sub-processors.

Version 1.16, 26 August 2026. Questions: contact@noctovisor.com

What this is

Noctovisor is your data processor. The companies below are the ones it uses to run the service, so they are your sub-processors. This page is the authoritative list, kept here rather than repeated inside the data processing agreement, because a list held in two places goes stale in one of them. If you are putting Noctovisor into a third-party register, what you need for the entry is in the table.

Read this first

Your data is hosted in Canada, not in the EU. Noctovisor is a Polish business, but the server that holds the database and runs the monitoring is in Canada. The language models are in the United States. Inside the European Economic Area there are two things and no more: the mailbox your list arrives in, held in the EU, and one backup copy in Poland.

Canada holds an EU adequacy decision, and standard contractual clauses are in place on top of it. But if your policy requires EEA-only or in-country hosting, this service will not meet that requirement, and no paperwork changes it. There is no choice of processing region.

The service also holds very little: company names and domains, the public identifiers we matched them to, findings already published elsewhere, and the addresses you nominate. No contracts, no spend data, no questionnaire responses, no credentials into your systems.

The list

ProviderWhat it doesWhereTransfer basis
OVH (contracted through OVH's Polish entity) The server that runs everything: the database with your list, entity matches, criteria and alert record, and the monitoring that checks sources. Also holds the primary backup, in a different data centre from the server. Canada: Quebec (server) and Ontario (backup) Two, on purpose: the EU adequacy decision for Canada (Commission Decision 2002/2/EC, confirmed still in force by the Commission's review published 15 January 2024), and standard contractual clauses (Commission Decision 2021/914). See the note below.
Anthropic (Claude) Drafts and translates alert text. Runs the automated check of each alert against its source. Processes a customer's list at onboarding. United States Standard contractual clauses (Commission Decision 2021/914), as incorporated in the provider's data processing terms, with Data Privacy Framework certification as additional cover where held.
xAI (Grok) Drafts and translates alert text. Runs the automated check of each alert against its source. United States As above.
OpenAI Drafts and translates alert text. Runs the automated check of each alert against its source. United States As above.
Google (Gemini) Drafts and translates alert text. Runs the automated check of each alert against its source. United States As above.
Google (Workspace) Hosts the contact@noctovisor.com mailbox. Your list and instructions arrive and are held here. It does not send your alerts. European Union: the Workspace data region is set to Europe. That setting covers message content; some service metadata sits outside its scope and may be processed in the United States. No transfer arises for the message content held in the EU. For the metadata outside the data-region scope, standard contractual clauses (Commission Decision 2021/914) as incorporated in Google's Cloud Data Processing Addendum.
Cloudflare Nameservers, reverse proxy, website hosting, the watch form's relay, and the connection to the comment page an alert links to. A list submitted through the watch form, and a comment left through an alert's link, pass through Cloudflare's network on the way to us and are not stored there. No finding or alert passes through it. Global network; processing under Cloudflare's data processing addendum Standard contractual clauses (Commission Decision 2021/914), as incorporated in Cloudflare's data processing addendum, with Data Privacy Framework certification as additional cover where held.
Resend Sends your alerts, summaries and reports, from alerts.noctovisor.com, and carries what you submit in the watch form to our own mailbox. United States Standard contractual clauses (Commission Decision 2021/914), with Data Privacy Framework certification as additional cover where held.
