Subprocessors

Last updated: July 30, 2026

This page lists every third party that processes personal data on behalf of Roxy Labs in operating the RoxyAPI service. It forms Annex III to our Data Processing Addendum, and the date above is the date of the most recent change.

Only two subprocessors are ever in the path of an API request, and both are infrastructure providers. Everything in the second table supports the website, email, or abuse handling and never receives an API request or an API response. In particular, no analytics provider and no language model provider ever sees data you submit to the API. Two clarifications on that sentence, because it is the one most worth stating precisely.

Our own website chat assistant is the exception, and it is not on the API path. The assistant can run calculations on behalf of a visitor who asks it to, so the language model provider behind it receives both what that visitor typed and the results computed from it. That involves only people who choose to chat with us on this website. It never touches a customer API request, and it is outside the scope of the Data Processing Addendum.

What you do with results after we return them is your decision, not ours. Many customers deliberately pass our output to a language model, which is the entire point of our remote MCP servers and our open source AI chatbot template. When you do that, you are sending the data to a provider you chose, under your own contract with them. We are not in that chain and cannot see it, so we make no claim about it either way. It is your processing to document.

Tier A: in the API request path

ProviderLegal entityPurposeLocationTransfer basis
HetznerHetzner Online GmbHHosting, database, cacheNuremberg, Germany (EU)No transfer. ISO/IEC 27001:2022 certified
CloudflareCloudflare, Inc.DNS, edge network, web application firewall, bot challenge, traffic measurementUnited States, global edgeData Processing Addendum with EU Standard Contractual Clauses. Active participant in the EU-US Data Privacy Framework. Verified compliant with the EU Cloud Code of Conduct, an approved code of conduct under Article 40 GDPR. Certified to ISO/IEC 27701 and ISO/IEC 27018

Hetzner hosts the servers, so API payloads exist in memory on its infrastructure during computation, and the short-lived response cache and all stored records sit there. This is unavoidable for any hosted API and it is the reason the data stays in Germany.

Cloudflare terminates TLS at the edge, so it processes request and response content in transit. It does not store API responses: every API response is served with no-store directives, so nothing is retained at the edge. We state this rather than describe Cloudflare as seeing only metadata, because the latter would not be accurate.

One consequence worth stating before you ask. TLS is terminated at whichever Cloudflare data centre is closest to the visitor, which for European traffic is normally in Europe but is not contractually guaranteed to be. Cloudflare offers regional inspection controls as a paid add-on and we do not currently have them enabled. So the accurate claim is the one made throughout these pages: data at rest never leaves Germany, and inspection in transit is bounded by the fact that nothing is retained at the edge. If your assessment requires contractually guaranteed EU-only inspection, raise it with us rather than assume either answer.

Tier B: website, email, and abuse handling only

None of the following receives an API request or response.

ProviderLegal entityPurposeLocationData involved
GoogleGoogle Asia Pacific Pte. Ltd.Language model behind the website chat assistantSingapore, United StatesText a visitor types into the on-site chat widget, and the results of any calculation the assistant runs at that visitor request. Never a customer API request or response. Paid tier, so prompts are not used to train or improve models
ResendPlus Five Five, Inc.Transactional email deliveryUnited StatesRecipient email address and message content
GoogleGoogle entity per applicable product termsOptional sign-in with GoogleUnited StatesAccount identity, only if you choose that sign-in method
GitHubGitHub, Inc.Optional sign-in with GitHubUnited StatesAccount identity, only if you choose that sign-in method
AbuseIPDBAbuseIPDB LLCCommunity abuse reportingUnited StatesIP addresses of hosts blocked for probing for vulnerabilities, reported publicly with the request path they probed. Never customer or visitor data

We run no third-party analytics, no session replay, and no advertising pixels. What traffic measurement we have is derived at the edge by Cloudflare, already listed in Tier A, from request metadata it already handles as our network provider. There is no measurement script, cookie, local storage entry, or identifier placed in your browser by us or on our behalf.

The website chat assistant is outside the scope of the Data Processing Addendum, because it answers visitors rather than processing data on the instructions of a customer. If your compliance posture requires that no personal data reach a language model provider, use the API and do not use the chat widget.

Payment providers

Payment providers are not our subprocessors. Each acts as an independent controller, or as merchant of record, for the payment data it collects, and each publishes its own privacy terms. We store no payment instrument data at all: card and wallet details are entered on a page hosted by the provider and never reach our servers, so no card number, expiry, security code, or token exists in our systems, masked or otherwise. The provider handling a given transaction is shown at checkout.

ProviderLegal entityRole
PayPalPayPal entity per its user agreement for your regionIndependent controller, card and wallet payments
Dodo PaymentsDodo Payments entity per its merchant termsMerchant of record, seller of record for the transaction
RazorpayRazorpay Software Private LimitedIndependent controller, payments in Indian rupees

Changes to this list

Before we add or replace a subprocessor that would process personal data submitted through the API, we give every affected customer at least 30 days notice by email to the address on the account. You may object on reasonable data protection grounds within that period, and if we cannot accommodate a reasonable objection you may terminate the affected subscription and receive a pro rata refund of prepaid fees for the unused remainder of the term. The full procedure is section 6 of the Data Processing Addendum.

To be notified of changes, or to ask about a specific provider, use our contact page. Every submission gets a ticket reference, so there is a record of when you asked and when we answered.