Subprocessors
This page lists every third party that may process personal data on behalf of TRIIVON S.R.L. in connection with GPTpostLLM at https://app.oraglegpt.org. It is published under GDPR art. 28 alin. (2) and (4), and it is the list referred to in Data Processing Addendum.
The list is short, and that is the point. GPTpostLLM is built so that most of what a comparable product outsources is either self-hosted or does not exist at all. Section 6 sets out the categories we have deliberately not engaged, and it is longer than the list of vendors we use.
1. How to read this page
A subprocessor is a third party that processes personal data on our instructions, in order for us to provide the Service to you. It is not the same thing as a company you send data to yourself using our product.
Three distinct categories appear below and confusing them is the usual source of error:
| Category | Who decides | Where it is listed |
|---|---|---|
| Our subprocessors | We do. They are engaged by us, under our contract, to run the Service | Section 2 |
| Customer-elected integrations | You do, with your own credentials, off by default | Section 4 |
| Destination social platforms | You do, every time you publish | Section 5 |
Only the first category are subprocessors. The other two are third parties you choose, and for those you are the one instructing them.
2. Current subprocessors
| Vendor | Role | What it processes | Location | Transfer mechanism |
|---|---|---|---|---|
| Contabo GmbH | Infrastructure hosting. Rents us the two physical servers on which everything runs | All data stored or processed by the Service: account records, workspace content, media files, logs and the company mailbox. Contabo does not access it in the ordinary course; it operates the machines and the facility | Application, database, object storage and media processing on a server in Lauterbourg, France. This legal site and the company mailbox on a server in Germany | None required. Both locations are inside the EU, so no transfer outside the EEA occurs and no art. 46 mechanism applies |
| Cloudflare | Authoritative DNS for the oraglegpt.org zone, and reverse proxy in front of this site | DNS queries for names in the zone, plus, because this hostname is proxied, the traffic itself: your IP address, the URL requested, your user agent, request timing and the content in transit. Cloudflare terminates TLS for this site | Anycast infrastructure, global. Vendor established in the United States. Our verification request was served from a Paris edge | Cloudflare's published data processing addendum incorporates the EU Standard Contractual Clauses, which is the mechanism relied on. See the open point in section 3 |
| Let's Encrypt (Internet Security Research Group) | Issues the TLS certificates that protect connections to our hostnames, over the ACME protocol | The domain names being certified and the ACME account key. The ACME account belongs to the company, not to any customer. No customer personal data is disclosed. Issued certificates are published in public Certificate Transparency logs, as all publicly trusted certificates are | Vendor established in the United States | No customer personal data is transferred, so no art. 46 mechanism is engaged for customer data |
That is the complete list. There is no fourth entry.
3. What these three actually do, and what they do not see
Contabo GmbH is the only vendor with the theoretical ability to reach customer content, because the content sits on disks in machines it owns. That is true of any hosting arrangement and it is why hosting is the entry that matters most on this page. What reduces it in practice is that there is nothing else in the path: object storage is served from our own server rather than a cloud storage product, media transcoding runs as a local ffmpeg subprocess rather than being sent to a vendor, and the queue is a table in our own database rather than a hosted broker. Data that never leaves the machine cannot be processed by a third party.
Cloudflare provides authoritative DNS for the zone and acts as a reverse proxy in front of this site. We state the second part explicitly because it is the more significant of the two and it is easy to under-describe.
- Answering DNS for a zone means Cloudflare learns that some resolver asked for a name. That alone would not mean Cloudflare sees your requests.
- This hostname is proxied. Verified on 2026-08-09:
https://gptpostllm.oraglegpt.orgresolves to Cloudflare addresses and responses carry Cloudflare'sserverandcf-rayheaders. In practice this means Cloudflare terminates TLS for this site and processes connection metadata and request content in transit, including your IP address, the URL you requested, your user agent and the timing of the request. The edge that served our own verification request was in Paris. - Cloudflare is therefore a genuine subprocessor for traffic to this site, not merely a DNS host, and it is listed as one in the table above.
Open point for the operator, disclosed rather than glossed over. Cloudflare publishes a data processing addendum incorporating the EU Standard Contractual Clauses, and that is the mechanism relied on above. Which Cloudflare contracting entity applies to this account, and confirmation that the addendum has been accepted for it, is an administrative matter we are settling. Ask at contact@oraglegpt.org for the current position. We would rather record this as unfinished than imply paperwork we have not verified.
Let's Encrypt issues certificates. It never sees a request to the application, only the ACME exchange that proves we control the domain name.
4. Customer-elected integrations
The application contains optional integrations that a workspace administrator can switch on using that workspace's own credentials. These are not our subprocessors, because we do not engage them, do not hold an account with them for your data, and do not instruct them. When you enable one, you are the party sending your data to a company you have chosen.
| Integration | Default state | Whose credentials |
|---|---|---|
| HubSpot | Off | The customer's own |
| Slack | Off | The customer's own |
| Google Analytics Measurement Protocol | Off | The customer's own |
| Zendesk | Off | The customer's own |
| Shopify | Off | The customer's own |
| An AI or large language model provider | Off | The customer's own API key, per workspace |
Points that follow from this, and that we would rather you read here than infer:
- None of them is enabled by default on this deployment. If nobody in your workspace has turned one on and supplied a key, no data goes to any of them.
