In accordance with Art. 28(2) of the GDPR and the transparency commitments in our Privacy Policy and DPA, we publish the up-to-date list of subprocessors that INVERSO HUB S.R.L. uses to provide the Furx service.
Change notifications: Team / Enterprise customers receive 30 days' advance notice before a subprocessor is added or replaced, by email and via the RSS feed /subprocessors/rss.xml. The Customer may object on reasonable grounds; if the objection is not resolved, the Customer may terminate without penalty.
Active subprocessors
| Subprocessor | Purpose | Data location | DPA / SCCs |
|---|---|---|---|
| Cloudflare, Inc. | DNS, CDN, Pages hosting (public site + dashboard), TLS termination, rate limiting, WAF. | United States (HQ) + global edge locations · routing data may be replicated in EU/AR/AP regions. | DPA Yes — SCCs 2021/914 Module 2 |
| Paddle.com Market Ltd. | Merchant of Record (MoR): payment processing, invoicing, handling of EU VAT / AR taxes / US sales tax / others. | United Kingdom (HQ) + United States. | DPA Yes — SCCs 2021/914 (processor → processor) |
| GitHub, Inc. | Open-source code hosting (Apache-2.0 core), release distribution (signed binaries), Issues, Discussions. | United States. | DPA Yes — via the Microsoft DPA |
| Better Stack (BetterStack OÜ) | External status page (status.furx.cloud), uptime monitoring. | Estonia (EU) | DPA Covered (intra-EU, SCCs not required) |
| Sentry (Functional Software, Inc.) | Opt-in crash capture (default OFF). Stack trace + platform + version, PII-scrubbed. | United States + DE region selected for EU users | DPA Yes — SCCs 2021/914 Module 2 |
| Hetzner Online GmbH | Hosting of the PostgreSQL primary + standby (dashboard data, audit metadata sync, license API). | Germany (EU) | DPA Covered (intra-EU, SCCs not required) |
| Fastmail Pty Ltd. | Transactional email (magic links, invoices via Paddle relay, support). Corporate email @furx.cloud. | Australia + United States. | DPA Yes — SCCs 2021/914 Module 2 |
Data NOT processed by third parties
As a reminder, the following User data is NOT transmitted to any subprocessor (because it NEVER reaches INVERSO HUB S.R.L. infrastructure in the first place):
- Prompts sent to LLM providers.
- Responses received from LLM providers.
- API keys for LLM providers (they live in the User's OS keychain).
- The User's source code.
- The User's local audit log.
Change history
| Date | Change |
|---|---|
2026-05-27 | Initial list published (version 1.0). |
To subscribe to change notifications: RSS or email dpo@furx.cloud with the subject "Subprocessor notifications".