Legal

Sub-processors

Version: 1.0  ·  Effective date: 7 October 2026  ·  Last updated: 7 October 2026

About this list

This page lists the third parties that Smart Unlimited Holding B.V. (trading as AnyForge) ("AnyForge") engages to process Customer Data, as referred to in Section 7 and Annex III of our Data Processing Addendum and Section 7 of our Privacy Policy. It also lists, separately, the AI providers and other services that customers connect themselves, which are not AnyForge sub-processors.

Changes. Before a new sub-processor begins processing Customer Personal Data, we update this page and email the owners of every customer organization at least 30 days in advance, as described in Section 7.2 of the DPA. Customers may object on reasonable data protection grounds within that period. Questions or objections: privacy@anyforge.ai.

Sub-processors engaged by AnyForge

AnyForge engages these providers on its own account. They act on our instructions under written data protection terms.

Sub-processors engaged by AnyForge
ProviderPurposeDataLocationIn use
Google Cloud and Firebase (Google LLC)
Data terms
Hosting and infrastructure: database (Firestore), file storage, application hosting, Cloud Functions and Cloud Run compute, task queues, secret storage, logging, analytics warehouse (BigQuery) and sign-in (Firebase Authentication).All Customer Data stored in or processed by the Service; Account data (name, email address, sign-in records); Provider credentials (encrypted in Secret Manager); Logs and usage dataEuropean Union: Netherlands (europe-west4) and the eur3 multi-region (Netherlands and Belgium); task queues in Belgium (europe-west1). Firebase Authentication is a global Google service.Always
Google Cloud Vertex AI (Google LLC)
Data terms
Text embeddings (model text-embedding-004) that power semantic search: AnyForge converts text into numeric vectors so the Oracle, crews and search can find relevant code, documentation and library documents. Runs on AnyForge's own Google Cloud account, not a customer key. Not used to train models.Source code from connected repositories (in chunks); Codebase analysis documentation; Context Library documents, including meeting summaries and transcripts a user shares to it; Search queries typed in the Oracle and in searchNetherlands (europe-west4)When a repository is analysed or indexed, a Context Library document is added, or a semantic search runs
Google Cloud Speech-to-Text (Google LLC)
Data terms
Live transcription of Google Meet audio for the Meeting Assistant. The audio is not stored by AnyForge.Meeting audio, including the voices of everyone in the call; The resulting transcript textEuropean Union (eu multi-region)Only when an organization turns on the Meeting Assistant and a user starts audio capture
Google Analytics (Google LLC)
Data terms
Website and product usage analytics (page views and visits). Not loaded on shared-link pages.Pages visited; Device and browser information; IP address (used by Google to derive approximate location); Analytics cookie identifiersUnited States and other Google locationsAlways
PostHog
Data terms
Product analytics: a small number of server-side product events (for example, that a crew was started). In-browser PostHog analytics is currently switched off.User and company identifiers; Product event names and propertiesEuropean Union (PostHog EU cloud)Always
Stripe
Data terms
Subscription billing and payment processing for AnyForge plans.Billing contact details; Company billing details; Payment card data (held by Stripe, never by AnyForge); Subscription and invoice recordsUnited States and other Stripe locationsWhen an organization subscribes to a paid plan
Resend
Data terms
Transactional email (invitations, notifications, digests) and receiving email sent to an organization's AnyForge intake address.Recipient and sender email addresses and names; Email content, including the text and attachments of emails sent to an intake addressUnited StatesTransactional email always; email intake only when an organization turns it on
WhatsApp Business Platform (Meta)
Data terms
The WhatsApp channel to the Oracle: messages a user sends to AnyForge's WhatsApp number and the replies.Phone number and WhatsApp profile name; Message content and media the user sends; Replies sent by the OracleMeta locations, including the United States and IrelandOnly when a user links WhatsApp and messages the AnyForge number
Discord
Data terms
AnyForge's community server: optional membership linking for the community request board, and announcements of shipped bug reports and feature requests users submitted to AnyForge.Discord user id and guild membership (when a user links Discord); Title and summary of feedback a user submitted to AnyForgeUnited StatesOnly when a user links Discord, or submits feedback to AnyForge that later ships
StackBlitz WebContainers
Data terms
The in-browser terminal in Code Studio. The runtime is loaded from StackBlitz into the user's browser and package installs run through StackBlitz's infrastructure.IP address and browser information; Names of packages installed from the terminalUnited StatesOnly when a user opens the Code Studio terminal

Providers you connect

These providers receive data only when your organization connects them with its own key, account or installation, and only the data your configuration routes to them. Under Section 8 of the DPA they are engaged by you, under your own agreement with them, and are not AnyForge sub-processors.

