Sub-processor directory
The sub-processors rattle mng GmbH engages to provide ARCNM, each with its purpose, the data it receives, its processing location and — for third-country transfers — the Art. 46/45 GDPR safeguard. Referenced by Annex 1.2 of the Terms and § 7 of the Privacy Policy; the authoritative version is the German directory.
As at: 2026-08-20.
Hetzner Online GmbH
Category: Hosting
Purpose: Hosting of the web application, the API, the worker infrastructure and our self-operated database, cache and search services.
Data processed: All platform and connection data (in particular IP addresses, stored customer and content data).
Processing location: Falkenstein, Germany (EU) exclusively; no access from non-EU countries. ISO/IEC 27001-certified data centres.
Third-country transfer / safeguard: No third-country transfer (processing in the EU/EEA).
Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest in operating professional EU-hosted infrastructure).
Stripe Payments Europe, Ltd. (Dublin, Ireland)
Category: Payments
Purpose: Payment processing and subscription management. Payment data is collected and processed directly by Stripe; we store only references to the Stripe transaction (customer ID, subscription status, receipt numbers), never full payment data.
Data processed: Payment data (e.g. card information, SEPA data) collected directly by Stripe.
Processing location: Ireland (EU), with data flows also to the USA.
Third-country transfer / safeguard: EU Standard Contractual Clauses (Art. 46 GDPR) or — where applicable — the EU-US Data Privacy Framework (Art. 45 GDPR).
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
Sendinblue Germany GmbH („Brevo“), Berlin (parent: Sendinblue SAS, Paris)
Category: Transactional email & CRM
Purpose: Delivery of transactional emails (registration confirmations, password resets, account notifications) and — as our customer-relationship system — management of contacts, enquiries and the customer lifecycle (onboarding, product news, opt-in newsletter).
Data processed: For email: recipient address, name, message content. For the CRM: business-contact identity (name, email, company, country, language) and account engagement metadata (organisation name, plan tier, usage counts, lifecycle stage, consent status). We deliberately do NOT send billing amounts, VAT IDs, invoice/payment data, part/material/geometry data, IP addresses, or contact-form message bodies.
Processing location: Germany and France (EU); no third-country transfer.
Third-country transfer / safeguard: No third-country transfer (processing in the EU/EEA).
Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest in reliable delivery and customer management); marketing sends only on Art. 6(1)(a) consent (double opt-in).
Scaleway S.A.S. (8 rue de la Ville l'Évêque, 75008 Paris, France)
Category: AI drawing analysis (primary path)
Purpose: Automated interpretation of technical drawings (dimensions, tolerances, material and title-block data). The uploaded 2D drawing is rasterised and the drawing image (plus the analysis prompt) is sent directly to Scaleway's AI API, which runs an open-weights vision model on it in its Paris data centre. Processing serves solely the analysis performed for you.
Data processed: The rasterised drawing image and the analysis prompt (transient, for the duration of the inference).
Processing location: France (EU), Paris data centre.
Third-country transfer / safeguard: No third-country transfer (processing in the EU/EEA).
Legal basis: Art. 6(1)(b) GDPR (performance of contract) on the controller's documented instruction; Scaleway's Data Processing Agreement forms an integral part of the contract (Art. 28(9) GDPR) and excludes any use of the transmitted content to train its models.
Cloudflare, Inc. (USA; EU: Cloudflare Germany GmbH, Munich)
Category: Object storage + edge (CDN/DNS/TLS)
Purpose: Object storage (Cloudflare R2) for uploaded files (e.g. part drawings, BOMs, calculation attachments), and CDN/DNS/TLS edge proxy in front of our Hetzner origin.
Data processed: File content, file name, MIME type, hash and access metadata; as edge proxy, connection and request metadata (incl. IP address, user agent) of all page views.
Processing location: Object storage configured as an EU-jurisdiction bucket (technically restricted to EU data centres); uploaded files are additionally encrypted per object with a tenant-specific key (envelope encryption) before storage.
Third-country transfer / safeguard: As a US company, any third-country reference is safeguarded additionally by EU Standard Contractual Clauses (Art. 46 GDPR); where Cloudflare is DPF-certified, we additionally rely on Art. 45 GDPR.
Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest in resilient, cost-effective storage infrastructure).
Google LLC, GitHub, Inc. (single sign-on)
Category: Single sign-on (optional)
Purpose: Optional social login when you choose „Continue with Google/GitHub“. Unless you actively use single sign-on, no data is exchanged with these providers for this purpose. (GitHub also acts as our development tracker — see the separate entry below.)
Data processed: Only what you authorise on sign-in (e.g. email address, name, provider account ID).
Processing location: Google, GitHub: USA.
Third-country transfer / safeguard: For US providers, EU Standard Contractual Clauses (Art. 46 GDPR) and — where applicable — the EU-US Data Privacy Framework (Art. 45 GDPR).
Legal basis: Art. 6(1)(b) GDPR (performance of contract) / your consent when you use single sign-on.
Google LLC (Google Calendar appointment scheduling)
Category: Sales-call scheduling (link-out, optional)
Purpose: The optional „Book a call“ button is a plain hyperlink to a Google Calendar scheduling page. The ARCNM application transmits no data to Google; only if you click through and book a slot do you provide your details directly on Google's page, and the booking lands in our Google Calendar.
Data processed: Nothing is sent by the application. If you book, you enter with Google: name, email and preferred time.
Processing location: Google: USA.
Third-country transfer / safeguard: For this user-initiated transfer to Google (US): EU Standard Contractual Clauses (Art. 46 GDPR) and — where applicable — the EU-US Data Privacy Framework (Art. 45 GDPR).
Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps at your request) — you actively choose to schedule.
GitHub, Inc. (development tracker; a Microsoft company)
Category: Bug and error tracking
Purpose: Internal ticket for each reported fault, so it can be analysed and fixed. Only reported errors and bug reports are processed here — no calculations, drawings, orders or account data.
Data processed: Your problem description, the automatically scrubbed console excerpt, the affected page, time, app version and browser identifier, a narrowly limited technical extract from linked records, and any follow-up question and answer. Screenshots are NOT transferred (only their number); nor are uploaded files, raw stack traces or account identifiers.
Processing location: USA.
Third-country transfer / safeguard: EU-US Data Privacy Framework (Art. 45 GDPR) and EU Standard Contractual Clauses (Art. 46 GDPR) as a fallback.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in the stability and security of the platform).