BadMars — Sub-processor List
from vendor DPAs / trust centres** (2026-08-13, sources cited per record). Google
“Sign in with Google” moved to independent controllers; OpenAI + Anthropic
represented as EEA contracting entities (Ireland) with a documented onward-US
chain. The per-recipient transfer basis is now the actual one (not “SCCs-first”):
Anthropic + OpenAI = SCCs; Cloudflare + Google + Resend + Sentry = DPF + SCCs
fallback; Hetzner = intra-EU, none. Shares Annex IV of dpa.md. What remains
VERIFY is genuinely publication-day (the live DPF Active badge, exact account
tier, importer Art 3 status). 0.5/0.3/0.2/0.1 — see git.
BadMars (operated by Nivobit Digital SRL, Romania — the EEA exporter) uses the third parties in the register to run the Service. A Sub-processor processes personal data on BadMars’s behalf where BadMars acts as a processor. A provider that independently determines the purposes or essential means of its processing is listed under Independent controllers / recipients.
Change notice
We give 30 days’ advance notice of any new or replaced sub-processor before it starts processing personal data — a new version of this page, plus email to business-tier (Fleet/Enterprise) owners, who may object; the remedy for a sustained objection is termination.
Transfer register — sub-processors (processors)
Each record is a processing chain. Facts are sourced to the vendor’s own documents;
VERIFY marks what must be confirmed on the publication date.
Anthropic — AI inference (core Panel analysis)
- Contracting entity: Anthropic Ireland, Limited (Dublin) — EEA/UK/Swiss customers contract with the Irish entity under Anthropic’s Commercial Terms (eff. 17 Jun 2025); Anthropic, PBC is the US/rest-of-world entity.
- GDPR role: Sub-processor
- Data categories: payload text; report/Debrief content, transiently, for generation
- Processing location: EEA contracting entity; onward inference in the United States (no EU inference region)
- Onward transfer (EEA → US): Anthropic’s own transfer under its DPA — not a direct BadMars → US flow (DPA §12.3). BadMars → Anthropic Ireland is intra-EEA.
- Importer subject to GDPR Art 3?:
- Transfer mechanism (onward leg): SCCs — Commission Decision 2021/914 (Module 2/3) + UK/Swiss addenda. Anthropic is NOT DPF-certified (its DPA specifies SCCs; no DPF registry entry).
- Training permitted?: No — Commercial Terms: “Anthropic may not train models on Customer Content from Services.”
- Provider retention: standard auto-delete within 30 days; up to 2 years (inputs/outputs) / 7 years (classification scores) only if flagged by trust-&-safety. ZDR not held (self-serve commercial/credit account — owner-confirmed). Note: “Covered Models” (Mythos-class) carry a mandatory 30-day retention even under ZDR (eff. 9 Jun 2026) —
- Last verified:
- Evidence: Commercial Terms (anthropic.com/legal/commercial-terms) · DPA (anthropic.com/legal/data-processing-addendum) · retention (privacy.claude.com, art. 7996866) · sub-processors (trust.anthropic.com/subprocessors —
OpenAI — AI inference (failover + text embeddings)
- Contracting entity: OpenAI Ireland Ltd (Dublin) — EEA/Swiss customers, since the 15 Feb 2024 terms. US entity = OpenAI, L.L.C. / OpenAI OpCo —
- GDPR role: Sub-processor
- Data categories: same as Anthropic, only when routed to OpenAI or for embeddings
- Processing location: EEA contracting entity with onward US processing (Azure primary infra)
- Onward transfer (EEA → US): under OpenAI’s DPA — do not characterise as a direct BadMars → US transfer (DPA §12.3)
- Importer subject to GDPR Art 3?:
- Transfer mechanism (onward leg): OpenAI Ireland’s onward third-country processing is subject to the safeguards in OpenAI’s DPA — SCCs 2021/914 + UK Addendum (the exact onward importer/module is held in the internal transfer evidence, not asserted publicly). OpenAI is NOT DPF-certified (SCCs-only per its DPA; corroborated by legal analyses).
- Training permitted?: No — API data not used to train since 1 Mar 2023 (opt-in only)
- Provider retention: 30-day abuse-monitoring; ZDR/Modified Abuse Monitoring only for approved eligible customers + endpoints via sales — not held
- Last verified:
- Evidence: DPA (openai.com/policies/data-processing-addendum, v.010126 —· data-controls guide (developers.openai.com) · sub-processor list (openai.com/policies/sub-processor-list —
Hetzner Online GmbH — hosting, database, object storage, backups
- Contracting entity: Hetzner Online GmbH (Germany). The US and Singapore regions are run by Hetzner US LLC / Hetzner Singapore Pte. Ltd. — BadMars uses EU/German locations only.
