Legal

Subprocessor Registry

Last updated: June 13, 2026. This registry lists providers that may process personal data to operate Corelyx or execute workflows you explicitly configure. Customer-configured providers may require separate customer account settings, DPAs, SCCs, or transfer assessments.

Our commitment

Corelyx is built for European users and runs under Austrian law and GDPR. Core infrastructure — database, web hosting, and workflow runtime — is deployed in EU regions. Where a provider cannot currently be configured EU-only (payments, transactional email, some AI model routing), we rely on signed DPAs and Standard Contractual Clauses as the transfer safeguard under Art. 46 GDPR. We are actively working to reduce and eliminate non-EU processing over time.

See Section 8 of our Privacy Policy for the full breakdown.

Showing 20 of 20 providers

ProviderPurposeData categoriesRegionEU-onlyTransfer basisDPASCCRetentionOptionalDefault useLast reviewed

Supabase

database

Always

Database, authentication, realtime APIs, and Vault-backed secret references.Account data, Workflow schemas, Runs, Approvals, Connection metadata, Secret referencesConfigured Supabase project region, expected EU for Corelyx production.YesDPA and SCCs where the configured project or subprocessors involve third-country processing.AvailableAvailable where neededControlled by Corelyx database retention settings and Supabase backup rotation.RequiredDefault2026-06-13

Vercel

hosting

Always

Hosts the Next.js web app, API routes, static assets, and deployment logs.Request metadata, IP addresses, Application logs, Rendered application dataGlobal CDN; server compute depends on project region configuration.YesDPA and transfer addendum; EU-only support depends on project routing and log configuration.AvailableAvailable where neededDeployment and request logs follow Vercel account retention and Corelyx log minimisation settings.RequiredDefault2026-06-13

Railway

hosting

Always

Hosts the Python workflow runtime used for execution steps.Workflow execution payloads, Runtime logs, Connector requests and responsesConfigured Railway service region.YesDPA and SCCs where the runtime or subprocessors involve third-country processing.AvailableAvailable where neededRuntime logs are minimised and governed by workspace retention settings where technically available.RequiredDefault2026-06-13

Inngest

orchestration

Always

Schedules, retries, event dispatch, and asynchronous workflow orchestration.Event metadata, Function payloads, Retry state, Timing dataProvider-managed cloud location based on the configured Inngest account.NoDPA and SCCs required if personal data is sent through orchestration events.AvailableAvailable where neededEvent retention depends on the Inngest account and should not include secrets or full payloads in EU-only mode.RequiredDefault2026-06-13

Cloudflare (Turnstile)

security

Only on abuse-protected public forms (e.g. signup) when Turnstile is enabled

Bot, spam, and abuse protection (CAPTCHA challenge) on public forms such as signup. Only active when Turnstile is enabled via the NEXT_PUBLIC_TURNSTILE_SITE_KEY / TURNSTILE_SECRET_KEY configuration.IP address, Browser and device signals, Challenge interaction data, Turnstile tokenProvider-managed global edge network.NoProcessed on Cloudflare's global edge as a bot/abuse safeguard under Art. 6(1)(f) GDPR (legitimate interest in security). Cloudflare DPA and SCCs cover any third-country processing.AvailableAvailable where neededCloudflare states Turnstile does not use the data for cross-site tracking or advertising; challenge data is retained only briefly for abuse prevention per Cloudflare's retention schedule.RequiredCustomer enabled2026-07-24

Resend

email

Only when transactional email is sent

Transactional email for approvals, failures, account, and billing notices.Recipient email, Sender details, Subject lines, Notification contentUnited States for account data, email metadata, logs, and API records.NoDPA and SCCs required for EEA personal data.AvailableAvailable where neededProvider email logs follow Resend retention; Corelyx avoids sending secrets in notifications.RequiredCustomer enabled2026-06-13

Stripe

payments

Only when billing features are used

Checkout, subscriptions, invoices, payment processing, and fraud prevention.Billing contact data, Subscription metadata, Invoice records, Payment and fraud signalsProvider-managed financial infrastructure.NoDPA, SCCs, adequacy mechanisms, and payment-law processing roles depending on account setup.AvailableAvailable where neededBilling and tax data is retained as required by law.RequiredCustomer enabled2026-06-13