Stripe (Stripe Payments Europe, Limited) Takes card payment for a subscription, on a checkout page hosted on Stripe's own domain. Receives the billing name, business name, address, VAT number and email address of whoever pays, which plan they bought, and the card details they type into Stripe's page. Card details do not pass through us: the page belongs to Stripe, and noctovisor.com loads no code from it. Receives nothing about your list, your watched companies, your alerts or your findings, because the monitoring system has no connection to it at all. Ireland, with Stripe group processing in the United States The contract is with an Irish entity, so no transfer arises for it. For the group processing outside the EEA, standard contractual clauses (Commission Decision 2021/914) as incorporated in Stripe's data processing agreement, with EU-US Data Privacy Framework certification as additional cover. See the note below on why this row is here at all.
Firecrawl (SideGuide Technologies, Inc.) Fetches and renders public web pages: press articles, and weekly checks of pages on the watched companies' own sites. Holds a copy of each watched page between checks so the service can see what changed. By design it is only given pages of watched businesses that are companies; where a watched business is an individual person, such as a sole trader, the check runs from our own server instead, and nothing about them reaches this provider. United States Not a transfer of your personal data, by design. This provider receives addresses of public pages about companies: never your identity, never your list as a whole, never a watched business that is an individual person. It offers no data processing agreement below its enterprise tier; rather than sign nothing and say otherwise, we keep personal data away from it entirely. If that boundary ever changes, contractual clauses come first and this entry changes with notice.
Serper (serper.dev) Finds news coverage: runs the daily news search for each watched company, the company's name as a search query, and returns links to publisher articles, which are then read by Firecrawl above. By design it is only given companies. Where a watched business is an individual person, such as a sole trader, their news search stays on the public news feed the service already reads, and nothing about them reaches this provider. Not published by the provider; its terms are governed by the law of the United Kingdom and state that it operates globally. Not a transfer of your personal data, by design. This provider receives search queries naming watched companies: never your identity, never your list as a whole, never a watched business that is an individual person. It publishes no data processing agreement; rather than sign nothing and say otherwise, we keep personal data away from it entirely. If that boundary ever changes, contractual clauses come first and this entry changes with notice.
Brave (Brave Software, Inc.) Under evaluation as a second news search, and the standing fallback for it: it runs the same daily news search as Serper above, in parallel, so the two can be compared on real coverage, and it takes over that search when Serper is unavailable or switched off. It may later take over the job outright. Receives the watched company's name as a search query and nothing else. By design it is only given companies. Where a watched business is an individual person, such as a sole trader, nothing about them reaches this provider. United States Not a transfer of your personal data, by design. This provider receives search queries naming watched companies: never your identity, never your list as a whole, never a watched business that is an individual person. Unlike Serper it publishes a data processing addendum for its search API; under its terms a record of queries is retained for up to 90 days for billing and troubleshooting.
Tavily (AlphaAI Technologies, Inc.) Under evaluation in the same way, for two jobs: the daily news search, and reading the public press pages that a search returns, run in parallel with Serper and Firecrawl above so the results can be compared. It is also the standing fallback for page reading, and takes that job over when Firecrawl is unavailable or switched off. Receives watched companies' names as search queries and addresses of public pages about companies. By design it is only given companies. Where a watched business is an individual person, such as a sole trader, nothing about them reaches this provider. United States Not a transfer of your personal data, by design. This provider receives search queries naming watched companies and addresses of public pages about them: never your identity, never your list as a whole, never a watched business that is an individual person.
Second backup copy, held by Noctovisor An independent copy of the backup, on our own encrypted hardware. No third party holds it. Daily, kept for 30 days. Poland Not a transfer.

