Subprocessor Register
Pre-launch draft · no active hosted-service subprocessors listed yet. This page becomes the canonical public register before the Privacy Notice takes effect.
Mahanu uses a subprocessor only when it needs that provider to operate the hosted service and only under written data-protection and confidentiality obligations. The effective register lists, for each provider, its legal entity, service, data categories, processing location, transfer safeguard where applicable, and date added or removed.
| Provider | Service and data | Location / safeguard | Status |
|---|---|---|---|
[hosting provider] |
application hosting, encrypted backups, and operational metadata | [location / safeguard] |
required before launch |
[transactional email provider] |
sign-in and service email address, delivery metadata | [location / safeguard] |
required before launch |
[payment provider] |
payment and billing data | [location / safeguard] |
required before paid hosting |
[error-monitoring provider] |
minimised error and incident data | [location / safeguard] |
required before monitoring is enabled |
[Mahanu-hosted AI provider] |
only the project context expressly sent through the hosted assistant route | [location / safeguard] |
required before hosted AI launches |
An owner’s custom endpoint, personal API-key provider, third-party bot operator, or direct visit to a sponsor site is not Mahanu’s subprocessor. It is a separate recipient chosen by the user and is explained at the point of disclosure.
For a material new subprocessor, Mahanu gives the notice and objection opportunity required by applicable law and relevant contracts before the change takes effect. Questions go to [email protected].
Mahanu