OpenAI

llm

Only when selected or configured

Optional model inference for workflow agent nodes and model operations. Also provides text embeddings for agent knowledge retrieval via the platform key; knowledge content and queries are PII-redacted before embedding, and EU-only workspaces are excluded unless the platform project is verified EU-resident (OPENAI_EU_RESIDENCY).Prompts, System instructions, Selected workflow inputs, Model outputs, Usage metadataUnited States by default unless eligible European data residency is configured in the customer or platform account.YesDPA and SCCs unless an eligible EU-resident project is verified for the workspace.AvailableAvailable where neededRetention depends on account, API project, abuse monitoring, and zero-data-retention settings.OptionalCustomer enabled2026-06-13

Anthropic

llm

Only when selected or configured

Optional model inference for workflow agent nodes.Prompts, System instructions, Selected workflow inputs, Model outputs, Usage metadataUnited States for customer data unless otherwise agreed.NoDPA and SCCs required for EEA personal data.AvailableAvailable where neededCommercial API retention is provider-controlled and subject to policy and abuse-monitoring exceptions.OptionalCustomer enabled2026-06-13

OpenRouter

llm

Always active when using the Corelyx platform key. Also active when customer configures their own OpenRouter API key.

LLM routing layer used by the Corelyx platform key to execute agent nodes. Also optionally used when a customer configures their own OpenRouter API key.Prompts, System instructions, Selected workflow inputs, Model outputs, Provider routing metadataProvider-managed global infrastructure. EU routing available on enterprise OpenRouter accounts.NoNo signed DPA or SCCs currently in place. Corelyx is pursuing an enterprise DPA with OpenRouter. Until completed, customers should treat OpenRouter as a third-country transfer risk and avoid routing special-category or high-risk personal data through the Corelyx platform key.Missing / customer review requiredMissing / required before useOpenRouter states prompts are not used for training and are not retained beyond request processing by default. Verify current policy at openrouter.ai/privacy.RequiredDefault2026-06-13

Google

connector

Sign-In available to all users. Workflow connectors only if explicitly connected by the customer.

Google Sign-In (OAuth authentication available to all users). Optionally also used for Gmail, Calendar, Docs, Drive, and Sheets workflow actions when explicitly connected.Profile data and email address (Sign-In), Mailbox and file metadata (if connected), Message and document content (if connected), Calendar data (if connected), Workflow payloads (if connected)Provider-managed; depends on Google account, Workspace region, and service.YesGoogle terms, DPA, SCCs, and customer tenant controls.AvailableAvailable where neededSign-In profile data retained for the life of the account. Connector data retention is controlled by the connected Google account or tenant.RequiredDefault2026-06-13

Notion

connector

Only if explicitly connected by the customer

Optional Notion workflow actions (pages, databases, search) when explicitly connected.Page and database content (if connected), Workspace metadata (if connected), Workflow payloads (if connected)United States by default; EU data residency available for eligible Notion Enterprise workspaces.NoNotion Data Processing Addendum incorporating SCCs for EEA personal data.AvailableAvailable where neededConnector data retention is controlled by the connected Notion workspace; Corelyx stores only workflow payloads per its retention settings.OptionalCustomer enabled2026-06-12

Slack

connector

Only if explicitly connected by the customer

Optional Slack workflow actions (read messages, post messages, channel and webhook events) when explicitly connected.Workspace identifiers, Channel metadata, Message content (if connected), Workflow payloads (if connected)United States by default; Slack offers EU data residency for eligible Enterprise Grid plans.NoSalesforce/Slack Data Processing Addendum incorporating SCCs for EEA personal data; customer-configured connector.AvailableAvailable where neededConnector data retention is controlled by the connected Slack workspace; Corelyx stores only workflow payloads per its retention settings.OptionalCustomer enabled2026-06-13

