Sub-processor List - FragonForge
This list supports the Privacy Policy and the DPA. A sub-processor is a third party the Provider (Fragon Studios e.U.) engages to process personal data on behalf of Customers.
Last updated: 2026-07-25
How to read this list
- Confirmed means the row is in production and verified against the product facts. Every row on this list is confirmed today; the column exists so that a planned addition can be shown as such rather than appear without warning, and any addition is announced 30 days in advance under clause 8.2 of the DPA.
- Which rows apply depends on how the Customer runs the agent. On FragonForge AI, the model gateway below is a sub-processor. On bring-your-own-key or a ChatGPT seat, the Customer's LLM provider is not a sub-processor; that case is set out separately at the end, with the reason.
Sub-processors
| Sub-processor | Location | Service / purpose | Data categories | Status |
|---|---|---|---|---|
| Hetzner Online GmbH | Germany (EU) | Hosting and infrastructure: compute for the platform and sandboxes, and EU object storage for point-in-time-recovery database backups | All platform data at rest and in processing, including account data, encrypted tokens, repository metadata, run logs, and code-index data | Confirmed |
| Stripe | Ireland (EU); see transfer note below | Payment processing: paid plans are billed through Stripe; card data is handled by Stripe, not stored by us | Billing contact and subscription identifiers; card data held by Stripe | Confirmed |
| Microsoft Ireland Operations Limited | European Union (data at rest in Austria; Microsoft EU Data Boundary) | Email delivery via Microsoft 365 / Exchange Online (Microsoft Graph): account and notification emails, which never contain repository content | Recipient email address and message metadata; no repository content | Confirmed |
| OpenRouter, Inc. | United States (corporate domicile); requests processed via the EU endpoint eu.openrouter.ai | Model gateway for FragonForge AI runs only: routes prompts to the models in the curated catalog that are reached through the gateway. Not involved in bring-your-own-key or ChatGPT-seat runs | Prompt and response content of those runs, in transit; token counts and the computed cost | Confirmed |
Note on Stripe: the contracting entity for EU customers is Stripe Payments Europe, Ltd., Ireland. Transfers to Stripe, Inc. (USA) may occur under the EU-US Data Privacy Framework and Standard Contractual Clauses, as set out in Stripe's own data processing agreement.
Note on Microsoft (email delivery): account and notification emails are sent through Microsoft 365 (Exchange Online) via the Microsoft Graph API. The contracting entity for the EEA is Microsoft Ireland Operations Limited, and the tenant's data at rest is committed to the European Union under the Microsoft EU Data Boundary (current storage in Austria). No repository content is ever included in these emails.
Note on the FragonForge AI model path: the curated catalog is served one way, through the OpenRouter gateway, with requests routed via eu.openrouter.ai. Zero data retention is set on the account and asserted per request, data collection is denied per request, and each catalog model is pinned to its allowed providers. These fields are injected server-side at the point the request is made, rather than left to configuration.
Worth being precise about what that does and does not give you. The EU endpoint keeps the processing of these requests in the EU, but OpenRouter, Inc. is a US company, so zero data retention and denied data collection are contractual and technical controls rather than a change of jurisdiction. There is no second path today that would be EU by domicile as well: if your procurement rules turn on jurisdiction rather than on processing location, this is the point to look at, and the answer available to you today is to point the agent at an EU provider of your own choosing with your own key, which takes us out of that chain entirely.
On that path FragonForge records token counts, the model, the run it belongs to, and the resulting cost in order to meter the budget. It does not log or persist prompt or response bodies. That row does not apply at all if you run on your own key or a ChatGPT seat.
Not a sub-processor: your own LLM provider
If you run on your own API key or a ChatGPT seat, the LLM provider you chose (for example Anthropic, OpenAI, Google, OpenRouter, Mistral, Groq, DeepSeek, or any OpenAI-compatible endpoint) is not a sub-processor of Fragon Studios e.U.
- That path is bring-your-own-key: the Customer configures its own API key and contracts directly with the LLM provider.
- The agent's model calls are forwarded through an egress proxy that does not log or persist request or response bodies. The Customer's own contract with the provider governs that data, and the provider's logs and bill are the complete record.
- The LLM provider is therefore a recipient chosen and contracted by the Customer as controller, not a processor engaged by us.
Change notification
We maintain this list and notify Customers at least 30 days in advance of any addition or replacement of a sub-processor, giving the opportunity to object on reasonable data protection grounds before the change takes effect, as set out in the DPA, clause 8.