Data processing
Sub-processors
Who else touches your data in the hosted deployment, and who does not.
Last reviewed 31 August 2026
Every third party that processes data on our behalf for the hosted deployment, what they do, and what reaches them. Required under GDPR Article 28, and the first thing most enterprise questionnaires ask for.
| Sub-processor | Purpose | Data involved | Location |
|---|---|---|---|
| Stripe, Inc. privacy policy | Payment processing, subscription billing and checkout. | Billing contact email, payment card details (entered on Stripe's own hosted page -- card numbers never reach our servers), subscription and invoice records. | United States |
| The Constant Company, LLC (Vultr) privacy policy | Cloud hosting and compute for the hosted deployment. | All data processed by the hosted deployment resides on infrastructure operated by this provider. | United States |
| Namecheap, Inc. privacy policy | Domain registration, DNS, and inbound email forwarding for role addresses. | Email sent to our published role addresses transits this provider. | United States |
| Let's Encrypt (Internet Security Research Group) privacy policy | TLS certificate issuance for both domains. | No customer data. Domain names appear in public certificate transparency logs. | United States |
What is deliberately not on that list
A short list is only meaningful if you say which obvious entries are missing and why.
Third-party LLM or inference provider
None. The site chatbot runs a local model on our own hardware, so a visitor's question is not sent to OpenAI, Anthropic, Google or anyone else. Agent traffic you route through the Fabric is not sent to a model provider by us either -- the Fabric decides about calls, it does not make model calls on your behalf.
Third-party analytics or advertising
None. Page analytics run on a self-hosted instance on our own infrastructure. There is no Google Analytics, no advertising pixel, and no third-party tracker on either site.
Customer support or CRM platform
None. Support runs over email and Discord; there is no third-party helpdesk holding conversation history.
The self-hosted deployment has no sub-processors at all. MCPGate runs inside your network under a perpetual licence. Neither the traffic nor the evidence reaches us, and no call has to leave your infrastructure for a decision to be made. If your data cannot go to a third party, that is the deployment for you.
Changes
We will publish a change here before a new sub-processor begins processing customer data. Customers with a signed agreement are notified directly. See also the data processing addendum and the privacy policy.