Subprocessors

Current Lumail infrastructure providers, roles, locations, and change process

Last reviewed: 2026-09-15

This register describes processors Codelynx uses to operate Lumail. It is an operational disclosure, not a Data Processing Agreement. See DPA status.

Locations are configured or typical processing locations. Edge networks, support access, and provider backups may involve additional countries. Unverified facts are marked unknown.

Current register

netcup GmbH

Current

Application host, self-hosted Redis

Data
App runtime, sessions, cache
Location
Nuremberg, Germany
Safeguards
Provider contract for hosting

Neon / Databricks

Current

PostgreSQL

Data
Accounts, subscribers, events
Location
AWS eu-central-1, Frankfurt
Safeguards
Provider DPA for Codelynx's account; not a customer DPA

Amazon Web Services, Inc. (SES / SNS)

Current

Email delivery and feedback

Data
Envelope, content, bounce/complaint
Location
ap-southeast-2, Sydney
Safeguards
AWS customer agreement for Codelynx; SES region is configured, not every worker inspected this review

Cloudflare, Inc.

Current

DNS, CDN, R2 archives

Data
Traffic metadata; sent-email archives
Location
Global edge; R2 APAC placement, no EU-only jurisdiction
Safeguards
Cloudflare terms; R2 region: auto is not residency

Hatchet (self-hosted)

Current

Background jobs

Data
Job payloads, including email/workflow data
Location
Nuremberg, Germany
Safeguards
Self-hosted software, not a separate external processor

Upstash (QStash)

Current

Queue orchestration

Data
Message metadata / payloads
Location
EU service endpoint
Safeguards
Provider terms; endpoint location is not a full residency guarantee

PostHog, Inc.

Current

Product analytics / diagnostics

Data
App events, may include context
Location
PostHog Cloud EU, Frankfurt
Safeguards
Provider EU cloud

Stripe, Inc.

Current

Billing

Data
Account billing identifiers
Location
Global, including US and EEA
Safeguards
Stripe DPA for Codelynx's account

Telegram Messenger Inc.

Current

Operational alerts

Data
May include a subscriber address on delivery failure
Location
Global
Safeguards
No Lumail-specific residency

Google (Gemini / AI)

When used

Optional AI generation

Data
Prompts, tool results when features are used
Location
Unknown / provider default
Safeguards
Used only when AI features run; fallback may apply

OpenAI (customer-connected)

When connected

Optional BYO assistant

Data
Prompts when the org connects ChatGPT
Location
Unknown / customer account
Safeguards
Independently controlled by the customer

Tchao

When enabled

Optional live support

Data
Support conversations
Location
Unknown
Safeguards
Independently controlled support processor

Umami (self-proxied /stats)

Current

Marketing-site analytics

Data
Page views
Location
Same app host / configured analytics backend
Safeguards
First-party script on public pages

Hashed suppression and delivery-guard records are retained by Lumail after unsubscribe or lawful erasure so the same address is not emailed again.

Self-hosted vs external

Hatchet and the Lumail application process are self-hosted on netcup. They are not separate legal subprocessors. Neon, AWS, Cloudflare, Upstash, PostHog, Stripe, Telegram, Google, OpenAI, and Tchao are external services when used.

Change procedure

Codelynx gives customers who accept the current DPA at least 30 days' advance written notice before adding or replacing a subprocessor, with an objection channel at [email protected]. The notice describes the provider, processing and intended start date. Customers who have not accepted the DPA should not treat the public list alone as a contractual notification mechanism.

This page will be updated when the register changes. Archived prior versions are the git history of this file until a dedicated archive is published.