Providers customers connect
ProviderPurposeDataLocationIn use
Anthropic
Data terms
Claude models for the Oracle, crews, Code Studio, triage and analysis, on the customer's own Anthropic API key or Claude subscription.Prompts, code and content the customer routes to the model; Model outputsAs set in the customer's Anthropic accountWhen the customer connects an Anthropic key or subscription
OpenAI
Data terms
OpenAI models, on the customer's own OpenAI API key.Prompts, code and content the customer routes to the model; Model outputsAs set in the customer's OpenAI accountWhen the customer connects an OpenAI key
Google AI Studio (Gemini API)
Data terms
Gemini models, on the customer's own Google AI Studio key.Prompts, code and content the customer routes to the model; Model outputsAs set in the customer's Google accountWhen the customer connects a Google AI Studio key
Google Cloud Vertex AI (customer project)
Data terms
Claude models served from the customer's own Google Cloud project, with the customer's service account.Prompts, code and content the customer routes to the model; Model outputsThe region the customer choosesWhen the customer connects a Vertex AI service account
Amazon Bedrock (Amazon Web Services)
Data terms
Claude and other models served from the customer's own AWS account.Prompts, code and content the customer routes to the model; Model outputsThe AWS region the customer choosesWhen the customer connects AWS Bedrock credentials
OpenRouter
Data terms
Access to models from many vendors through one API, on the customer's own OpenRouter key.Prompts, code and content the customer routes to the model; Model outputsUnited States; the serving model vendor depends on the model the customer picksWhen the customer connects an OpenRouter key
Z.ai (Zhipu AI)
Data terms
GLM models, on the customer's own Z.ai or BigModel key.Prompts, code and content the customer routes to the model; Model outputsAs set by the endpoint the customer chooses (Z.ai international or BigModel, China)When the customer connects a Z.ai key
DeepSeek
Data terms
DeepSeek models, on the customer's own DeepSeek key.Prompts, code and content the customer routes to the model; Model outputsChinaWhen the customer connects a DeepSeek key
Baseten
Data terms
Models hosted in the customer's own Baseten account.Prompts, code and content the customer routes to the model; Model outputsAs set in the customer's Baseten accountWhen the customer connects a Baseten key
TypeSafe
Data terms
Independent second-opinion checks on selected crew decisions, on the customer's own TypeSafe key.The crew decision being checked and its context; The verdict returnedAs set in the customer's TypeSafe accountWhen the customer connects a TypeSafe key
Self-hosted model endpointsA model server the customer runs itself (an OpenAI-compatible endpoint such as vLLM).Prompts, code and content the customer routes to the model; Model outputsWherever the customer hosts itWhen the customer registers its own endpoint
GitHub
Data terms
Reading and writing the customer's repositories, pull requests and reviews, through the AnyForge GitHub App installed by the customer and its operators' own GitHub sign-in.Source code and repository metadata; Pull requests, reviews and comments; GitHub usernamesAs set in the customer's GitHub accountWhen the customer installs the GitHub App or an operator connects GitHub
Slack
Data terms
The Oracle, triage and notifications in the customer's Slack workspace.Messages and files in channels and threads where AnyForge is used; Slack user names and idsAs set in the customer's Slack workspaceWhen the customer installs the AnyForge Slack app
Microsoft Teams
Data terms
Approval and halt notifications posted to a Teams channel through an incoming webhook the customer creates.Notification text: crew, work item and approval names and statusAs set in the customer's Microsoft 365 tenantWhen the customer adds a Teams webhook
Sign-in identity providersSigning in with Google, Microsoft, GitHub or the customer's own SAML or OIDC provider.Name, email address and the identifier the provider sharesAs set by the identity providerWhen a user signs in with that provider
Atlassian (Jira and Confluence)
Data terms
Reading and updating the customer's Jira issues and Confluence pages through the Atlassian connector.Issues, pages and comments the connector reads or writesAs set in the customer's Atlassian siteWhen the customer connects Atlassian
Linear
Data terms
Syncing work items with the customer's Linear workspace.Issues, projects and comments that are syncedAs set in the customer's Linear workspaceWhen the customer connects Linear
Zendesk
Data terms
Help desk intake: filing tagged tickets as requests and adding completion notes.Ticket content and requester name and emailAs set in the customer's Zendesk accountWhen the customer connects Zendesk intake
Intercom
Data terms
Help desk intake: conversations the customer's Intercom workspace sends to AnyForge.Conversation content and requester name and emailAs set in the customer's Intercom workspaceWhen the customer connects Intercom intake
Datadog
Data terms
Reading monitors, logs and traces for investigations, and receiving alerts.Alerts, logs, traces and metrics the customer's Datadog account returnsAs set in the customer's Datadog siteWhen the customer connects Datadog
Sentry
Data terms
Receiving error alerts the customer's Sentry account sends to AnyForge.Error titles, stack locations and alert metadataAs set in the customer's Sentry accountWhen the customer points a Sentry alert at AnyForge
Aikido Security
Data terms
Reading the customer's security findings.Security findings for the customer's repositoriesAs set in the customer's Aikido accountWhen the customer adds an Aikido token
Vanta
Data terms
Reading the customer's compliance tests and evidence.Compliance controls, tests and evidence statusAs set in the customer's Vanta accountWhen the customer adds a Vanta credential
Amazon Web Services (customer account)
Data terms
Reading cost data and fetching private packages (CodeArtifact) from the customer's own AWS account.Cost and usage figures; Package names and versionsThe AWS region the customer choosesWhen the customer adds AWS credentials
Stripe (customer account)
Data terms
Reading revenue figures from the customer's own Stripe account for business-value reporting.Revenue and subscription figuresAs set in the customer's Stripe accountWhen the customer adds a Stripe key
Snowflake
Data terms
Read-only queries against the customer's Snowflake warehouse.Query results the customer's warehouse returnsAs set in the customer's Snowflake accountWhen the customer adds Snowflake credentials
Databricks
Data terms
Read-only queries against the customer's Databricks workspace.Query results the customer's workspace returnsAs set in the customer's Databricks workspaceWhen the customer adds Databricks credentials
Temporal Cloud
Data terms
Reading workflow status from the customer's Temporal Cloud namespace.Workflow names, status and historyAs set in the customer's Temporal Cloud accountWhen the customer adds Temporal credentials
Harness
Data terms
Reading pipelines and deployments from the customer's Harness account.Pipeline, deployment and service metadataAs set in the customer's Harness accountWhen the customer adds a Harness token
Source-code escrow agent (SFTP)Delivering source-code escrow deposits to the SFTP server of the escrow agent the customer appoints.Source code and build documentation in the depositWherever the escrow agent hosts itWhen the customer configures escrow deliveries

Your organization can also connect other tools through MCP servers it adds itself. Data goes to those servers only as your configuration directs.