Legal
Subprocessor Registry
Last updated: June 13, 2026. This registry lists providers that may process personal data to operate Corelyx or execute workflows you explicitly configure. Customer-configured providers may require separate customer account settings, DPAs, SCCs, or transfer assessments.
Our commitment
Corelyx is built for European users and runs under Austrian law and GDPR. Core infrastructure — database, web hosting, and workflow runtime — is deployed in EU regions. Where a provider cannot currently be configured EU-only (payments, transactional email, some AI model routing), we rely on signed DPAs and Standard Contractual Clauses as the transfer safeguard under Art. 46 GDPR. We are actively working to reduce and eliminate non-EU processing over time.
See Section 8 of our Privacy Policy for the full breakdown.
Showing 20 of 20 providers
| Provider | Purpose | Data categories | Region | EU-only | Transfer basis | DPA | SCC | Retention | Optional | Default use | Last reviewed |
|---|---|---|---|---|---|---|---|---|---|---|---|
Supabase database Always | Database, authentication, realtime APIs, and Vault-backed secret references. | Account data, Workflow schemas, Runs, Approvals, Connection metadata, Secret references | Configured Supabase project region, expected EU for Corelyx production. | Yes | DPA and SCCs where the configured project or subprocessors involve third-country processing. | Available | Available where needed | Controlled by Corelyx database retention settings and Supabase backup rotation. | Required | Default | 2026-06-13 |
Vercel hosting Always | Hosts the Next.js web app, API routes, static assets, and deployment logs. | Request metadata, IP addresses, Application logs, Rendered application data | Global CDN; server compute depends on project region configuration. | Yes | DPA and transfer addendum; EU-only support depends on project routing and log configuration. | Available | Available where needed | Deployment and request logs follow Vercel account retention and Corelyx log minimisation settings. | Required | Default | 2026-06-13 |
Railway hosting Always | Hosts the Python workflow runtime used for execution steps. | Workflow execution payloads, Runtime logs, Connector requests and responses | Configured Railway service region. | Yes | DPA and SCCs where the runtime or subprocessors involve third-country processing. | Available | Available where needed | Runtime logs are minimised and governed by workspace retention settings where technically available. | Required | Default | 2026-06-13 |
Inngest orchestration Always | Schedules, retries, event dispatch, and asynchronous workflow orchestration. | Event metadata, Function payloads, Retry state, Timing data | Provider-managed cloud location based on the configured Inngest account. | No | DPA and SCCs required if personal data is sent through orchestration events. | Available | Available where needed | Event retention depends on the Inngest account and should not include secrets or full payloads in EU-only mode. | Required | Default | 2026-06-13 |
Cloudflare (Turnstile) security Only on abuse-protected public forms (e.g. signup) when Turnstile is enabled | Bot, spam, and abuse protection (CAPTCHA challenge) on public forms such as signup. Only active when Turnstile is enabled via the NEXT_PUBLIC_TURNSTILE_SITE_KEY / TURNSTILE_SECRET_KEY configuration. | IP address, Browser and device signals, Challenge interaction data, Turnstile token | Provider-managed global edge network. | No | Processed on Cloudflare's global edge as a bot/abuse safeguard under Art. 6(1)(f) GDPR (legitimate interest in security). Cloudflare DPA and SCCs cover any third-country processing. | Available | Available where needed | Cloudflare states Turnstile does not use the data for cross-site tracking or advertising; challenge data is retained only briefly for abuse prevention per Cloudflare's retention schedule. | Required | Customer enabled | 2026-07-24 |
Resend Only when transactional email is sent | Transactional email for approvals, failures, account, and billing notices. | Recipient email, Sender details, Subject lines, Notification content | United States for account data, email metadata, logs, and API records. | No | DPA and SCCs required for EEA personal data. | Available | Available where needed | Provider email logs follow Resend retention; Corelyx avoids sending secrets in notifications. | Required | Customer enabled | 2026-06-13 |
Stripe payments Only when billing features are used | Checkout, subscriptions, invoices, payment processing, and fraud prevention. | Billing contact data, Subscription metadata, Invoice records, Payment and fraud signals | Provider-managed financial infrastructure. | No | DPA, SCCs, adequacy mechanisms, and payment-law processing roles depending on account setup. | Available | Available where needed | Billing and tax data is retained as required by law. | Required | Customer enabled | 2026-06-13 |
