Guidelines for
Sub-processors

Last Updated: January 19, 2026

1. Introduction

Kertos GmbH (“Kertos”, “we”, “our” or “us”) is committed to protecting the privacy and security of customer data. To provide our services, we engage certain third-party service providers (“Sub-processors”) to process data on our behalf. We only share data to the extent necessary to deliver our services. All Sub-processors are required to maintain appropriate security measures and comply with applicable data protection laws.

2. Our Sub-processors

Amazon Web Services EMEA Sàrl

Service: Server hosting and infrastructure provider
Data Processing: Processes data necessary to provide hosting and infrastructure services
Location: Luxembourg (EU)
Website: https://aws.amazon.com

Telekom Deutschland GmbH

Service: Microsoft 365 Office suite and mail services
Data Processing: Processes communication and productivity data necessary to provide email and office services
Location: Germany (EU)
Website: https://www.telekom.de

Marker.io SRL

Service: Bug fixing and feedback collection
Data Processing: Processes feedback data, including reported issues and related technical information
Location: Belgium (EU)
Website: https://marker.io

BuiltWith Pty Ltd

Service: Tool-scan provider
Data Processing: Processes website and domain data to identify technologies used
Location: Australia
Website: https://builtwith.com

Google Ireland Limited*

Service: SSO provider and mail provider
Data Processing: Processes identity, authentication, and email service data necessary to provide SSO and mail services
Location: Ireland (EU)
Website: https://www.google.com

Microsoft Corporation*

Service: SSO provider and mail provider
Data Processing: Processes identity, authentication, and communication data necessary to provide SSO and mail services
Location: United States of America
Website: https://www.microsoft.com

Okta, Inc. / Auth0, LLC.*

Service: SSO provider
Data Processing: Processes identity and authentication data necessary to manage secure access
Location: United States of America
Website: https://www.okta.com

Product Fruits s.r.o.

Service: Customer onboarding guidance provider
Data Processing: Processes user interaction data related to onboarding and in-product guidance
Location: Czech Republic (EU)
Website: https://productfruits.com

Merge API, Inc.*

Service: Unified API provider
Data Processing: Processes data required to enable and manage API integrations with third-party services
Location: United States of America
Website: https://merge.dev

Langfuse GmbH

Service: Logging and analysis of LLM requests to improve quality
Data Processing: Processes request and usage data related to LLM interactions
Location: Germany (EU)
Website: https://langfuse.com

Microsoft Germany GmbH

Service: Provision of AI services via Azure AI Foundry
Data Processing: Processes data necessary to deliver AI-based services such as semantic search and text generation
Location: Germany (EU)
Website: https://www.microsoft.com

Google Cloud EMEA Ltd.

Service: LLM-supported search functions for chat content
Data Processing: Processes chat and query data to enable search functionality
Location: Ireland (EU)
Website: https://cloud.google.com

Datadog, Inc.

Service: Logging, performance, and error monitoring
Data Processing: Processes telemetry, performance metrics, and error data
Location: United States of America
Website: https://www.datadoghq.com

Qdrant Solutions GmbH

Service: Semantic search for documents
Data Processing: Processes document embeddings and query data for semantic search
Location: Germany (EU)
Website: https://qdrant.tech

n8n GmbH

Service: Workflow optimization
Data Processing: Processes workflow configuration and execution data
Location: Germany (EU)
Website: https://n8n.io

3. Sub-processor Requirements

Before engaging any Sub-processor, Kertos ensures that the Sub-processor:

  • Implements appropriate technical and organizational security measures to protect personal data
  • Processes personal data only in accordance with documented instructions from Kertos
  • Ensures the confidentiality of personal data and restricts access to authorized personnel only
  • Complies with applicable data protection laws and regulations, including the GDPR where applicable
  • Assists Kertos in meeting its data protection and compliance obligations
  • Applies appropriate data security measures, including encryption in transit and at rest where applicable
  • Notifies Kertos without undue delay of any personal data breaches or security incidents

4. Changes to Sub-processors

Kertos may update or change the list of Sub-processors. When a new Sub-processor is engaged that processes personal data, Kertos will:

  • Update this page with relevant information about the new Sub-processor
  • Ensure that the new Sub-processor meets Kertos’ security and privacy requirements
  • Provide notification through the Services or via email to account administrators, where required

Customers are encouraged to periodically review this page to stay informed about changes to Kertos’ Sub-processors.

5. Data Protection and Security

Kertos maintains oversight of all Sub-processors to ensure that personal data is processed in accordance with Kertos’ instructions and applicable data protection laws.

Kertos regularly reviews the security practices of its Sub-processors and requires them to maintain appropriate certifications and compliance standards relevant to the services provided.

For additional information on how Kertos protects personal data, please refer to the Privacy Policy.

6. Your Rights and Control

You retain control over your personal data at all times. Subject to applicable law, you have the right to:

  • Access your personal data processed by Kertos and its Sub-processors
  • Request correction of inaccurate or incomplete personal data
  • Request deletion of your personal data
  • Object to certain types of data processing
  • Request data portability

To exercise these rights, please contact dsb@kertos.io.

7. Contact Information

If you wish to contact us with any questions related to our Sub-processors or data processing practices, please reach out to:

Kertos GmbH
Email: dsb@kertos.io

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check