This page lists the third parties that process personal data on behalf of AutomateSEO. It is referenced by our Privacy Policy and forms Annex 2 of our Data Processing Agreement.
We keep this list current. To be notified before we add or replace a subprocessor, email privacy@automateseo.app with the subject "Subprocessor notifications" and we will add you to the notification list (see "Changes" at the end of this page).
1. Core infrastructure
These subprocessors are used for every customer.
| Subprocessor | Entity and location | What it does | Data it may process | Transfer safeguard |
|---|---|---|---|---|
| Supabase | Supabase, Inc. (USA), hosting on AWS in eu-west-1 (Ireland), within the EEA | Primary database, authentication, file storage | Account details, business profiles, all article and media records, connection metadata, encrypted credentials | Standard Contractual Clauses / UK Addendum |
| Cloudflare | Cloudflare, Inc. (USA) and Cloudflare Ltd (UK) | Application hosting (Pages), edge compute (Workers), object storage (R2), image delivery, CDN, DDoS protection | All data in transit; generated images, audio and video at rest in R2; IP addresses in edge logs | Standard Contractual Clauses / UK Addendum |
| n8n | n8n GmbH, Berlin, Germany (EU) — n8n Cloud, EU-hosted | Orchestrates content generation, publishing and media workflows | Article briefs, business profile context, generated content, callback payloads | Within EEA — no transfer safeguard required |
| Stripe | Stripe Payments Europe, Ltd. (Ireland), with Stripe, Inc. (USA) | Payment processing, subscription billing, invoicing | Name, email, billing address, card token, transaction history. We never receive full card numbers. | Stripe acts as an independent controller for payment data; SCCs apply to onward transfers |
| Resend | Resend, Inc. (USA) | Transactional email (account, billing, job notifications) | Email address, name, message content | Standard Contractual Clauses / UK Addendum |
2. AI model providers
These process the prompts, business context and research data needed to generate your content. None of them are permitted to train their models on your data — we use their API tiers, under which customer data is excluded from training by default.
| Subprocessor | Entity and location | What it does | Data it may process | Transfer safeguard |
|---|---|---|---|---|
| Anthropic | Anthropic PBC (USA) | Article writing, outlining, editing, agent reasoning | Prompts containing your business profile, brand voice, keywords, research material and draft content | Standard Contractual Clauses / UK Addendum. Zero data retention / no-training terms apply to API use. |
| OpenAI | OpenAI, L.L.C. / OpenAI Ireland Ltd | Article generation, embeddings, image generation, analysis | As above, plus image prompts | Standard Contractual Clauses / UK Addendum. API data is not used for training. |
| KIE.ai | NexusAI Services LLC (Colorado, USA) | Video generation (short-form and long-form), model routing | Video prompts, reference images you upload, generated video | Standard Contractual Clauses / UK Addendum |
| HeyGen | HeyGen, Inc. (USA) | AI avatar and spokesperson video | Spokesperson images and voice samples you upload, scripts, generated video | Standard Contractual Clauses / UK Addendum. Biometric-adjacent data — see the note below. |
Note on likeness and voice. Avatar and spokesperson features send an image and/or voice sample to HeyGen and, for some video features, to KIE.ai. If that likeness or voice belongs to a real person, you must have their documented consent before uploading it. In the UK and EU this may constitute special category data requiring explicit consent. See clause 7 of the Terms of Service.
3. Data and research providers
| Subprocessor | Entity and location | What it does | Data it may process | Transfer safeguard |
|---|---|---|---|---|
| DataForSEO | DataForSEO OÜ, company no. 14502291, Estonia (EU) | Keyword research, search volume, SERP data, backlink and competitor data, rank tracking | Your keywords, target domains and competitor domains. No customer personal data is sent. | Within EEA — no transfer safeguard required |
| Google Ireland Limited / Google LLC | Search Console data, Indexing API submissions, YouTube data, Google Business Profile posting — only for properties you connect | OAuth tokens, site and property identifiers, performance metrics, post content | Standard Contractual Clauses / UK Addendum |
4. Customer-directed integrations
These are platforms you choose to connect. When you authorise a connection, you are directing us to send your content and credentials to that platform. Each acts as an independent controller of the data once it arrives, under its own terms and privacy policy. We only hold the encrypted access token and the metadata needed to publish.
| Platform | Provider | What we send when you connect it |
|---|---|---|
| GitHub | GitHub, Inc. (Microsoft) | Article files committed to the repository you nominate |
| WordPress | Your own WordPress host | Article content, media, categories and tags via the REST API |
| Facebook / Instagram / Threads | Meta Platforms, Inc. / Meta Platforms Ireland Ltd | Page and account identifiers, post content, media, comment data |
| LinkedIn Ireland Unlimited Company (Microsoft) | Profile or page identifier, post content, media | |
| Google Business Profile | Google Ireland Limited | Location identifier, post content, media |
| YouTube | Google Ireland Limited | Channel identifier, video metadata |
| Custom webhooks | Whoever you point them at | Whatever payload you configure. You are responsible for the security of any endpoint you nominate. |
You can revoke any of these connections at any time in Settings, which deletes the stored token from our systems.
5. What we do NOT use
For clarity, AutomateSEO does not use:
- third-party advertising networks or advertising pixels;
- third-party analytics or session-recording tools (no Google Analytics, no Meta Pixel, no Hotjar, no PostHog, no Mixpanel);
- data brokers or enrichment providers;
- any subprocessor that sells personal data.
We do not sell or share personal data for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act.
6. Due diligence
Before engaging a subprocessor we assess its security posture, data location, retention and deletion practices, sub-processing chain, and training-data terms for AI providers. We put a written data processing agreement in place with each subprocessor imposing obligations no less protective than those in our own DPA, including the required international transfer safeguards.
7. Changes to this list
We will give 30 days' notice before adding or replacing a subprocessor that processes customer personal data, by updating this page and emailing customers on the subprocessor notification list.
If you are a business customer and you have a reasonable, documented data protection objection to a new subprocessor, tell us within those 30 days at privacy@automateseo.app. We will work with you to find an alternative; if we cannot, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid, unused amounts.
We may add a subprocessor immediately, with notice as soon as practicable afterwards, where required to address an urgent security or availability issue.
Last reviewed: 26 July 2026.