© 2026 OSOS/Omega. All rights reserved.
Omega version: 0.10.1
Product: OSOS / Omega
Provider: Osos AI GmbH, Cosimastraße 121, 81925 Munich, Germany
Effective Date: 12.06.2026
Relationship to other documents: This list is Annex 2 to the Data Processing Agreement (DPA) (Art. 28(2), (4) GDPR). The status at the time of contract conclusion forms a snapshot part of the respective DPA. Notification and objection rights arise from Section 5 of the DPA.
> Note: We name each subprocessor with its registered office, purpose, data categories, processing region, and — where a third-country transfer applies — the transfer mechanism per Art. 46 GDPR.
| Subprocessor | Registered office | Purpose | Data categories | Processing region | Third-country transfer mechanism |
|---|---|---|---|---|---|
| Supabase Inc. | USA (infrastructure on AWS, EU) | Database, authentication, file storage | Account/profile data, project content, chat histories, file uploads | EU (AWS eu-central-1, Frankfurt am Main) |
Processing in the EU; for any support access by the US parent company: EU Standard Contractual Clauses (SCC) |
| Hetzner Online GmbH | Germany | Hosting of the application (compute, container) | All data processed by the application (in transit / in compute) | EU (Germany) | No third-country transfer |
| Mistral AI SAS | France (EU) | AI inference (default model provider) | Inputs submitted to the AI (project content, requirements, chat inputs) | EU (France) | No third-country transfer |
| OpenAI, L.L.C. | USA | AI inference – only when the customer actively selects the OpenAI configuration (opt-in; the default is Mistral/EU) | Inputs submitted to the AI (project content, requirements, chat inputs) | USA | EU Standard Contractual Clauses (Art. 46 GDPR); EU-US Data Privacy Framework, where the provider is certified |
| Stripe Payments Europe Ltd. | Ireland (EU) | Payment processing (subscription, boost purchases) | Name, email, Stripe customer ID, payment-method token (no plaintext at the Provider) | EU (Ireland) | Processing in the EU; for any transfer to Stripe, Inc. (USA): SCC / EU-US Data Privacy Framework. Stripe is PCI-DSS Level 1 certified |
| Upstash Inc. | USA (infrastructure in the EU) | Fast counters and session caches (rate limiting, Redis-based) | Technical counters with user/IP reference | EU | Processing in the EU; for the US parent company: EU Standard Contractual Clauses (SCC) |
| Resend, Inc. | USA | Delivery of transactional system emails (welcome, notifications, cancellations) | Email address and content of the system email | USA | EU Standard Contractual Clauses (Art. 46 GDPR); EU-US Data Privacy Framework, where the provider is certified |
For all AI subprocessors, the AI Data Policy applies additionally:
The following providers are part of our development and operations infrastructure but process no personal customer data and are therefore not subprocessors within the meaning of Art. 28 GDPR:
This list is kept current. The Provider notifies of the intended addition or replacement of a subprocessor with at least 30 days' notice; the objection right arises from Section 5.2 of the DPA. The current version is available via the Trust Center.
Contact for data protection enquiries: info@ososomega.com