data feed: we accept Meta's data deletion and deauthorize callbacks for facebook, instagram and threads, verified by signature. Their only effect is to delete data or disconnect an account. No other inbound receiver exists.


6. Categories we have deliberately not engaged

Each line is a statement of fact about this deployment on the date at the top, not an intention.

Because none of these exist, there is no vendor to list for them, no contract to disclose and no transfer to assess.


7. How we choose and control a subprocessor

Before a vendor is engaged we consider whether the function can be self-hosted instead, what personal data it would actually receive, where it processes, whether an art. 28 contract is in place, and what happens to the data when the relationship ends. Every subprocessor in section 2 is bound by written terms imposing confidentiality and security obligations equivalent to ours, as GDPR art. 28 alin. (4) requires.

We remain fully liable to our customers for the performance of a subprocessor's obligations. That is stated as a contract term in Data Processing Addendum section 8.


8. Changes to this list, and how to object

If we intend to add or replace a subprocessor:

  1. This page is updated before the new subprocessor begins processing.
  2. We give at least 30 days notice of the change to business customers who have asked to be notified.
  3. During that period a business customer may object on reasonable data-protection grounds, in writing to contact@oraglegpt.org. We will discuss it and look for an alternative. If no reasonable accommodation is available, you may terminate the affected part of the Service without penalty for the unused remainder of a prepaid term.

To be added to the notification list, write to contact@oraglegpt.org and ask. There is no automatic subscription: the Service sends no email, so notice is sent by a person from the company mailbox to the addresses on that list. We would rather tell you that than offer a subscribe button that nothing implements.

Where a change is required urgently to replace a vendor for security or continuity reasons, we will make the change and tell you as soon as we can rather than wait out the notice period, and we will explain why.


Questions about anything on this page, including a request for the art. 28 terms we hold with a vendor, go to contact@oraglegpt.org. We answer in Romanian or English.