Skip to content
autopageBeta
  • how it works
  • the loop
  • pricing
  • questions
  • start free

Operated by Finalform GmbH

EU company · GDPR

Sub-processors

Last updated: 2026-06-25

Effective / last updated: 2026-06-25. List version: 2.0

This list is published by Finalform GmbH, Theodor-Heuss-Str. 106, 26129 Oldenburg, Germany (“Finalform”, “we”, “us”), the operator of Autopage.

1. Purpose and authorization basis

This list names the third parties (the “Sub-processors”) that Finalform engages to process personal data on behalf of its customers when providing Autopage. For visitor data processed through the Autopage snippet, Finalform acts as the processor and the Customer is the controller.

This list operates under, and forms part of, the general written authorization that the Customer grants in the Data Processing Agreement (Article 28(2) GDPR). By entering into the Data Processing Agreement, the Customer authorizes Finalform to engage the Sub-processors named below. The Data Processing Agreement governs the notice and objection mechanism that applies before Finalform adds or replaces a Sub-processor (see Section 5).

Each row below states the Sub-processor’s identity, role, the personal-data categories it receives, its processing location, and the transfer mechanism, so that the Customer can assess each Sub-processor and exercise the objection right.

The categories of personal data processed by each Sub-processor are also described in the Privacy Policy and the Data Processing Agreement. This list, the Privacy Policy, and the Data Processing Agreement name the same Sub-processors. Recipients that are not Article 28 Sub-processors (such as our external accounting provider / Steuerberater for the statutory billing hold) are addressed separately, not in this Sub-processor table.

2. Sub-processors

Exactly five Sub-processors are authorized. Four receive data today; Stripe begins processing personal data only when paid billing goes live. Railway provides both application hosting and the managed database under a single contracting entity and is shown as one row with both services named.

Sub-processor (legal entity) Service / role Personal data received Hosting region Transfer mechanism
Railway Corporation, Delaware, US Application hosting and compute (engine API and web dashboard) and managed PostgreSQL primary database All processed and persisted personal data: pseudonymous visitor session identifier and behavioral events, customer account data, billing metadata. The raw visitor IP address transits the Railway edge and proxy layer and may appear in provider access logs (infrastructure layer); no Autopage application code stores it. United States by default; EU data residency can be set per service in the Railway dashboard. US recipient → EU-US Data Privacy Framework (DPF) adequacy if Railway is certified, otherwise Article 46 Standard Contractual Clauses (SCCs) plus a transfer impact assessment (TIA).
Anthropic, PBC, Delaware, US Large language model that generates and rewrites landing-page copy No per-visitor personal data. Only the customer’s optimization brief, baseline page copy, and population-level aggregate metrics (rates and medians) are sent. Direct identifiers are stripped; no session identifier, IP address, or raw visitor event reaches a prompt. No prompt or response content is logged by Finalform (only token-count telemetry). United States (api.anthropic.com, no region override) US recipient → DPF adequacy if certified, otherwise SCCs plus TIA. A no-training / zero-retention tier is contractually enabled.
Cloudflare, Inc., Delaware, US Browser Rendering API that renders the customer’s single-page-application landing page during the baseline scrape Only the customer’s public landing-page URL; the API returns rendered HTML. No visitor personal data and no account data are sent. United States (api.cloudflare.com, anycast) US recipient → DPF adequacy if certified, otherwise SCCs plus TIA. Cloudflare Browser Rendering DPA on file.
Stripe: Stripe Payments Europe, Ltd. (Ireland) or Stripe, Inc. (US) Payments: Checkout, Customer Portal, subscription management, webhooks. Payment processor, not merchant of record; Finalform is the legal seller. Customer billing email and name, organization-id metadata, subscription and transaction data. Card and PAN data go directly to Stripe-hosted pages; Finalform stores no card data. European Union and United States, per account If the contracting entity is Stripe Payments Europe, Ltd. (Ireland), the EU leg is intra-EEA with no Chapter V transfer; onward US processing relies on Stripe’s own DPF/SCC safeguards. If the contracting entity is Stripe, Inc. (US), the transfer relies on DPF adequacy if certified, otherwise SCCs plus TIA.
Resend: Plus Five Five, Inc., US Transactional email: verification, magic-link, password reset, invitations, and service notifications Recipient customer email address and email content (subject and HTML body), and the recipient name in templates. United States (api.resend.com, no region override) US recipient → DPF adequacy if certified, otherwise SCCs plus TIA.

