Draft for legal review. This policy is for Business Viremail and does not apply until it has been approved and published.
Sub-processors
Last updated 2 October 2026Effective 26 September 2026
Who processes data for us
These companies process personal data for Viremail when it is needed to provide the service. Mail, files and account data are stored on servers we run with our hosting provider, in France (EU) and the United Kingdom.
| Company | What for | Where | What data |
|---|---|---|---|
| Contabo GmbH | Hosting: the servers that run the app, its database and the mail server | France (EU) and the United Kingdom | All service data |
| Cloudflare, Inc. | DNS, network protection and content delivery, and TLS certificates for the custom domains of business pages (Cloudflare for SaaS) | Worldwide network; the company is in the United States | Connection data such as IP addresses, and the pages and files passing through |
| Stripe Payments Europe, Ltd. and Stripe, Inc. | Payments, invoices and tax for the Business plans we sell. For payment data Stripe is an independent controller | Ireland, the United States and other countries | Billing contact, company details, tax ID and payment details (card data goes to Stripe, never to us) |
| GitHub, Inc. | Hosting the desktop app downloads | United States | The IP address and browser details of whoever downloads the app |
| Anthropic, PBC | AI features (Piccolo and Fix with AI), only when someone uses them. Not used to train AI models | United States | The question or the text someone chose, and what Piccolo reads for it, such as an email or a page they asked about |
| OpenAI, L.L.C. | AI features, only for people who choose ChatGPT in Settings and only when they use them. Not used to train AI models | United States | The question or the text someone chose, and what Piccolo reads for it |
| KLIPY | GIF search in Vire, only where it is switched on | [To be confirmed] | The words searched for, a country code and an anonymous ID; never names or email addresses |
Services you choose yourself
AI apps you connect, such as Claude or ChatGPT, and other mail providers you write to or import from, are not our sub-processors: you or your users choose to send data to them, under their own terms.
The same goes for the accounts a business connects to its own features: a Stripe or Razorpay account to take payments on the invoices it sends from Billing, and a Facebook Page for lead ads. The business chooses them and has its own agreement with them. Stripe also appears in the list above, but only for the plans we sell to businesses.
| Service | What for | What we send or receive |
|---|---|---|
| Stripe | Card and other payments for a business’s own invoices, through the business’s own Stripe account | The invoice number, amount and currency, and the customer’s email address |
| Razorpay | Payments for a business’s own invoices in India, through the business’s own Razorpay account | The invoice number, amount and currency, and the customer’s email address |
| Meta (Facebook and Instagram) | Lead ads: leads a business’s own Facebook Page sends to Leads, once it connects that Page | Leads arrive from Meta; we send Meta nothing about your customers |
Changes to this list
We email the owner of every business at least 30 days before we add or replace a sub-processor, and update this page. Anyone else who wants to hear about changes can ask us at [email protected]. How a business can object is in our Data Processing Addendum.