Subprocessors
The German version is authoritative.
Annex 3 to the Data Processing Agreement — list of subprocessors engaged by roleALPHA GmbH pursuant to Art. 28(2) and (4) GDPR
Language note: This is a translation for information purposes. In the event of any discrepancy, the German version prevails.
Version applicable at the time. This list is published at
https://rolealpha.com/en/legal/subprocessors. The version published there is the one that
applies; an update under section 6 is not an amendment to the contract.
1. Purpose and binding nature of this list
This list names every service provider that processes personal data of our customers on behalf of roleALPHA GmbH. By accepting the Terms of Service, the Customer grants general authorisation for the engagement of the subprocessors listed here (section 5 of the DPA).
The list is versioned. Every change receives a new version, a new date and an entry in the change history (section 7).
2. Hosting by netcup
netcup GmbH, Emmy-Noether-Strasse 10, 76131 Karlsruhe, Germany.
Service: operation of the server infrastructure, the databases, the network connection and the backups — for the Core in all models M1 to M3 and for the Data Nodes operated by roleALPHA in model M1.
Data concerned: all data processed in the platform on behalf of the Customer under Annex 1 of the DPA, at rest and in processing.
Seat of the operator: Germany. Server location: Vienna, Austria. Location of the backups: ⟨TODO: country and, where applicable, site to be confirmed by netcup⟩.
Contract: data processing agreement pursuant to Art. 28 GDPR, concluded on 23 August 2026 (customer number 415167).
netcup's own subprocessors: Anexia Holding GmbH and Anexia Cloud Solutions GmbH, each at Feldkirchner Strasse 140, 9020 Klagenfurt, Austria, as well as Anexia Cloud Solutions GmbH, Emmy-Noether-Strasse 10, 76131 Karlsruhe, Germany — infrastructure services in the data centre environment and provision of personnel.
Third country: no third-country transfer; all of the above places of processing are located in Germany and Austria.
3. Further subprocessors engaged on a permanent basis
These service providers are engaged for the operation of the platform in all operating models.
| Provider | Service and data concerned | Places of processing | Third-country transfer | Condition of engagement |
|---|---|---|---|---|
| Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland (group: Microsoft Corporation) | dispatch of system and notification e-mails (invitations, password resets, operational messages, domain notifications) via the Microsoft Graph interface (graph.microsoft.com, sign-in via login.microsoftonline.com); e-mail address, name, content of the message |
EU/EEA — data centre region of the provider's Microsoft 365 tenant | none within the EU/EEA; for support and administration access from third countries, the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and EU standard contractual clauses (Art. 46(2)(c) GDPR) under the Microsoft data protection addendum | always |
| GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA (group: Microsoft Corporation) | operation of the development team's private issue repository; technical error descriptions (error message, stack trace, operations alerts) and tasks written by staff. Names, e-mail addresses, user and tenant identifiers, tenant names and customer addresses are removed before transfer; a transfer that still contains such details is refused technically. No in-app feedback, no screenshots, no attachments | USA | EU-U.S. Data Privacy Framework (Art. 45 GDPR) and EU standard contractual clauses (Art. 46(2)(c) GDPR) under the Microsoft data protection terms | only when an error is handed over to development |
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | provision of the servers on which roleALPHA itself operates the language model for support requests (classification of the request, reply drafts based on the public help); content of the request, including details that may contain personal data of third parties | ⟨TODO: confirm server location at Hetzner⟩ | none | only when the feedback function or a support request is used |
On e-mail dispatch: the platform's dispatch path is a platform-wide operational setting. Listed is the path actually used, via Microsoft Graph. If a separate SMTP provider is set up instead, it is to be added here and notified to customers under section 6; a self-operated SMTP server does not create an additional subprocessor. The Customer may instead set up its own dispatch path for its tenant or switch dispatch off; mail of that tenant then goes through its mail system and not through the provider named here (see section 5). A delivery log is kept for every dispatch attempt (recipient address, time, occasion, path, result) — without the message text, retention 90 days.
On the feedback function: reports from the platform arrive in roleALPHA GmbH's self-operated helpdesk (Zammad, on the infrastructure under section 2); notifications about them are delivered via the e-mail dispatch listed in this table. Before sending, the screenshot and page export are shown to the user for review and editing. A tenant's administration can switch the feedback function off itself; reports then go to support by e-mail.
