Skip to content

Sub-processors

Last updated: 2026-09-16. Every third party that processes data on our behalf, and nothing else.

1. What this page is

A sub-processor is a third party that processes personal data on our behalf, because we use its service to run Chartosaurus. This page lists all of them. It is not a sample and not a "such as" list — if a company is not named here, it does not process personal data for us.

We keep this page current. Before we add a sub-processor, we will email you and show an in-app notice at least 30 days before it takes effect, which is the same notice rule as section 13 of the Privacy Policy.

Chartosaurus is built and operated by one person from Indonesia. That is relevant to section 4, so it is worth saying here.

2. Contabo — hosting and database

What it is used for: Contabo provides the virtual private server that runs the Chartosaurus application. PostgreSQL runs in Docker on that same server and is managed by us — it is not a managed database service, so nobody at Contabo administers the database itself. The backups described in section 10 of the Privacy Policy are taken by us on that same server, not by Contabo.

What it receives: everything listed in section 2 of the Privacy Policy — your email address, hashed password, session records, encrypted data source tokens, charts and dashboards, billing records and the audit log. Contabo is the infrastructure underneath all of it.

Where it processes it: Germany. The server, the PostgreSQL database on it and the cached Notion rows written to its filesystem are all in a Contabo data centre in Germany, which puts the data listed above at rest inside the EEA. See section 9 for what that does and does not settle about international transfers.

3. Creem — payments

What it is used for: Creem is the merchant of record for every paid plan. It runs checkout and the billing portal, manages subscriptions, issues invoices and handles sales tax and VAT.

What it receives: your email address, your card details entered directly into its own hosted checkout, and whatever billing address it needs for tax. Card data never reaches our servers. What comes back to us is a customer ID, a subscription ID, a plan and a status.

Where it processes it: under Creem's own published terms and privacy notice. We do not choose its processing location.

4. Resend — transactional email

What it is used for: two emails and no others — address verification when you sign up, and the password reset link when you ask for one. We send no marketing email, so there is no list and nothing to unsubscribe from.

What it receives: your email address and the contents of that message, which includes a single-use token in a link.

Where it processes it: under Resend's own published terms and sub-processor list.

5. Sentry — error and performance monitoring

What it is used for: runtime errors and a sample of performance traces, so crashes get found and fixed.

What it receives: error events and traces. Sentry's "send default PII" option is switched off, so IP addresses and request bodies are not attached. Every outbound event passes through a scrubber that redacts embed tokens, share tokens and password-reset tokens. An event can still incidentally contain a user ID or a database ID inside a stack trace, so we list Sentry as a sub-processor rather than pretend it never sees personal data.

Where it processes it: under Sentry's own published terms and sub-processor list.

6. Upstash Redis — rate limiting

What it is used for: counting requests to sign-up, sign-in, password reset and embed endpoints so they can be rate limited.

What it receives: the requesting IP address, as part of a counter key, and a number. It holds no account data, no email addresses and no content.

Where it processes it: under Upstash's own published terms.

7. There is no AI provider on this list

We do not send your data to any large language model provider, and there is no AI processing of your Notion rows, your CSV contents or your account data anywhere in the stack. We are not listing one as "coming soon" either. If that ever changes, it becomes a new sub-processor and gets the 30 days' notice described in section 1.

8. Notion is not our sub-processor

Reviewers ask about this, so here is the distinction. A sub-processor is a service we chose and engaged to process your data for us. Notion is the opposite: it is your service, holding your data, and you connect it to Chartosaurus by granting us access through an OAuth flow you control. A CSV you upload is the same in kind — your file, handed to us by you.

We are the recipient of that data, not the processor sending it somewhere. Your relationship with Notion is governed by your own agreement with them, not by ours. You can end our access at any time from inside Notion — Settings then Connections then remove Chartosaurus.

Practically: if your legal team needs a data processing agreement covering Notion, they need it from Notion. We cannot sign one on Notion's behalf, and listing Notion here would imply a control over it that we do not have.

9. International transfers

Start with where the data actually is. Everything in section 2 of the Privacy Policy is at rest on the Contabo server in Germany — inside the EEA. That is the bulk of what we hold, and it does not move.

What crosses a border is access rather than storage. We operate from Indonesia, which has no EU adequacy decision, and the one person who administers that server reaches it remotely from there. Under the GDPR that remote access counts as a transfer, so it still needs a safeguard even though the database never leaves Germany.

The remaining providers on this list — Creem, Resend, Sentry and Upstash — process in their own locations, which we do not choose. Those are transfers in the ordinary sense, including for data belonging to people in the EU and the UK.

Where our providers offer Standard Contractual Clauses in their data processing agreements, we rely on those clauses. Be aware of what that means in practice for a one-person company: these are the providers' own published DPAs and SCCs, accepted by us as a customer — not clauses negotiated individually, and not a transfer impact assessment produced by a law firm.

We have not obtained an adequacy decision, binding corporate rules or any certification, and we are not going to claim otherwise. If your organisation requires a signed DPA or SCCs directly with us before you can use Chartosaurus, email support@chartosaurus.com and say so — we would rather have that conversation than have you assume paperwork exists that does not.

10. Changes and notice

The last-updated date at the top of this page changes whenever this list does.

Adding a sub-processor is a material change to the Privacy Policy. We will email you and show an in-app notice at least 30 days before the new provider starts processing. If you object, you can cancel before it takes effect and we will refund the unused part of your term, as described in section 6 of the Refund Policy.

Removing a sub-processor, or narrowing what one receives, takes effect immediately and needs no notice.

11. Contact

Email support@chartosaurus.com for anything on this page: a vendor review question, a request for a data processing agreement, or a correction if something here is out of date. One person reads that inbox and answers within two business days.

For a suspected vulnerability, use the same address and read Security first for what to include.