Subprocessors

Effective: February 7, 2026 | Last updated: 2/11/2026

1. Our Technology Partners

Faultrix uses best-in-class infrastructure providers, each selected for security, reliability, and GDPR compliance.

2. Subprocessors

This table is the official overview of third-party vendors that may process personal data to deliver the Faultrix services.

ProviderRolePurposeData categoriesRegion / processing locationTransfer mechanism (if third-country)Optional?LinksLast reviewed
ClerkSubprocessorAuthentication and session management
  • Account data
  • Session tokens
  • Login metadata
USASCCs (EU 2021/914), where requiredNo2/11/2026
ConvexSubprocessorApplication database and backend operations
  • Account records
  • Analysis metadata
  • Technical usage data
USASCCs (EU 2021/914), where requiredNo2/11/2026
Cloudflare R2SubprocessorFile storage for uploaded photos and exports
  • Photos
  • EXIF metadata (where available)
  • Object metadata (e.g., hash, upload timestamp)
Cloudflare (region konfigurierbar)Depends on configuration; SCCs (EU 2021/914) where requiredNo2/11/2026
VercelSubprocessorHosting, delivery, and operational monitoring
  • Request metadata
  • Technical logs
WeltweitSCCs (EU 2021/914), where requiredNo2/11/2026
StripeProcessorPayment processing and fraud prevention
  • Transaction data
  • Payment status
  • Billing metadata
USASCCs (EU 2021/914), where requiredYes2/11/2026
Open BigModel (GLM)SubprocessorAI analysis of uploaded image content (primary model provider)
  • Image content
  • Analysis prompts and context data
ChinaSCCs (EU 2021/914), where requiredNo2/11/2026
OpenAI (Fallback)SubprocessorFallback AI processing if GLM is unavailable
  • Image content
  • Analysis prompts and context data
USASCCs (EU 2021/914), where requiredYes2/11/2026
Google Maps PlatformSubprocessorMap display, address autocomplete, and location verification (optional)
  • GPS coordinates
  • Address/map requests
  • Technical usage data
WeltweitSCCs (EU 2021/914), where requiredYes2/11/2026
PostHog (Analytics)SubprocessorWebsite/product analytics (consent-based)
  • Pseudonymous user IDs
  • Events and properties
  • Usage metadata
EU (Server verfuegbar) / WeltweitDepends on configuration; SCCs (EU 2021/914) where requiredYes2/11/2026
Sentry (Error Tracking)SubprocessorError reporting and diagnostics (consent-based)
  • Error events
  • Stack traces
  • Session diagnostics (on errors only, if enabled)
USASCCs (EU 2021/914), where requiredYes2/11/2026

3. Notes & Definitions

  • Subprocessors are third-party vendors we engage to process personal data on our behalf to deliver the services.
  • The Role column (Processor/Subprocessor) is provided for transparency and may vary by processing context and contract type.
  • Data categories are limited to what is necessary and may vary by feature and consent (e.g., analytics).
  • If processing occurs outside the EU/EEA, we use appropriate safeguards (e.g., SCCs) where required.
  • Changes to subprocessors are documented by updating this page and its change log.

4. Change Log

  • 2/7/2026: Initial publication of the vendors/subprocessors documentation.
  • 2/11/2026: Expanded the subprocessors table with enterprise fields (role, data categories, transfer mechanism, links, review date).
  • 2/11/2026: Harmonized vendor list and purposes with Security/Privacy/Cookies references.

5. Data Processing Agreements

  • We use data processing agreements (DPAs) under GDPR Article 28 where required.
  • Transfers outside the EU/EEA use appropriate safeguards (e.g., SCCs) where required.
  • DPA information is available upon request.

6. Vendor Selection Criteria

  • Security certifications (SOC 2, ISO 27001, or equivalent).
  • GDPR compliance and DPA availability.
  • Data residency options.
  • Incident response SLA.
  • Financial stability and market position.

7. Exit Strategy

  • Auth: Clerk can be migrated to Auth0, Firebase Auth, or a self-hosted stack.
  • Database: Convex supports data export and migration paths to PostgreSQL.
  • Storage: R2 is S3-compatible and can migrate to any S3 provider.
  • AI: The Faultrix Engine runs in a provider-agnostic pipeline and backend providers can be switched.
  • Payments: Stripe can migrate to other PSP providers.
  • Data export: Full data export available within 30 days of request.
  • No vendor lock-in by design.

8. Vendor Risk Monitoring

  • Annual vendor security review.
  • Continuous uptime monitoring.
  • Incident notification within 24 hours.
  • Last review date: February 2026.