OpenAI llm Only when selected or configured | Optional model inference for workflow agent nodes and model operations. Also provides text embeddings for agent knowledge retrieval via the platform key; knowledge content and queries are PII-redacted before embedding, and EU-only workspaces are excluded unless the platform project is verified EU-resident (OPENAI_EU_RESIDENCY). | Prompts, System instructions, Selected workflow inputs, Model outputs, Usage metadata | United States by default unless eligible European data residency is configured in the customer or platform account. | Yes | DPA and SCCs unless an eligible EU-resident project is verified for the workspace. | Available | Available where needed | Retention depends on account, API project, abuse monitoring, and zero-data-retention settings. | Optional | Customer enabled | 2026-06-13 |
Anthropic llm Only when selected or configured | Optional model inference for workflow agent nodes. | Prompts, System instructions, Selected workflow inputs, Model outputs, Usage metadata | United States for customer data unless otherwise agreed. | No | DPA and SCCs required for EEA personal data. | Available | Available where needed | Commercial API retention is provider-controlled and subject to policy and abuse-monitoring exceptions. | Optional | Customer enabled | 2026-06-13 |
OpenRouter llm Always active when using the Corelyx platform key. Also active when customer configures their own OpenRouter API key. | LLM routing layer used by the Corelyx platform key to execute agent nodes. Also optionally used when a customer configures their own OpenRouter API key. | Prompts, System instructions, Selected workflow inputs, Model outputs, Provider routing metadata | Provider-managed global infrastructure. EU routing available on enterprise OpenRouter accounts. | No | No signed DPA or SCCs currently in place. Corelyx is pursuing an enterprise DPA with OpenRouter. Until completed, customers should treat OpenRouter as a third-country transfer risk and avoid routing special-category or high-risk personal data through the Corelyx platform key. | Missing / customer review required | Missing / required before use | OpenRouter states prompts are not used for training and are not retained beyond request processing by default. Verify current policy at openrouter.ai/privacy. | Required | Default | 2026-06-13 |
connector Sign-In available to all users. Workflow connectors only if explicitly connected by the customer. | Google Sign-In (OAuth authentication available to all users). Optionally also used for Gmail, Calendar, Docs, Drive, and Sheets workflow actions when explicitly connected. | Profile data and email address (Sign-In), Mailbox and file metadata (if connected), Message and document content (if connected), Calendar data (if connected), Workflow payloads (if connected) | Provider-managed; depends on Google account, Workspace region, and service. | Yes | Google terms, DPA, SCCs, and customer tenant controls. | Available | Available where needed | Sign-In profile data retained for the life of the account. Connector data retention is controlled by the connected Google account or tenant. | Required | Default | 2026-06-13 |
Notion connector Only if explicitly connected by the customer | Optional Notion workflow actions (pages, databases, search) when explicitly connected. | Page and database content (if connected), Workspace metadata (if connected), Workflow payloads (if connected) | United States by default; EU data residency available for eligible Notion Enterprise workspaces. | No | Notion Data Processing Addendum incorporating SCCs for EEA personal data. | Available | Available where needed | Connector data retention is controlled by the connected Notion workspace; Corelyx stores only workflow payloads per its retention settings. | Optional | Customer enabled | 2026-06-12 |
Slack connector Only if explicitly connected by the customer | Optional Slack workflow actions (read messages, post messages, channel and webhook events) when explicitly connected. | Workspace identifiers, Channel metadata, Message content (if connected), Workflow payloads (if connected) | United States by default; Slack offers EU data residency for eligible Enterprise Grid plans. | No | Salesforce/Slack Data Processing Addendum incorporating SCCs for EEA personal data; customer-configured connector. | Available | Available where needed | Connector data retention is controlled by the connected Slack workspace; Corelyx stores only workflow payloads per its retention settings. | Optional | Customer enabled | 2026-06-13 |
