KI-Denkraum
Service providers
Who processes data for us, where and on what basis. Part A is annex 2 to the DPA.
Version of 9 October 2026 · identifier denkraum-dienstleister-2026-10-09 · Download as PDF
This English text is a translation for information purposes. Only the German version is authoritative: Dienstleister.
Who processes personal data for the KI-Denkraum, where and on what basis. As of 9 October 2026; DPF status checked on 9 October 2026 in the list at dataprivacyframework.gov.
Part A is Annex 2 to the data processing agreement (kidenkraum.com/en/avv, § 7): the sub-processors for the data the provider processes on behalf of a Customer. The provider also uses the same services for processing under its own responsibility; the privacy policy (kidenkraum.com/en/datenschutz) states which. Part B names further service providers and recipients that concern only the privacy policy. The provider announces a new or replacing sub-processor at least 30 days in advance in accordance with § 7 of the DPA; every version of this list remains available under its date.
Part A: Sub-processors
| Sub-processor | Service | Place of processing | Safeguard where a third country is involved |
|---|---|---|---|
| Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 | Database, sign-in (Supabase Auth) | Amazon Web Services data centres in Frankfurt am Main (eu-central-1); access for operations and support from Singapore and the USA possible | Standard contractual clauses in Supabase’s data processing agreement. There is no adequacy decision for Singapore; Supabase is not certified under the Data Privacy Framework. |
| Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA | Hosting, delivery, server functions, technical logs | Server functions in Frankfurt am Main, delivery via a global network | EU-US Data Privacy Framework (certified, active), additionally standard contractual clauses |
| AC PM, LLC (Postmark, a company of ActiveCampaign), 1 N Dearborn Street, Suite 500, Chicago, IL 60602, USA | Sending of emails | USA (data centres of Deft and Amazon Web Services) | EU-US Data Privacy Framework (certified as an affiliated company of ActiveCampaign, LLC, active), additionally standard contractual clauses |
| Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA | Turnstile: check on forms that create an account or trigger an email to an address without a sign-in, for example at registration, including of invited Users, or at password reset, whether a human is filling in the form (IP address, technical characteristics of the browser) | Cloudflare’s global network | EU-US Data Privacy Framework (certified, active), additionally standard contractual clauses |
| Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland | Email mailbox hallo@kidenkraum.com for enquiries, instructions and notifications concerning team management | Data centres in the EU; access from the USA not excluded | EU-US Data Privacy Framework (Microsoft Corporation certified), additionally standard contractual clauses |
| Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg | AI model (Claude via Amazon Bedrock) for support and operations in individual cases, in a separate working session; for the search, the conversion of the search term (model by Cohere via Amazon Bedrock), without the identifier of the account | Data centres in the EU; no storage of inputs and outputs; the developers of the models have no access | Processing in the EU; AWS data processing agreement with standard contractual clauses, Amazon in the EU-US Data Privacy Framework |
Notes:
- The services use their own sub-processors, such as Amazon Web Services, and publish lists of them.
- According to its own statements, Cloudflare additionally uses the Turnstile signals under its own responsibility to improve bot detection.
- Cover images are delivered by the provider via its own server; Spotify receives no User data in the process.
Part B: Further service providers and recipients
These service providers are not sub-processors under the data processing agreement: the provider conducts billing under its own responsibility, and the payment service provider receives only the number of seats from team management, and nothing at all from a team under an individual contract; Users choose sign-in with Google voluntarily, and Google is itself responsible for it.
| Service provider | Service | Role | Safeguard where a third country is involved |
|---|---|---|---|
| Stripe Payments Europe, Limited, One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland | Checkout, payment, invoices, VAT, customer portal | partly a processor of the provider (checkout, customer portal, tax), partly independently responsible (payment processing, fraud prevention) | Access by the Stripe group from the USA; EU-US Data Privacy Framework, additionally standard contractual clauses |
| Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland | Sign-in with Google, only if the User chooses it | own responsibility | USA (Google LLC); EU-US Data Privacy Framework |