Subprocessors
- Version
- 1
- Effective date
Atelye is a platform operated by Murat Gözel, a sole proprietor established in Türkiye. When you use it, Atelye acts as your processor for the personal data you and your customers put into it — the Data Processing Addendum sets out the terms.
To run the platform, Atelye relies on a small number of third parties. Those that process personal data on Atelye's behalf are sub-processors, and this page lists all of them. It is Annex III of the Data Processing Addendum and is versioned like every other document in this set.
What counts as a sub-processor here
A sub-processor is a third party that processes personal data on Atelye's behalf in the course of providing the platform to you.
A supplier is not a sub-processor merely because Atelye buys something from it. Software that Atelye runs itself, on infrastructure Atelye controls, creates no separate processing relationship — the section "Not sub-processors" below names the ones most likely to be mistaken for one.
When a given sub-processor is engaged depends on what you use. Hosting and storage apply to every account. The messaging platforms and the AI providers are engaged only once you connect a messaging channel and use the AI-assisted reply features. Email and SMS delivery are engaged for sign-in codes and service notices to your staff.
Current sub-processors
Hetzner Online GmbH
- Role: compute, database hosting, and the servers on which the platform runs.
- Personal data processed: all platform data, as stored and processed by the application.
- Processing location: Frankfurt, Germany (EU).
Cloudflare, Inc. — R2 object storage
- Role: object storage for media, generated documents, exports and archived telemetry.
- Personal data processed: media and files uploaded to or captured by the platform, generated documents, and data exports.
- Processing location: European Union.
Meta Platforms, Inc. — Instagram, Messenger, WhatsApp
- Role: the messaging channels themselves. Messages reach Atelye from Meta's platforms, and approved replies are sent back through them.
- Personal data processed: message content and media, channel-scoped identifiers, display names, and conversation metadata.
- Processing location: United States and globally.
- Engaged when: you connect an Instagram professional account, a Facebook Page or a WhatsApp Business Account.
Anthropic PBC
- Role: AI inference — generating reply drafts.
- Personal data processed: conversation content and the business context assembled to answer it.
- Processing location: United States.
- Engaged when: you use the AI-assisted reply features.
OpenAI, L.L.C.
- Role: AI inference — generating reply drafts.
- Personal data processed: conversation content and the business context assembled to answer it.
- Processing location: United States.
- Engaged when: you use the AI-assisted reply features.
Mistral AI SAS
- Role: AI inference — generating reply drafts. This is the routing target for accounts that require inference to stay inside the EU.
- Personal data processed: conversation content and the business context assembled to answer it.
- Processing location: European Union.
- Engaged when: you use the AI-assisted reply features.
Postmark (ActiveCampaign, LLC)
- Role: transactional email — sign-in codes, service notices.
- Personal data processed: the email address and name of your staff members.
- Processing location: United States.
Twilio Inc.
- Role: SMS delivery — sign-in codes.
- Personal data processed: the phone number of your staff members.
- Processing location: United States.
GitHub, Inc. — GitHub Container Registry
- Role: storage and distribution of the platform's own build artifacts.
- Personal data processed: none. It holds application images, not data.
- Processing location: United States.
GitHub is listed for completeness rather than because it processes personal data. Naming a supplier in the delivery path and stating that it holds no personal data is more useful than omitting it and leaving you to wonder.
Not sub-processors
The following are self-hosted on Atelye's own Hetzner infrastructure in Frankfurt. They are software Atelye runs, not services Atelye sends your data to, and there is no independent processing relationship with their authors or vendors:
- Meilisearch — search indexing.
- Cerbos — authorisation policy decisions.
- Hatchet — background job execution.
- OpenObserve — logs, metrics and traces.
Data handled by these components never leaves the infrastructure described under Hetzner above.
Terms Atelye requires of a sub-processor
Before a sub-processor processes personal data in production, Atelye requires:
- a data processing agreement in writing, imposing obligations that are in substance no less protective than those Atelye owes you under the Data Processing Addendum;
- an Article 46 transfer safeguard — in practice the EU Standard Contractual Clauses or an equivalent mechanism — for any sub-processor outside the European Economic Area;
- for an AI provider, contractual terms that exclude the use of inputs to train models. Atelye's statement that your data is not used for model training has to hold across the whole processing chain, not just for Atelye's own intentions, so it is a condition of engagement rather than an assumption about a provider's default settings.
Atelye records the evidence for each of these before the provider is put into production use, and remains fully liable to you for a sub-processor's performance.
Changes to this list
Atelye gives at least 30 days' notice before adding a new sub-processor or replacing an existing one. Notice goes to the address registered on your account.
You may object. Within those 30 days you may object on reasonable, documented data-protection grounds by writing to legal@atelye.net. Atelye will work with you in good faith towards a resolution — a configuration change, an alternative provider, or withholding the affected feature from your account. If no resolution is reached you may terminate the affected part of the service without penalty, and section 12 of the Data Processing Addendum governs what happens to your data.
Emergency replacement. If a sub-processor has to be replaced sooner than 30 days to protect the security or continuity of the service — because it has suffered a breach, or has ceased to operate — Atelye makes the change and notifies you without undue delay, with the reason. Your right to object is unaffected and runs from that notice.
Each change to this list is published as a new version, and the superseded version stays available
at /legal/archive/subprocessors/<version>.
Contact
Questions about this list, or an objection to a proposed change: legal@atelye.net
Data protection matters generally: privacy@atelye.net