Subprocessors and Partners
This document lists every third party that processes personal data or content on NAL's behalf as part of operating the Services. It is the authoritative reference for GDPR Article 28 / 152-FZ subprocessor disclosure.
Read this first if you are sending NAL anything sensitive. Some Services route content through third-party AI providers and community-operated GPU workers (NAL Net). NAL cannot control how a third party stores, logs, or handles the data we forward to them beyond the contractual terms in place. Where the third party operates under stricter terms than ours (e.g., zero-retention inference modes), we configure that by default; where they operate under looser terms, their terms govern.
Effective date: 2026-07-14 (v1.0.1; originally published 2026-05-15) Last reviewed: 2026-07-14
How to read this document
| Column | Meaning |
|---|---|
| Role | Why we use them (infrastructure, payments, AI inference, etc.) |
| Data accessed | What categories of data they see |
| Region | Where the data is processed |
| Cross-border basis | The legal mechanism for EU/RU data transfers (SCC = Standard Contractual Clauses) |
| Their privacy policy | Where you can read their terms |
If you do not want a particular subprocessor to see your data, the relevant model picker / region selector lets you avoid them in most cases. Where avoidance is not possible (Hetzner is our sole hosting provider; Stripe is the sole non-RU payment processor) the only alternative is to not use the affected Service.
Infrastructure
Hetzner Online GmbH
- Role. Primary infrastructure — bare-metal servers, networking, S3-compatible object storage, BX backups.
- Data accessed. All NAL data at rest and in transit through the primary datacentre. Encrypted at rest on managed volumes; backups encrypted at rest.
- Region. Nuremberg, Germany.
- Cross-border basis. Within EU; no cross-border transfer from EU data subjects.
- Their privacy policy. https://www.hetzner.com/legal/privacy-policy
- Notes. All four production servers (nal-db, nal-ai, nal-api, nal-mon) run on Hetzner. If Hetzner is unavailable, the Services are unavailable.
Cloudflare, Inc.
- Role. DNS, CDN, edge security, frontend Workers (account.nal.digital, guild.nal.digital, mira.nal.digital, music.nal.digital, brain.nal.digital), DDoS mitigation, SSL/TLS at the edge.
- Data accessed. All HTTP requests to NAL frontends and APIs pass through Cloudflare's edge. Request URL, headers, IP, geographic location. Static assets and frontend bundles are cached on Cloudflare's global network.
- Region. Global edge.
- Cross-border basis. SCC + Cloudflare's published EU Addendum.
- Their privacy policy. https://www.cloudflare.com/privacypolicy/
Payments
Stripe, Inc.
- Role. International payments — card processing, wallet top-ups, withdrawals.
- Data accessed. Card number (full), billing address, email, transaction amount, currency. NAL stores only the last 4 digits and Stripe's payment-method token.
- Region. United States, with EU/UK representation. Card data processed in compliance with PCI-DSS.
- Cross-border basis. SCC + Stripe's UK/EU Adequacy Schedules.
- Their privacy policy. https://stripe.com/privacy
YooKassa (NSPK / Yandex)
- Role. RU / CIS payments — card processing for Russian-issued cards and rubles.
- Data accessed. Card number, billing details, transaction amount, payment-method token.
- Region. Russia.
- Cross-border basis. Operations within RU jurisdiction for RU data subjects; 152-FZ compliance.
- Their privacy policy. https://yookassa.ru/legal/fz152-policy
AI inference providers
Routing to a specific AI provider depends on the model you select in the picker. NAL configures the strictest commercially-available data-handling option (e.g., zero-retention / no-training) by default. The provider's own terms govern what they see and do.
OpenAI, OpCo, L.L.C.
- Role. LLM inference when you select an OpenAI model (GPT-4 family, gpt-4o, o1, embedding models).
- Data accessed. Your prompt + retrieved-context for that single
call. NAL uses the OpenAI API with
store=false(zero-retention) where supported. - Region. US primary; EU residency option used for EU-resident users where the selected model supports it.
- Cross-border basis. SCC.
- Their privacy policy. https://openai.com/policies/privacy-policy/
- Their no-training commitment. API-tier requests are excluded from training by default per OpenAI's published policy.
Anthropic, PBC
- Role. LLM inference when you select a Claude model (Claude 4 family).
- Data accessed. Prompt + context for the single call.
- Region. US, with EU edge serving for EU-resident users where available.
- Cross-border basis. SCC.
- Their privacy policy. https://www.anthropic.com/legal/privacy
- Their no-training commitment. API-tier requests are excluded from training per Anthropic's published policy.
Google LLC
- Role. LLM inference (Gemini family) when selected. OAuth provider for "Sign in with Google".
- Data accessed. For inference: prompt + context for the single call. For OAuth sign-in: your Google account identifier, name, email, and profile photo URL.
- Note. NAL does not currently use Google Calendar, Drive, or Gmail APIs. Features named "calendar" or "files" in NAL use NAL's own self-hosted CalDAV and OpenCloud storage, not Google. See Google User Data & Limited Use.
- Region. Global Google infrastructure.
- Cross-border basis. SCC + Google's published Data Processing Addendum.
