Last updated: August 24, 2026
A sub-processor is a third party that processes customer data on our behalf so that Nimvox can operate. This page is the complete, current list. It is maintained here rather than inside the Privacy Policy so that it can be kept accurate without amending a policy document — a list that is awkward to update is a list that goes stale.
We publish any addition to this list at least 30 days before that sub-processor begins processing customer data, so customers have an opportunity to object.
| Sub-processor | Purpose | Data received | Location |
|---|---|---|---|
| Cloudflare, Inc. | CDN, DNS, DDoS protection, analytics | IP address, page views | Global edge |
| netcup GmbH | Application and database hosting | All service data at rest | United States (Virginia) |
| Hetzner Online GmbH | Build and CI infrastructure; outbound routing for job-listing fetches | Build artefacts; no customer content at rest | Finland (Helsinki) |
| Cloudflare R2 | Object storage for uploaded and generated assets | Files you upload or generate | EU region |
| Sub-processor | Purpose | Data received | Location |
|---|---|---|---|
| Stripe, Inc. | Card payments and subscription billing | Email, billing amount. Card details go directly to Stripe — Nimvox never receives them. | United States |
| PayPal (Europe) S.à r.l. | PayPal payments and subscriptions | Email, billing amount | Luxembourg / United States |
These are used only when you invoke an AI feature — asking Markvox to suggest brand names, or to draft a logo. Nothing is sent to an AI provider in the background, and no AI provider receives your account or billing data.
| Sub-processor | Purpose | Data received | Location |
|---|---|---|---|
| OpenAI, L.L.C. | Generating brand name suggestions and logo drafts you request | The brief or prompt you supply for that request | United States |
Training. We contract with our AI providers so that content you send through Nimvox is not used to train their models.
Retention. A provider may retain input for a limited period for its own abuse monitoring, separately from training. Where that applies we state it here rather than implying the data is never stored at all. For OpenAI this is currently up to 30 days.
For a data processing agreement, a security review, or to object to a sub-processor, contact [email protected].