Subprocessors & International Data Transfers
Last updated: 2026-05-17
FlowZap relies on a limited set of subprocessors to deliver the Service. This page lists each subprocessor, its purpose, hosting region, data categories processed, and the applicable transfer mechanism under GDPR Art. 46 and PIPL Art. 38–39. Material changes will be announced on this page before they take effect.
| Subprocessor | Purpose | Region | Data processed | Transfer mechanism |
|---|---|---|---|---|
| Deepseek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.) | LLM analysis for the SOC2 / GDPR / PIPL Compliance Checker. Receives only the FlowZap Code DSL submitted by the user — no account identifiers, no IP, no email. | People's Republic of China | FlowZap Code DSL text (user-pasted diagram). No personal data is intentionally transmitted; users are warned not to paste personal data. | PIPL Art. 38(1)(3) Standard Contract for cross-border transfer + GDPR Art. 49(1)(a) explicit consent (the user voluntarily submits the diagram knowing it is sent to Deepseek). No diagram content is retained by FlowZap. |
| Perplexity AI, Inc. | LLM generation for the AI-assisted FlowZap Code generator (authenticated users only). | United States | User prompt text submitted to the AI generator. No diagrams, no account credentials. | GDPR Art. 46 Standard Contractual Clauses (SCC, 2021 module 2 controller-to-processor). UK IDTA addendum applicable for UK users. |
| Hetzner Online GmbH | Application and database hosting (primary infrastructure). | European Union (Germany / Finland) | All application data: user accounts, diagrams, telemetry, logs. | No third-country transfer (data remains in EU/EEA). |
| Scaleway SAS | Transactional email delivery (login codes, notifications). | European Union (France) | Recipient email address, message content (login code or notification). | No third-country transfer (data remains in EU/EEA). |
Questions about subprocessors or to exercise your rights, contact us via the feedback form.