Subprocessors — Return
Version: 1.1.2
Effective Date: 2026-06-02
This page lists the third-party service providers (subprocessors) that may process personal data on our behalf in connection with the Return service. It supplements our Privacy Policy and the Data Processing Agreement (DPA) we sign with business customers on request.
We use a deliberately minimal set of subprocessors. We give 30 days’ prior notice of material changes (adding or replacing a subprocessor) by email and via the Application. The authoritative, current version of this list is always at returneditor.ai/sub-processors.
For an explanation of when we act as a controller versus a processor — including the case where your documents contain third parties’ personal data — see §7 and §12 of the Privacy Policy.
Tier 1: Critical infrastructure
| Subprocessor | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Anthropic PBC | AI model inference (Claude) for Cloud Mode | Customer prompts, AI Outputs (transient, max 7-day retention) | USA | SCCs + EU-US DPF |
| Hetzner Online GmbH | Proxy server hosting | Server logs (IP, timestamp, max 7 days); ephemeral request data | Germany (Falkenstein) | Within EEA |
| Supabase Inc. | Authentication (OTP), Account database | Email addresses, Account metadata | EU region (Frankfurt); HQ USA | SCCs + Supabase DPA |
| Cloudflare, Inc. | CDN, DDoS protection, update distribution for returneditor.ai | Hashed IP, request metadata | Global PoPs; HQ USA | SCCs + Cloudflare DPA |
Tier 2: Payment and tax
| Subprocessor | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| Paddle.com Market Ltd | Merchant of Record: payment processing, subscription management, billing, sales-tax/VAT collection and remittance, customer invoicing | Customer payment tokens, billing data, transaction metadata | United Kingdom | UK adequacy decision (Commission Implementing Decision (EU) 2021/1772) + SCCs where applicable |
| inFakt sp. z o.o. | The Provider’s own accounting and Polish KSeF e-invoicing (Provider-side bookkeeping; not customer payment data) | Provider’s accounting records, payout/settlement data | Poland | Within EEA |
Note on the payment chain. As Merchant of Record, Paddle is the seller of record toward customers: Paddle charges the customer, collects and remits VAT/sales tax, and issues the purchase invoice. inFakt is used only for the Provider’s own bookkeeping and Polish e-invoicing obligations — it processes the Provider’s accounting records and Paddle settlement/payout data, and does not receive or process end-customer payment instruments or end-customer personal data. It is listed here for transparency rather than because it acts as a processor of customers’ personal data.
Tier 3: Operational
| Subprocessor | Purpose | Data | Location | Transfer mechanism |
|---|---|---|---|---|
| GitHub, Inc. (Microsoft) | Source code hosting | No customer data; only application code | USA | SCCs (Microsoft EU DPA) |
| Error tracking (if enabled) | Crash reports (only with user consent) | Anonymized stack traces, OS version | EU region preferred | Within EEA (if EU-only configuration) |
Advertising partners (website only) — not Article 28 subprocessors
This section is separate from the subprocessor tables above. It concerns the marketing website returneditor.ai only — never the desktop app, which sends nothing to any advertising platform.
When you consent to ad-conversion measurement on the website (see Privacy Policy §2.4), we forward conversion events to the following advertising partners. For Conversion API purposes these companies act as independent (or joint) controllers, not as our processors under GDPR Article 28 — so they are disclosed here as advertising partners rather than listed in the subprocessor tables above.
| Advertising partner | Purpose | Data shared (only with consent) | Location | Basis / mechanism |
|---|---|---|---|---|
| Google (Google Ireland Ltd / Google LLC) — Google Ads Conversion API | Measure conversions from Google/YouTube ad campaigns | Google click ID (gclid), event name + timestamp | EU (Google Ireland) + USA | Your consent (GDPR Art. 6(1)(a)); EU-US Data Privacy Framework for US transfers |
| Meta (Meta Platforms Ireland Ltd / Meta Platforms, Inc.) — Conversions API | Measure conversions from Facebook/Instagram ad campaigns | Meta click ID (fbclid), event name + timestamp, your IP address and User-Agent (used in-memory at forwarding time to match the event; not stored by us). No email — we do not currently forward purchases | EU (Meta Ireland) + USA | Your consent (GDPR Art. 6(1)(a)); EU-US Data Privacy Framework for US transfers |
Notes:
- Consent-gated and geo-aware. In the EU/EEA/UK (and wherever we cannot determine location) nothing is forwarded unless you opt in; elsewhere you can opt out. Withdraw any time via “Privacy choices” in the website footer — this stops all forwarding to Google and Meta, enforced server-side.
- No advertising data from the app. The desktop application has no advertising trackers and transmits nothing to Google or Meta under any circumstances.
- Controller classification (independent/joint controller vs. processor) for Conversion API is the prevailing industry position and is provided here as a disclosure; it is being confirmed with counsel and will be updated if that assessment changes.
Not subprocessors (clarification)
- Built-in local AI engine (Free mode) — bundled with the Application; runs entirely on the Customer’s computer; no data transmission. Not a subprocessor.
- Hugging Face, Inc. (model downloads) — optional local AI model files are downloaded by the Application directly from Hugging Face’s servers at the Customer’s explicit request; as with any direct download, the Customer’s IP address is visible to Hugging Face. No Content, account data, or other personal data held by us is transmitted, and Hugging Face does not process data on our behalf. Not a subprocessor.
- Apple, Microsoft, Linux distributions — OS providers; data on the Customer’s device does not pass through them in connection with our Service.
- Customer’s own infrastructure — not a subprocessor; outside our control.
Subprocessor selection criteria
Before adding a subprocessor, we verify:
- Adequate data protection guarantees under GDPR Article 28 and Article 32.
- A signed DPA with the subprocessor.
- For non-EEA subprocessors: a valid transfer mechanism (SCCs, an adequacy decision, DPF certification where applicable, supplementary measures per Schrems II).
- A no-training commitment for any AI subprocessor.
- A reasonable security posture (SOC 2, ISO 27001, or equivalent preferred).
- Compatibility with the Customer’s privilege and confidentiality requirements for legal professional use cases.
Version history:
| Version | Date | Changes |
|---|---|---|
| 1.0 | 2026-05-26 | Initial standalone Subprocessors page, extracted from Privacy Policy Appendix A. Billing tier reflects Paddle.com Market Ltd as Merchant of Record (replacing Stripe and the Stripe→inFakt bridge). |
| 1.1 | 2026-05-31 | Added “Advertising partners (website only)” section disclosing Google and Meta as independent/joint controllers for consent-gated conversion measurement on returneditor.ai (kept separate from the Article 28 subprocessor tables). Documents data shared, EU/US locations, DPF transfer mechanism, and the consent/withdrawal model. No change to the desktop app’s no-advertising guarantee. |
| 1.1.1 | 2026-06-02 | Accuracy: removed the “hashed email for a completed purchase” clause from the Meta row — purchases are not currently forwarded, so no email is sent. Mirrors Privacy Policy 2.6.3. |
| 1.1.2 | 2026-06-11 | Local-engine accuracy update: “Ollama” replaced by the built-in local AI engine (bundled llama.cpp — ADR-0007) and Hugging Face added to “Not subprocessors” as the direct, Customer-initiated source of optional local model downloads. Mirrors Privacy Policy 2.6.4. No change to actual data flows. |