- GDPR role: Sub-processor
- Data categories: all stored account data, payloads, reports, backups
- Processing location: Germany (EU); Hetzner processes master/billing data exclusively within the EU; backups stay in the chosen region
- Transfer mechanism: — (intra-EU, none) for EU-region use; DPF N/A (German entity)
- Provider retention: per contract / until deletion
- Last verified:
- Evidence: Data-protection page (docs.hetzner.com) · DPA (hetzner.com/AV/DPA_en.pdf; in-account signing) · sub-processor PDF at hetzner.com/AV —
Cloudflare, Inc. — DNS, CDN, WAF, Turnstile bot protection
- Contracting entity: Cloudflare, Inc. (Delaware, US) — sole contracting/importer entity for EU customers (Customer DPA v6.4, eff. 3 Apr 2026)
- GDPR role: Sub-processor
- Data categories: IP address, request metadata, Turnstile challenge signals
- Processing location: geographically-distributed edge / United States (no EU-only pin for general services)
- Third-country importer: Cloudflare, Inc. (US) — BadMars → Cloudflare is a direct EEA → US transfer
- Importer subject to GDPR Art 3?:
- Transfer mechanism: DPF-first — Cloudflare self-certifies EU-US + UK Extension + Swiss-US DPF (participant #5666 —
- Provider retention:
- Last verified:
- Evidence: DPA v6.4 (cloudflare.com/cloudflare-customer-dpa) · sub-processor list (cloudflare.com/gdpr/subprocessors, upd. 1 Oct 2025)
Resend (Plus Five Five, Inc.) — transactional email
- Contracting entity: Plus Five Five, Inc. (San Francisco, US) — direct EEA → US transfer
- GDPR role: Sub-processor
- Data categories: email address, name, transactional message content
- Processing location: United States
- Importer subject to GDPR Art 3?:
- Transfer mechanism: DPF (EU-US + UK Extension — participant #8907;
- Provider retention: 30-day send-log retention (Free/Pro/Scale; Enterprise flexible); account data deleted 90 days post-termination; compliance records kept 3 years
- Last verified:
- Evidence: DPA (resend.com/legal/dpa, upd. 31 Dec 2025) · DPF changelog (resend.com/changelog) · sub-processor list (resend.com/legal/subprocessors — 22 US sub-processors, upd. 15 Jul 2026)
Functional Software, Inc. (Sentry) — error monitoring
- Contracting entity: Functional Software, Inc. d/b/a Sentry (San Francisco, US)
- GDPR role: Sub-processor
- Data categories: diagnostic/error data; incidental technical identifiers (payload content scrubbed pre-send)
- Processing location: EU region (Frankfurt) selected (hosting ruling §7)
- Remote / admin-access — residual non-EEA (Sentry’s own docs): the EU region does not eliminate Chapter V exposure. Account/auth/2FA/access-token/SSO and org audit-log data, plus any support-ticket content, are US-resident regardless of region; technical support runs through an affiliate in Canada (Sentry Software Canada Inc.) and US-based Intercom. Relies on DPF + SCCs for that residual US/CA transfer.
- Transfer mechanism: DPF (EU-US + UK Extension + Swiss-US — participant #5869;
- Provider retention:
- Last verified:
- Evidence: DPA v5.1.0 (sentry.io/legal/dpa, eff. 29 May 2024) · data-storage-location docs (docs.sentry.io) · sub-processor list (sentry.io/legal/subprocessors, upd. 1 Jun 2026)
Independent controllers / recipients / controller-side processors (not Customer-Content sub-processors)
Neither of the Google rows is a sub-processor of Customer Content: OAuth is an independent controller, and GA4 is a processor for BadMars’s own controller-side website analytics (not Fleet Customer Content) — which is why both sit here rather than in the transfer register above.
Google — “Sign in with Google” (OAuth)
- Role: Independent controller for the account data it returns (moved out of the processor register — v4).
- Contracting entity: Google LLC / Google Ireland —
- Data disclosed / received: Google account identifier, email, name — only if the user chooses this login (source: Google, Privacy Policy Art 14)
- Transfer: governed by Google’s own terms as controller
- Evidence: support.google.com/accounts (art. 12849458 / 12921417); business.safety.google/controllerterms
Google — Google Analytics 4 (consent-gated)
- Role: BadMars’s controller-side analytics processor under the Google Ads Data Processing Terms, consent-gated in basic Consent Mode — Google Analytics is not contacted until the visitor opts in (owner ruling 2026-08-13; engineering: GA loader set to basic mode). Google Signals + advertising features OFF (owner-verified) — with Signals on, Google becomes a joint controller, so keeping it off preserves the processor posture.
- Data categories: usage/analytics data, online identifiers — only after cookie consent
- Processing location: United States
- Transfer mechanism: DPF — Google LLC self-certifies EU-US + Swiss-US DPF (participant #5780, covers Google LLC + wholly-owned US subsidiaries incl. Analytics; in force for Ads/Analytics since 1 Sep 2023;
- Evidence: Google Ads Data Processing Terms (google.com/analytics/terms/dpa) · transfer frameworks (policies.google.com/privacy/frameworks) · business.safety.google/adsdatatransfers
- (Cookie/consent behaviour is in the Cookie Policy.)
Paddle.com Market Ltd — Merchant of Record
- Role: Independent controller of the purchase transaction (seller of record; handles payment, tax, invoicing under its own buyer terms and privacy policy). Not a BadMars sub-processor.
- Data: purchase/transaction data the buyer provides to Paddle (no card data reaches BadMars)
- Evidence: Paddle buyer/privacy terms —
Fallback-honesty note
OpenAI is listed from day one because the service can route inference to it (failover and embeddings), even in months when it never does. Listing the capability means a mid-month failover is never a surprise change to this page.
Future additions (not active today)
- Advertising pixels — Meta Platforms (Facebook) and TikTok would be added for marketing measurement, consent-gated and listed here before they go live. They act as recipients / independent (or joint) controllers of the pixel data; enabling them also triggers the California “Do Not Sell or Share” handling in the Privacy Policy.
- Apple / Google (independent controllers) and RevenueCat (sub-processor) would be added for a future mobile app, each with the 30-day notice above.