- Their privacy policy. https://policies.google.com/privacy
Runware AI
- Role. Hosted image / video / music generation fallback. Used when the primary NAL pipeline is unavailable or when you select a Runware-only model.
- Data accessed. Generation prompt, reference inputs you supply, output image / video / audio.
- Region. EU.
- Cross-border basis. Within EU for EU users.
- Their privacy policy. https://runware.ai/privacy
Communications and support
Chatwoot
- Role. In-product support chat (the chat bubble at the bottom of NAL frontends).
- Data accessed. Your name, email, support conversation contents, page URL where the chat was opened.
- Region. Self-hosted by NAL on Hetzner infrastructure.
- Cross-border basis. No cross-border transfer (self-hosted alongside primary infrastructure).
- Their software. https://www.chatwoot.com/ (open source).
Telegram FZ-LLC
- Role. Telegram bot integration for BRAIN — sending and receiving Telegram messages where you have linked your Telegram account.
- Data accessed. Telegram user ID, username, first name, and the message contents in conversations where the BRAIN bot is a participant.
- Region. UAE (Telegram's stated jurisdiction).
- Cross-border basis. SCC where required; the integration is opt-in per conversation.
- Their privacy policy. https://telegram.org/privacy
Observability
Grafana Labs (Faro)
- Role. Frontend observability — browser error tracking, performance metrics.
- Data accessed. Browser session metadata, user-agent, page URL, error stack traces, performance timings. No content of forms, uploads, or messages.
- Region. EU.
- Cross-border basis. Within EU; Grafana Cloud EU region.
- Their privacy policy. https://grafana.com/legal/privacy-policy/
NAL Net community workers
NAL Net is a community-operated GPU marketplace. Workers are independent third-party contributors, not employees or subprocessors of NAL in the traditional sense — they are subprocessors only for the specific job they process for you.
- Role. GPU inference on demand for Studio, Music, and selected BRAIN jobs.
- Data accessed. Job prompt, reference inputs you supply, and the generated output. The worker sees your prompt and output in plaintext. The worker does not see your NAL account ID, email, wallet, payment history, or any other job you submitted.
- Region. Distributed (worker's location depends on the worker). You cannot select a worker's jurisdiction.
- Cross-border basis. Each worker registration includes a worker agreement that imposes the obligations of the NAL Net Addendum (no retention, no use, no training, no resale of prompts and outputs). NAL enforces these obligations through reputation, monitoring, and deactivation — but NAL cannot prevent a determined worker from exfiltrating data they receive.
- Avoidance. Select "hosted endpoint only" in the model picker to exclude community workers from your job. This excludes your prompt from being sent to a third-party community machine. The hosted alternative is more expensive.
- Worker obligations. See NAL Net Addendum Section 3.
Selfhosted (no third-party data flow)
The following technologies run inside NAL's own infrastructure and do not transfer your data to a third party. Listed for completeness and audit transparency only.
| Technology | Role | Hosted on |
|---|---|---|
| PostgreSQL | Primary relational store | nal-db (Hetzner) |
| Neo4j | Knowledge graph (BRAIN, Guild) | nal-db / nal-ai |
| Apache Pulsar | Message bus | nal-db |
| Redis | Cache and session store | nal-db / nal-api |
| Qdrant | Vector search | nal-ai |
| MinIO / S3 | Object storage (files, media) | nal-db |
| OpenCloud | File storage UI (cloud.nal.digital) | nal-db |
| Prometheus / Loki / Grafana | Server-side metrics and logs | nal-mon |
| Kong 3.9 OSS | Public API gateway | nal-api |
| GitLab CE | Source control (internal) | NAL infra |
| ACE-Step | Music generation pipeline | nal-net workers / NAL GPUs |
| faster-whisper | Speech-to-text | nal-ai |
| edge-tts | Text-to-speech | nal-ai |
| Wan2GP | Video / image generation pipeline | nal-net workers / NAL GPUs |
These are NAL's tools, not subprocessors. Your data does not leave Hetzner / NAL infrastructure when these technologies process it.
Disclosure to law enforcement
Separate from the subprocessor list above, NAL may disclose user data to law-enforcement or regulators in response to a valid legal process (court order, subpoena, regulator demand) or where NAL has a good-faith belief disclosure is necessary to prevent imminent harm to life. The recipients vary by request and are not enumerated here.
NAL publishes an annual transparency report summarising the number and category of such requests received and complied with. The first transparency report will be published once NAL has been operating for a full calendar year.
Changes to this list
Adding or replacing a subprocessor is a change to the Privacy Policy. We will:
- update this document and bump its version,
- update
docs/legal/VERSIONS.md, - show an in-product banner and email account-holders at least 30 days before the new subprocessor begins processing your data.
You have the right to object to a new subprocessor by emailing privacy@nal.digital. If we cannot accommodate the objection, your option is to stop using the affected Service and (if you wish) close your account, in which case we will refund any prepaid subscription pro rata to your wallet.
Contact
| Topic | Address |
|---|---|
| Subprocessor objections, data-subject requests | privacy@nal.digital |
| Cross-border-transfer documentation (SCC copies) | privacy@nal.digital |
| Security incidents | security@nal.digital |