_Last reviewed: 2026-09-15_

This register describes processors Codelynx uses to operate Lumail. It is an operational disclosure, not a Data Processing Agreement. See [DPA status](/docs/legal/dpa).

Locations are configured or typical processing locations. Edge networks, support access, and provider backups may involve additional countries. Unverified facts are marked unknown.

## Current register

<DocsRegister>
  <DocsRegisterItem
    name="netcup GmbH"
    role="Application host, self-hosted Redis"
    data="App runtime, sessions, cache"
    location="Nuremberg, Germany"
    safeguards="Provider contract for hosting"
    effective="Current"
  />
  <DocsRegisterItem
    name="Neon / Databricks"
    role="PostgreSQL"
    data="Accounts, subscribers, events"
    location="AWS eu-central-1, Frankfurt"
    safeguards="Provider DPA for Codelynx's account; not a customer DPA"
    effective="Current"
  />
  <DocsRegisterItem
    name="Amazon Web Services, Inc. (SES / SNS)"
    role="Email delivery and feedback"
    data="Envelope, content, bounce/complaint"
    location="ap-southeast-2, Sydney"
    safeguards="AWS customer agreement for Codelynx; SES region is configured, not every worker inspected this review"
    effective="Current"
  />
  <DocsRegisterItem
    name="Cloudflare, Inc."
    role="DNS, CDN, R2 archives"
    data="Traffic metadata; sent-email archives"
    location="Global edge; R2 APAC placement, no EU-only jurisdiction"
    safeguards="Cloudflare terms; R2 region: auto is not residency"
    effective="Current"
  />
  <DocsRegisterItem
    name="Hatchet (self-hosted)"
    role="Background jobs"
    data="Job payloads, including email/workflow data"
    location="Nuremberg, Germany"
    safeguards="Self-hosted software, not a separate external processor"
    effective="Current"
  />
  <DocsRegisterItem
    name="Upstash (QStash)"
    role="Queue orchestration"
    data="Message metadata / payloads"
    location="EU service endpoint"
    safeguards="Provider terms; endpoint location is not a full residency guarantee"
    effective="Current"
  />
  <DocsRegisterItem
    name="PostHog, Inc."
    role="Product analytics / diagnostics"
    data="App events, may include context"
    location="PostHog Cloud EU, Frankfurt"
    safeguards="Provider EU cloud"
    effective="Current"
  />
  <DocsRegisterItem
    name="Stripe, Inc."
    role="Billing"
    data="Account billing identifiers"
    location="Global, including US and EEA"
    safeguards="Stripe DPA for Codelynx's account"
    effective="Current"
  />
  <DocsRegisterItem
    name="Telegram Messenger Inc."
    role="Operational alerts"
    data="May include a subscriber address on delivery failure"
    location="Global"
    safeguards="No Lumail-specific residency"
    effective="Current"
  />
  <DocsRegisterItem
    name="Google (Gemini / AI)"
    role="Optional AI generation"
    data="Prompts, tool results when features are used"
    location="Unknown / provider default"
    safeguards="Used only when AI features run; fallback may apply"
    effective="When used"
  />
  <DocsRegisterItem
    name="OpenAI (customer-connected)"
    role="Optional BYO assistant"
    data="Prompts when the org connects ChatGPT"
    location="Unknown / customer account"
    safeguards="Independently controlled by the customer"
    effective="When connected"
  />
  <DocsRegisterItem
    name="Tchao"
    role="Optional live support"
    data="Support conversations"
    location="Unknown"
    safeguards="Independently controlled support processor"
    effective="When enabled"
  />
  <DocsRegisterItem
    name="Umami (self-proxied /stats)"
    role="Marketing-site analytics"
    data="Page views"
    location="Same app host / configured analytics backend"
    safeguards="First-party script on public pages"
    effective="Current"
  />
</DocsRegister>

Hashed suppression and delivery-guard records are retained by Lumail after unsubscribe or lawful erasure so the same address is not emailed again.

## Self-hosted vs external

Hatchet and the Lumail application process are self-hosted on netcup. They are not separate legal subprocessors. Neon, AWS, Cloudflare, Upstash, PostHog, Stripe, Telegram, Google, OpenAI, and Tchao are external services when used.

## Change procedure

Codelynx gives customers who accept the current DPA **at least 30 days' advance written notice** before adding or replacing a subprocessor, with an objection channel at [help@codelynx.dev](mailto:help@codelynx.dev). The notice describes the provider, processing and intended start date. Customers who have not accepted the DPA should not treat the public list alone as a contractual notification mechanism.

This page will be updated when the register changes. Archived prior versions are the git history of this file until a dedicated archive is published.
