OSOS/Omega← Back

Subprocessor List

Product: OSOS / Omega

Provider: Osos AI GmbH, Cosimastraße 121, 81925 Munich, Germany

Effective Date: 12.06.2026

Relationship to other documents: This list is Annex 2 to the Data Processing Agreement (DPA) (Art. 28(2), (4) GDPR). The status at the time of contract conclusion forms a snapshot part of the respective DPA. Notification and objection rights arise from Section 5 of the DPA.

> Note: We name each subprocessor with its registered office, purpose, data categories, processing region, and — where a third-country transfer applies — the transfer mechanism per Art. 46 GDPR.


1. Active Subprocessors

Subprocessor Registered office Purpose Data categories Processing region Third-country transfer mechanism
Supabase Inc. USA (infrastructure on AWS, EU) Database, authentication, file storage Account/profile data, project content, chat histories, file uploads EU (AWS eu-central-1, Frankfurt am Main) Processing in the EU; for any support access by the US parent company: EU Standard Contractual Clauses (SCC)
Hetzner Online GmbH Germany Hosting of the application (compute, container) All data processed by the application (in transit / in compute) EU (Germany) No third-country transfer
Mistral AI SAS France (EU) AI inference (default model provider) Inputs submitted to the AI (project content, requirements, chat inputs) EU (France) No third-country transfer
OpenAI, L.L.C. USA AI inference – only when the customer actively selects the OpenAI configuration (opt-in; the default is Mistral/EU) Inputs submitted to the AI (project content, requirements, chat inputs) USA EU Standard Contractual Clauses (Art. 46 GDPR); EU-US Data Privacy Framework, where the provider is certified
Stripe Payments Europe Ltd. Ireland (EU) Payment processing (subscription, boost purchases) Name, email, Stripe customer ID, payment-method token (no plaintext at the Provider) EU (Ireland) Processing in the EU; for any transfer to Stripe, Inc. (USA): SCC / EU-US Data Privacy Framework. Stripe is PCI-DSS Level 1 certified
Upstash Inc. USA (infrastructure in the EU) Fast counters and session caches (rate limiting, Redis-based) Technical counters with user/IP reference EU Processing in the EU; for the US parent company: EU Standard Contractual Clauses (SCC)
Resend, Inc. USA Delivery of transactional system emails (welcome, notifications, cancellations) Email address and content of the system email USA EU Standard Contractual Clauses (Art. 46 GDPR); EU-US Data Privacy Framework, where the provider is certified

2. AI Subprocessors: Processing Rules

For all AI subprocessors, the AI Data Policy applies additionally:

  • The default model provider is Mistral (EU) – processing occurs without any third-country transfer.
  • OpenAI (USA) processes data only if the customer actively selects the OpenAI configuration (opt-in). Without that selection, no data is transmitted to OpenAI. A restriction of AI inference to EU resources can be agreed in the Order Form.
  • No training on customer data: Neither Mistral nor OpenAI uses the submitted content to train their own models; access is exclusively via the respective API. This is contractually assured (AI Data Policy, Section 3.1).

3. Infrastructure Not Processing Personal Customer Data

The following providers are part of our development and operations infrastructure but process no personal customer data and are therefore not subprocessors within the meaning of Art. 28 GDPR:

  • GitHub, Inc. (USA, Microsoft) – source code management and CI/CD pipeline. Only source code and build artifacts are processed, no customer data.

4. Currentness and Changes

This list is kept current. The Provider notifies of the intended addition or replacement of a subprocessor with at least 30 days' notice; the objection right arises from Section 5.2 of the DPA. The current version is available via the Trust Center.

Contact for data protection enquiries: info@ososomega.com