01Actual roles
A hosting, backup, email, support or model provider handling entrusted personal data can be a subprocessor. An independent payment provider or registrar may be a controller for its own legal purposes. Customer-selected integrations may involve the customer’s own supplier. A software library or a supported adapter is not itself evidence of an active recipient.
02Service-specific register
The applicable order/DPA must identify each authorised legal entity, service and purpose, data categories, processing and remote-access countries, backup locations and transfer safeguards. Request the register applicable to your contracted deployment from hello@huberway.com. This page describes the authorisation framework; it is not an executed supplier list or a statement that every integration is authorised.
03Changes and international safeguards
Subprocessor changes follow the specific/general written authorisation in the DPA, advance notice and a reasonable objection route before disputed processing. Huberway remains responsible for its contracted subprocessor obligations. Restricted transfers require their actual mechanism and completed annexes; neither a US address nor use of standard cloud technology establishes adequacy, certification or signed transfer clauses.
04Named providers
OVHcloud — hosting/infrastructure supplier; Stripe — payment services where enabled; OpenAI — model services for enabled AI requests. The provider brands identify confirmed suppliers, not every contracting legal entity, region or product entitlement. The relevant order and provider account determine the actual entity and configuration.
For supplier disclosures see https://www.ovhcloud.com/en/terms-and-conditions/, https://stripe.com/legal/privacy-center and https://openai.com/policies/data-processing-addendum/. These public provider documents do not themselves prove Huberway’s signed agreement, selected processing region, backup location or special retention setting. A customer-selected integration is assessed separately.