- No AI provider is configured on this deployment by the company. The AI integration is bring-your-own-key per workspace. Prompt content leaves for a model provider only if your own administrator enabled it with your own key. Embeddings are computed locally and deterministically and are never sent out.
- If the company you choose is outside the EEA, you are the party making that transfer decision and the responsibility for a lawful transfer mechanism sits with you. Data Processing Addendum section 12 says the same thing in contract terms.
- The credentials you paste in are stored encrypted at the field level, as described in Security section 4.
5. Destination social platforms are not subprocessors
When you publish through GPTpostLLM to Facebook, Instagram, Threads, TikTok, Bluesky, Telegram, Discord, WordPress or any other destination, that platform is an independent controller, not our subprocessor.
The reason is not a formality. A subprocessor processes data on our instructions, for our purpose, under our contract. A destination platform does none of those things: it receives content because you told our product to send it, it then processes that content for its own purposes under its own terms with you, and your relationship with it exists independently of us. Your account there is yours, and it survives you deleting your account here.
The narrowness of our connection makes this concrete. Every connector on this deployment is publish-only. The product cannot read comments, mentions, direct messages, replies or any inbox from any platform. It cannot fetch analytics or insights from any platform. It cannot like, repost, edit, delete or moderate anything. It sends your content out and that is the whole of it. One provider connection, Snapchat, performs identity only and publishes nothing.
Only four platforms can be connected here by OAuth: facebook, instagram, threads and tiktok. Four more can be connected with a credential you paste in: bluesky, telegram, discord and wordpress. The rest cannot be connected on this deployment at all.
Analytics deserves a specific note, because it is the place where a reader might assume a platform relationship exists. The only route by which analytics data enters this platform is your own authenticated request to POST /api/v1/analytics/observations. Nothing is fetched, scraped or received from any provider, and the code actively refuses a collection method of provider_api, webhook, scrape or crawl. If a number appears in your analytics, you put it there.
The one exception on the inbound side is not analytics and is not a data feed: we accept Meta's data deletion and deauthorize callbacks for facebook, instagram and threads, verified by signature. Their only effect is to delete data or disconnect an account. No other inbound receiver exists.
6. Categories we have deliberately not engaged
Each line is a statement of fact about this deployment on the date at the top, not an intention.
- No third-party email vendor. The company mailbox is self-hosted postfix and dovecot on our own server in Germany. There is no sending platform, no transactional email service and no newsletter tool. The Service itself sends no email at all.
- No payment processor. No card data, no stored payment instrument, no tokenisation vendor. Billing is an internal entitlement ledger.
- No third-party object storage. The S3-protocol endpoint on this deployment is
https://media.oraglegpt.org, which resolves to our own application server. It is self-hosted. - No CDN holding customer data. No third party caches or stores your media on our behalf.
- No transcoding or media processing vendor.
ffmpegruns locally on the same host. - No web analytics vendor. No Google Analytics, no Plausible, no Matomo, no product analytics SDK, no session replay. See Cookie and Local Storage Policy.
- No advertising network, adtech, retargeting or tag manager.
- No error tracking or crash reporting vendor. No Sentry or equivalent.
- No customer data platform and no CRM vendor holding your data on our behalf.
- No data broker, enrichment, lead scoring or identity resolution vendor. We buy no data about anyone and we sell none.
- No AI or model provider by default. See section 4.
- No offshore support or outsourced service desk. Support is answered by the company. See Support.
- No Redis, message broker or other hosted middleware holding your data in transit between components.
Because none of these exist, there is no vendor to list for them, no contract to disclose and no transfer to assess.
7. How we choose and control a subprocessor
Before a vendor is engaged we consider whether the function can be self-hosted instead, what personal data it would actually receive, where it processes, whether an art. 28 contract is in place, and what happens to the data when the relationship ends. Every subprocessor in section 2 is bound by written terms imposing confidentiality and security obligations equivalent to ours, as GDPR art. 28 alin. (4) requires.
We remain fully liable to our customers for the performance of a subprocessor's obligations. That is stated as a contract term in Data Processing Addendum section 8.
8. Changes to this list, and how to object
If we intend to add or replace a subprocessor:
- This page is updated before the new subprocessor begins processing.
- We give at least 30 days notice of the change to business customers who have asked to be notified.
- During that period a business customer may object on reasonable data-protection grounds, in writing to contact@oraglegpt.org. We will discuss it and look for an alternative. If no reasonable accommodation is available, you may terminate the affected part of the Service without penalty for the unused remainder of a prepaid term.
To be added to the notification list, write to contact@oraglegpt.org and ask. There is no automatic subscription: the Service sends no email, so notice is sent by a person from the company mailbox to the addresses on that list. We would rather tell you that than offer a subscribe button that nothing implements.
Where a change is required urgently to replace a vendor for security or continuity reasons, we will make the change and tell you as soon as we can rather than wait out the notice period, and we will explain why.
9. Contact and related pages
Questions about anything on this page, including a request for the art. 28 terms we hold with a vendor, go to contact@oraglegpt.org. We answer in Romanian or English.
- Data Processing Addendum is the processing agreement these terms sit under.
- Privacy Policy explains what personal data we process and on what basis.
- Security describes the technical controls, including their limits.
- Your Data Protection Rights explains how to exercise your rights.
- Company Identification identifies the company.