Subprocessors

Last updated: August 3, 2026

This page lists every third party that processes personal data on behalf of Roxy Labs in operating the RoxyAPI service. It forms Annex III to our Data Processing Addendum, and the date above is the date of the most recent change.

Only two subprocessors are ever in the path of an API request, and both are infrastructure providers. Everything in the second table supports the website, email, or abuse handling and never receives an API request or an API response. In particular, no analytics provider and no language model provider ever sees data you submit to the API. Two clarifications on that sentence, because it is the one most worth stating precisely.

Our own website chat assistant is the exception, and it is not on the API path. The assistant can run calculations on behalf of a visitor who asks it to, so the language model provider behind it receives both what that visitor typed and the results computed from it. That involves only people who choose to chat with us on this website. It never touches a customer API request, and it is outside the scope of the Data Processing Addendum.

What you do with results after we return them is your decision, not ours. Many customers deliberately pass our output to a language model, which is the entire point of our remote MCP servers and our open source AI chatbot template. When you do that, you are sending the data to a provider you chose, under your own contract with them. We are not in that chain and cannot see it, so we make no claim about it either way. It is your processing to document.

Tier A: in the API request path

ProviderLegal entityPurposeLocationTransfer basis
HetznerHetzner Online GmbHHosting, database, cacheNuremberg, Germany (EU)No transfer. ISO/IEC 27001:2022 certified
CloudflareCloudflare, Inc.DNS, edge network, web application firewall, bot challenge, traffic measurementUnited States, global edgeData Processing Addendum with EU Standard Contractual Clauses. Active participant in the EU-US Data Privacy Framework. Verified compliant with the EU Cloud Code of Conduct, an approved code of conduct under Article 40 GDPR. Certified to ISO/IEC 27701 and ISO/IEC 27018

Hetzner hosts the servers, so API payloads exist in memory on its infrastructure during computation, and the short-lived response cache and all stored records sit there. This is unavoidable for any hosted API and it is the reason the data stays in Germany.

Cloudflare terminates TLS at the edge, so it processes request and response content in transit. It does not store API responses: every API response is served with no-store directives, so nothing is retained at the edge. Cloudflare sees content in transit, not only metadata.

One consequence follows. TLS is terminated at whichever Cloudflare data centre is closest to the visitor, which for European traffic is normally in Europe but is not contractually guaranteed to be. Cloudflare offers regional inspection controls as a paid add-on and we do not currently have them enabled. So the accurate claim is the one made throughout these pages: data at rest never leaves Germany, and inspection in transit is bounded by the fact that nothing is retained at the edge. If your assessment requires contractually guaranteed EU-only inspection, raise it with us rather than assume either answer.

Tier B: website, email, and abuse handling only

None of the following receives an API request or response.

ProviderLegal entityPurposeLocationData involved
GoogleGoogle Asia Pacific Pte. Ltd.Language model behind the website chat assistantSingapore, United StatesText a visitor types into the on-site chat widget, and the results of any calculation the assistant runs at that visitor request. Never a customer API request or response. Paid tier, so prompts are not used to train or improve models
ResendPlus Five Five, Inc.Transactional email deliveryUnited StatesRecipient email address and message content
GoogleGoogle entity per applicable product termsOptional sign-in with GoogleUnited StatesAccount identity, only if you choose that sign-in method
GitHubGitHub, Inc.Optional sign-in with GitHubUnited StatesAccount identity, only if you choose that sign-in method
AbuseIPDBAbuseIPDB LLCCommunity abuse reportingUnited StatesIP addresses of hosts blocked for probing for vulnerabilities, reported publicly with the request path they probed. Never customer or visitor data

We run no third-party analytics, no session replay, and no advertising pixels. What traffic measurement we have is derived at the edge by Cloudflare, already listed in Tier A, from request metadata it already handles as our network provider. There is no measurement script, cookie, local storage entry, or identifier placed in your browser by us or on our behalf.

The website chat assistant is outside the scope of the Data Processing Addendum, because it answers visitors rather than processing data on the instructions of a customer. If your compliance posture requires that no personal data reach a language model provider, use the API and do not use the chat widget.

Widget and embed delivery (only if you embed a widget)

This section applies to one optional feature and to nobody else. If you use the API directly, through an SDK, or through Remote MCP, nothing here is in your path and you can skip it.

Our copy-paste widgets and the hosted /embed pages render a browser component that is delivered by jsDelivr, a public open-source content delivery network operated by Volentio JSD Limited, a company registered in England and Wales. When a visitor loads a page carrying one of our widgets, that visitor's browser requests the component file directly from jsDelivr, so jsDelivr receives the visitor's IP address, browser type and version, and the referring domain. jsDelivr states that it sets no cookies, does not store location data, and never associates the data it gathers with a specific user. It publishes its own privacy policy and data processing agreement.

What it never receives. jsDelivr serves a static component file and is never in the path of an API request or response. It sees no birth data, no request body, no computed result, and no API key. The two-tier list above is unchanged by this: only hosting and the edge network ever touch an API payload.

How to avoid it entirely. The component is published on npm, so you can install it and serve it from your own domain instead, and no request reaches jsDelivr. The one delivery mode where that choice is ours rather than yours is the hosted /embed URL, because we serve that page. If your assessment does not permit a third-party content delivery network in your visitors' path, self-host the component or use the API directly and render the result yourself.

Where you embed a widget on your own site, you are the controller for the page your visitors load and for the disclosure your own privacy notice makes about it.

Payment providers

Payment providers are not our subprocessors. Each acts as an independent controller, or as merchant of record, for the payment data it collects, and each publishes its own privacy terms. We store no payment instrument data at all: card and wallet details are entered on a page hosted by the provider and never reach our servers, so no card number, expiry, security code, or token exists in our systems, masked or otherwise. The provider handling a given transaction is shown at checkout.

ProviderLegal entityRole
PayPalPayPal entity per its user agreement for your regionIndependent controller, card and wallet payments
Dodo PaymentsDodo Payments entity per its merchant termsMerchant of record, seller of record for the transaction
RazorpayRazorpay Software Private LimitedIndependent controller, payments in Indian rupees

Changes to this list

Before we add or replace a subprocessor that would process personal data submitted through the API, we give every affected customer at least 30 days notice by email to the address on the account. You may object on reasonable data protection grounds within that period, and if we cannot accommodate a reasonable objection you may terminate the affected subscription and receive a pro rata refund of prepaid fees for the unused remainder of the term. The full procedure is section 6 of the Data Processing Addendum.

To be notified of changes, or to ask about a specific provider, use our contact page. Every submission gets a ticket reference, so there is a record of when you asked and when we answered.