Why two transfer bases for the hosting

Canada's adequacy decision covers recipients subject to PIPEDA, the federal privacy law. Quebec, where the server sits, has its own provincial privacy law, and that provincial law does not hold adequacy in its own right. (The backup capacity is in Ontario, which has no equivalent general private-sector statute, so PIPEDA applies to it directly and the adequacy decision reaches it without the argument that follows.) There are arguments that the adequacy decision reaches this anyway: PIPEDA continues to apply to personal information crossing a national border, and our contract is with OVH's Polish entity rather than a Canadian one. Rather than ask you to rely on how that argument resolves, standard contractual clauses are in place as well, so the transfer stands on either basis independently.

Language models, in more detail

The models see company names, company domains, and the public-source material being summarised. They do not see contracts, spend, questionnaire responses or anything you never sent us, because we never hold those.

Your data is not used to train anyone's model. That is a term of our data processing agreement and a term of our agreements with each of these providers.

All four providers keep the request and the response for up to 30 days and then delete them. Content flagged under a provider's usage policy may be retained for longer periods under that provider's terms, outside our control. This is why deletion under our data processing agreement is not instant everywhere; it is written into that agreement rather than left for you to find.

Where your data ends up, in one place

  • Your list and the alert record: Canada, on the OVH server. Backups in Canada and in Poland.
  • Company names inside a model request: United States, for up to 30 days, with the flagged-content exception above.
  • Watched companies' page addresses, and a copy of each watched page between weekly checks: United States, at Firecrawl, and page addresses, while the evaluation above runs, at Tavily. Watched businesses who are individual people are checked from our own server instead and never reach either.
  • A customer's list, at onboarding: United States, at Anthropic, for up to 30 days.
  • Watched companies' names inside a news search query: at Serper, and while the evaluation above runs, at Brave and Tavily, at query time. Watched businesses who are individual people are never searched through any of them.
  • Your alerts, once sent: your own mailbox, plus what Resend retains after delivery under its terms.
  • The message that brought us your list: the contact mailbox, whether you emailed it yourself or sent it through the watch form, which Resend relays and retains for 30 days under the same published terms that cover your alerts.
  • Your card details, if you pay by card: Stripe, and nowhere else. They are typed into a page Stripe hosts and never touch a system we run.
  • Nothing at all: inside your own systems. There is no integration and no access.

What is not on this list

Self-hosted software. The workflow and container software running on our own server is software we operate, not a company with access to your data. The sub-processor for that layer is OVH, as the provider of the server. We do not name the exact self-hosted stack in public: doing so helps an attacker and helps you not at all.

Stripe is a payment processor, and not a sub-processor of your data. It is in the table above because its absence from a page like this raises the question, and answering it here is faster than answering it by email. The distinction is a real one: for billing data Noctovisor is the controller rather than your processor, so nothing Stripe holds is held on your behalf under the data processing agreement, and your list never reaches it. The change notice below applies to it regardless.

No error monitoring or log management service. None used.

No website analytics. None installed: the site loads no code from anyone else, which you can confirm by viewing source. Analytics would concern visitors to noctovisor.com, where we are the controller rather than your processor, so it would not be a sub-processor of your data in any case.

Domain registrars. They hold our registration details, not your data. Not sub-processors.

Anything with access to your systems. There is nothing. No integration, no installed software, no API key, no VPN, no account in your tenant. No sub-processor has a path into your environment because there is no path into your environment.

When this list changes

30 days' notice by email before a sub-processor is added or replaced, published here at the same time. You can object on reasonable data protection grounds within those 30 days. If we cannot resolve the objection, you can terminate immediately without penalty and get back any fees covering the period after you leave. If a provider has to be swapped urgently for security or continuity reasons, we make the change, tell you as soon as we can and within five business days at the latest, and your right to object and leave runs from that notice instead.

This matches clause 7 of the data processing agreement, so the public commitment and the contractual term are the same thing.

To object, email contact@noctovisor.com and say what the data protection grounds are. You will get a written reply. Where we can use a different provider, or change the processing to meet the objection without disproportionate effort, we will.

What we require of every provider here

  • A written contract with data protection obligations matching what we owe you, in substance. If a provider fails, we remain fully liable to you for its performance.
  • Your data used only to provide the service to us, and nothing else.
  • No training of models on your data.
  • No pooling of your data with another customer's.
  • A lawful basis for any processing outside the EEA, recorded in the table above.

We do not audit these providers ourselves and will not pretend otherwise. What we do is pick providers whose security is independently audited, and point you at their own attestations so you can check rather than take our word:

We will also send you a provider's processing terms on request, redacted for commercial terms, where we are allowed to.

Checking this yourself

  • Each provider's certifications, on their own trust pages, linked above.
  • TLS on noctovisor.com, from any browser or command line.
  • That the site runs no analytics scripts, by viewing source.
  • Our entity: Noctovisor – Piotr Bogdanowicz, registered in Poland, REGON 146596070, EU VAT ID PL5262736443, D-U-N-S® Number 427695885, verifiable in the Polish business register, the EU VAT validation service, and the D&B database.

Ask and you will be sent: the security summary, the data processing agreement, and a redacted sample export so your audit function can read the real output rather than a description of it. Send back whatever this fails to answer and you will get a written reply.


Version 1.16, 26 August 2026. Questions and corrections to contact@noctovisor.com