GitHub connector Only if explicitly connected by the customer | Optional GitHub workflow actions (read repositories, create issues, pull requests, comments, webhooks) when explicitly connected. | Repository metadata, Issue and PR content (if connected), Comments, Webhook payloads | Provider-managed global infrastructure (United States). | No | GitHub (Microsoft) Data Protection Addendum incorporating SCCs for EEA personal data; customer-configured connector. | Available | Available where needed | Retention is controlled by the connected GitHub account or organization; Corelyx stores only workflow payloads per its retention settings. | Optional | Customer enabled | 2026-06-13 |
Airtable connector Only if explicitly connected by the customer | Optional Airtable workflow actions (read or write bases, records, and schemas) when explicitly connected. | Base metadata, Table schemas, Records and fields (if connected), Webhook events | Provider-managed infrastructure (United States). | No | Airtable Data Processing Addendum incorporating SCCs for EEA personal data; customer-configured connector. | Available | Available where needed | Retention is controlled by the connected Airtable account; Corelyx stores only workflow payloads per its retention settings. | Optional | Customer enabled | 2026-06-13 |
Asana connector Only if explicitly connected by the customer | Optional Asana workflow actions (read or create projects, tasks, and related events) when explicitly connected. | Workspace identifiers, Task content (if connected), Assignee data, Comments, Webhook events | Provider-managed infrastructure (United States). | No | Asana Data Processing Addendum incorporating SCCs for EEA personal data; customer-configured connector. | Available | Available where needed | Retention is controlled by the connected Asana workspace; Corelyx stores only workflow payloads per its retention settings. | Optional | Customer enabled | 2026-06-13 |
HubSpot connector Only if explicitly connected by the customer | Optional HubSpot workflow actions (read or update contacts and related CRM information) when explicitly connected. | Contact records (if connected), Names, emails, phone numbers, Company and CRM metadata, Webhook events | United States by default; HubSpot offers EU data hosting for eligible accounts. | No | HubSpot Data Processing Agreement incorporating SCCs for EEA personal data; customer-configured connector. | Available | Available where needed | Retention is controlled by the connected HubSpot account; Corelyx stores only workflow payloads per its retention settings. | Optional | Customer enabled | 2026-06-13 |
Typeform connector Only if explicitly connected by the customer | Optional Typeform workflow triggers and reads (form definitions, submissions, webhook responses) when explicitly connected. | Form metadata, Answer payloads (if connected), Response identifiers, Personal data collected in the form | European Union by default; provider-managed subprocessors may process data outside the EEA. | No | Typeform Data Processing Agreement incorporating SCCs where subprocessors process EEA personal data; customer-configured connector. | Available | Available where needed | Retention is controlled by the connected Typeform account; Corelyx stores only workflow payloads per its retention settings. | Optional | Customer enabled | 2026-06-13 |
Microsoft (Outlook, Microsoft 365 / Graph) connector Only if explicitly connected by the customer (Outlook / Microsoft 365) | Optional Microsoft 365 / Outlook workflow actions (read and send email and related Microsoft Graph data) when explicitly connected. | Mailbox metadata, Message content (if connected), Recipients and subject lines, Microsoft account information | Provider-managed; depends on the connected Microsoft 365 tenant region and the Microsoft EU Data Boundary. | Yes | Microsoft Products and Services Data Protection Addendum incorporating SCCs and the EU Data Boundary; regional controls depend on the customer tenant. | Available | Available where needed | Retention is controlled by the connected Microsoft 365 tenant; Corelyx stores only workflow payloads per its retention settings. | Optional | Customer enabled | 2026-06-13 |
Customer-configured HTTP endpoint connector Only if enabled by the customer | Customer-configured webhook or HTTP connector calls to arbitrary public endpoints. | Workflow payloads selected by the customer | Customer-configured destination. | No | Customer must document recipient, DPA, SCCs, and transfer basis before personal-data use. | Missing / customer review required | Missing / required before use | Retention is controlled by the customer-configured endpoint. | Optional | Customer enabled | 2026-06-13 |
Change notice
Corelyx will provide at least 30 days advance notice before adding or replacing a subprocessor that processes customer personal data, unless urgent security, availability, or legal requirements make advance notice impracticable.
See the DPA and Data Residency pages for processor terms and regional controls.
Last registry review: 2026-06-13.