GitHub

connector

Only if explicitly connected by the customer

Optional GitHub workflow actions (read repositories, create issues, pull requests, comments, webhooks) when explicitly connected.Repository metadata, Issue and PR content (if connected), Comments, Webhook payloadsProvider-managed global infrastructure (United States).NoGitHub (Microsoft) Data Protection Addendum incorporating SCCs for EEA personal data; customer-configured connector.AvailableAvailable where neededRetention is controlled by the connected GitHub account or organization; Corelyx stores only workflow payloads per its retention settings.OptionalCustomer enabled2026-06-13

Airtable

connector

Only if explicitly connected by the customer

Optional Airtable workflow actions (read or write bases, records, and schemas) when explicitly connected.Base metadata, Table schemas, Records and fields (if connected), Webhook eventsProvider-managed infrastructure (United States).NoAirtable Data Processing Addendum incorporating SCCs for EEA personal data; customer-configured connector.AvailableAvailable where neededRetention is controlled by the connected Airtable account; Corelyx stores only workflow payloads per its retention settings.OptionalCustomer enabled2026-06-13

Asana

connector

Only if explicitly connected by the customer

Optional Asana workflow actions (read or create projects, tasks, and related events) when explicitly connected.Workspace identifiers, Task content (if connected), Assignee data, Comments, Webhook eventsProvider-managed infrastructure (United States).NoAsana Data Processing Addendum incorporating SCCs for EEA personal data; customer-configured connector.AvailableAvailable where neededRetention is controlled by the connected Asana workspace; Corelyx stores only workflow payloads per its retention settings.OptionalCustomer enabled2026-06-13

HubSpot

connector

Only if explicitly connected by the customer

Optional HubSpot workflow actions (read or update contacts and related CRM information) when explicitly connected.Contact records (if connected), Names, emails, phone numbers, Company and CRM metadata, Webhook eventsUnited States by default; HubSpot offers EU data hosting for eligible accounts.NoHubSpot Data Processing Agreement incorporating SCCs for EEA personal data; customer-configured connector.AvailableAvailable where neededRetention is controlled by the connected HubSpot account; Corelyx stores only workflow payloads per its retention settings.OptionalCustomer enabled2026-06-13

Typeform

connector

Only if explicitly connected by the customer

Optional Typeform workflow triggers and reads (form definitions, submissions, webhook responses) when explicitly connected.Form metadata, Answer payloads (if connected), Response identifiers, Personal data collected in the formEuropean Union by default; provider-managed subprocessors may process data outside the EEA.NoTypeform Data Processing Agreement incorporating SCCs where subprocessors process EEA personal data; customer-configured connector.AvailableAvailable where neededRetention is controlled by the connected Typeform account; Corelyx stores only workflow payloads per its retention settings.OptionalCustomer enabled2026-06-13

Microsoft (Outlook, Microsoft 365 / Graph)

connector

Only if explicitly connected by the customer (Outlook / Microsoft 365)

Optional Microsoft 365 / Outlook workflow actions (read and send email and related Microsoft Graph data) when explicitly connected.Mailbox metadata, Message content (if connected), Recipients and subject lines, Microsoft account informationProvider-managed; depends on the connected Microsoft 365 tenant region and the Microsoft EU Data Boundary.YesMicrosoft Products and Services Data Protection Addendum incorporating SCCs and the EU Data Boundary; regional controls depend on the customer tenant.AvailableAvailable where neededRetention is controlled by the connected Microsoft 365 tenant; Corelyx stores only workflow payloads per its retention settings.OptionalCustomer enabled2026-06-13

Customer-configured HTTP endpoint

connector

Only if enabled by the customer

Customer-configured webhook or HTTP connector calls to arbitrary public endpoints.Workflow payloads selected by the customerCustomer-configured destination.NoCustomer must document recipient, DPA, SCCs, and transfer basis before personal-data use.Missing / customer review requiredMissing / required before useRetention is controlled by the customer-configured endpoint.OptionalCustomer enabled2026-06-13

Change notice

Corelyx will provide at least 30 days advance notice before adding or replacing a subprocessor that processes customer personal data, unless urgent security, availability, or legal requirements make advance notice impracticable.

See the DPA and Data Residency pages for processor terms and regional controls.

Last registry review: 2026-06-13.

Subprocessors | Corelyx