Transmission boundary. The customer-side snippet transmits behavioral and event data only to the first-party Autopage API; it calls no third party directly. Every third-party transfer of visitor data takes place server-side from the Autopage engine, never browser-to-vendor. This supports Finalform’s role as processor and the Customer’s role as controller.

Providers that are not Sub-processors. The following are not active recipients and are therefore not listed: OpenAI (not integrated; Anthropic is the sole language-model provider), Keak (not integrated), Google OAuth (not enabled), error-monitoring and third-party analytics services (not active), Cloudflare Turnstile (not active, distinct from the active Browser Rendering above), and object storage. If any of these becomes active, it will be added to this list under the change-notification process in Section 5. Object storage is dormant at launch.

3. International transfers

Some Sub-processors process personal data outside the European Economic Area (EEA), including in the United States. For each such transfer, Finalform relies on an appropriate safeguard under Chapter V GDPR:

  • EU-US Data Privacy Framework (DPF) adequacy, where the recipient entity is certified under the DPF. The transfer then relies on the European Commission’s adequacy decision for the DPF.
  • Standard Contractual Clauses (SCCs) plus a transfer impact assessment (TIA), where the recipient is not DPF-certified. The TIA evaluates the legal regime in the recipient country and the supplementary measures in place.

Per-recipient position:

  • Railway (US): third-country transfer; DPF adequacy if certified, otherwise SCCs plus TIA.
  • Anthropic (US): third-country transfer; DPF adequacy if certified, otherwise SCCs plus TIA. The exposure is mitigated by the data-minimisation posture: no per-visitor data, direct identifiers stripped, no prompt or response content logged, no-training tier enabled.
  • Cloudflare (US): third-country transfer; DPF adequacy if certified, otherwise SCCs plus TIA. This is the lowest-exposure recipient, since only a public URL leaves Finalform’s systems.
  • Stripe: the EU leg has no Chapter V transfer if the contracting entity is Stripe Payments Europe, Ltd. (Ireland); onward US processing relies on Stripe’s own safeguards. If the contracting entity is Stripe, Inc. (US), the transfer is treated as a third-country transfer under DPF or SCCs plus TIA.
  • Resend (US): third-country transfer; DPF adequacy if certified, otherwise SCCs plus TIA.

On request, Finalform will disclose in advance the recipient country and the Article 44 et seq. transfer mechanism for any Sub-processor, and will make a copy of the relevant safeguards (including the SCCs) available to the Customer through the contact details in the Privacy Policy.

4. Flow-down and residual liability

Finalform imposes on each Sub-processor data-protection obligations that are equivalent to those agreed with the Customer in the Data Processing Agreement, in particular under Article 28(4) GDPR. Where a Sub-processor fails to fulfil its data-protection obligations, Finalform remains fully liable to the Customer for the performance of that Sub-processor’s obligations.

On the end of the provision of services, Finalform instructs each Sub-processor to delete or return the Customer’s personal data on the same basis as set out in the Data Processing Agreement.

5. Change notification and objection

This list operates under the general written authorization in the Data Processing Agreement (Section 1). Finalform may add or replace Sub-processors as Autopage evolves, subject to the following:

  • Advance notice. Finalform gives affected Customers at least 30 days’ advance notice before a new or replaced Sub-processor begins processing personal data, by email to the registered account holder and by an in-app notice, and by updating this list with a new effective date and version.
  • Objection. Within an appropriate period after notice, the Customer may object to the change on reasonable, data-protection-related grounds. German supervisory guidance reads the appropriate objection period as typically up to about two weeks; this objection period is distinct from the 30-day advance-notice period and runs in parallel within it.
  • Consequence of objection. If the Customer does not object within the period, the change is deemed approved. If the Customer raises a justified objection on data-protection grounds that the parties cannot resolve, the Customer may terminate the affected part of the service without penalty.

6. Cookie and storage disclosure

This list covers Sub-processors that process personal data on behalf of Customers. For information on the cookies and device storage used on Finalform’s own websites, see the Cookie and Storage Policy.

autopage

Built and operated by Finalform, a studio that makes tools that run without the founder.

© 2026 Autopage, operated by Finalform GmbH.Business customers only. All rights reserved.

EU company · GDPR

Site
How it worksPricingStart free
Legal
Terms of ServiceDatenschutzCookie PolicyImpressumAcceptable Use PolicySub-processorsData Processing AgreementTechnical and Organizational MeasuresData Retention PolicyDPIA Assist Template
www.autopage.dev