← Mahanu

Subprocessor Register

Pre-launch draft · no active hosted-service subprocessors listed yet. This page becomes the canonical public register before the Privacy Notice takes effect.

Mahanu uses a subprocessor only when it needs that provider to operate the hosted service and only under written data-protection and confidentiality obligations. The effective register lists, for each provider, its legal entity, service, data categories, processing location, transfer safeguard where applicable, and date added or removed.

Provider Service and data Location / safeguard Status
[hosting provider] application hosting, encrypted backups, and operational metadata [location / safeguard] required before launch
[transactional email provider] sign-in and service email address, delivery metadata [location / safeguard] required before launch
[payment provider] payment and billing data [location / safeguard] required before paid hosting
[error-monitoring provider] minimised error and incident data [location / safeguard] required before monitoring is enabled
[Mahanu-hosted AI provider] only the project context expressly sent through the hosted assistant route [location / safeguard] required before hosted AI launches

An owner’s custom endpoint, personal API-key provider, third-party bot operator, or direct visit to a sponsor site is not Mahanu’s subprocessor. It is a separate recipient chosen by the user and is explained at the point of disclosure.

For a material new subprocessor, Mahanu gives the notice and objection opportunity required by applicable law and relevant contracts before the change takes effect. Questions go to [email protected].