4. Providers of AI services
These providers are engaged only if the Customer has activated the AI functions and released the relevant data area. Without such a release no transmission takes place (fail-closed default, section 5 of the DPA).
| Provider | Service and data concerned | Places of processing | Third-country transfer | Condition of engagement |
|---|---|---|---|---|
| Anthropic PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA | language models for the assistant and chat, summaries, suggestions, classification, translation; request content, conversation history, released context data, file attachments (images, PDF) | USA | EU standard contractual clauses; ⟨TODO: check certification under the EU-U.S. Data Privacy Framework and record it here⟩ | provider chosen by the Customer |
| OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland (affiliate: OpenAI, L.L.C., USA) | language models and vector representations (embeddings) for semantic search; as above, plus text content of released objects for computing embeddings | Ireland, USA | EU-U.S. Data Privacy Framework and EU standard contractual clauses | provider chosen by the Customer |
| Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (affiliate: Google LLC, USA) | language models and embeddings as alternative AI processing; data as for OpenAI | Ireland, USA | EU-U.S. Data Privacy Framework and EU standard contractual clauses | provider chosen by the Customer |
| Mistral AI SAS, 15 rue des Halles, 75001 Paris, France | language models and embeddings as alternative AI processing; data as for OpenAI | France (EU) | none; data processing agreement under Art. 28 GDPR | provider chosen by the Customer |
Choice by the Customer. The Customer determines which of these providers is used for its tenant. Anyone wishing to exclude third-country transfers entirely chooses a provider that processes solely within the EU (currently Mistral AI) or leaves the AI functions disabled.
Retention at the provider. The provider's terms for application programming interfaces (API) apply. These usually provide that API data are not used to train the models and are deleted after a short time; ⟨TODO: confirm the specific retention periods and training exclusion per provider against the current terms and record them here⟩.
5. Expressly not subprocessors
To avoid misunderstandings in a data protection review:
Operated by roleALPHA itself — no transmission to a service provider takes place: GlitchTip (error tracking) runs on our own infrastructure in its own network with its own database; the browser does not send there but to roleALPHA's server, which redacts the report before forwarding it. Umami (usage statistics) is likewise self-operated, cookieless, respects "Do Not Track" and uses only salted hash values as identifiers.
Processors of the Customer, not of roleALPHA: where the Customer supplies its own provider access for the AI functions ("BYOK"), the contractual relationship exists between the Customer and the provider; roleALPHA merely forwards the request technically, and concluding the contract as well as assessing the third-country transfer are for the Customer. The same applies to users' own AI applications connected by them: they are connected for the user's own account after the undertaking has enabled the function; where such an application transmits content to an AI provider, that happens outside the platform. Likewise the host of the Data Nodes in models M2 and M3 and the Customer's identity provider (single sign-on) are engaged by the Customer.
Systems of the Customer within its own sphere of responsibility: the Customer's own mail system (its own SMTP server or its own Microsoft 365 tenant) where it sets up its own dispatch path for its tenant, the source systems from which connectors take data (Entra ID, LDAP, SAP HCM, SAP FI, Microsoft Dynamics), the source systems of the interaction signals (Microsoft Graph, Jira, SharePoint, calendars, file systems) and the systems in which linked documents reside (document management, SharePoint, network drives). roleALPHA reads only with the access supplied by the Customer; for linked documents roleALPHA stores only the web address, and the user's browser retrieves the document directly from the source system.
No connection to customer data: Let's Encrypt and other certification authorities issue TLS certificates without processing personal data of our customers. The container registry and build environment process program code and release artefacts, not customer data. Tax advisers, legal advisers and auditors are bound by professional secrecy and act as controllers in their own right.
6. Procedure for changes
Notification. roleALPHA notifies the intended addition or replacement of a subprocessor at least 14 days in advance in text form — by e-mail to the contact address named by the Customer and as a notice in the platform. The notification states name, address, service, data categories, place of processing and transfer mechanism.
Objection and consequence. The Customer may object within that period on substantial data protection grounds (section 5 of the DPA). The parties then seek an amicable solution; if none is possible and the service cannot be provided at the agreed quality without that subprocessor, either party may terminate the affected part of the service on one month's notice.
Urgent replacement. If a subprocessor has to be replaced at short notice for compelling reasons (failure, security incident, insolvency), roleALPHA gives notice without delay after the change; the right of objection is preserved.
Contact address. The Customer designates the address for these notifications in the contract data of the DPA (section 9). Absent a separate designation, the administrator address recorded in the customer account applies.
7. Change history
| Version | Date | Change |
|---|---|---|
| 1.0 | 30 July 2026 | first version |
| 1.1 | 30 July 2026 | section "not subprocessors" extended: systems in which documents referenced by document links reside are systems of the Customer. No subprocessor added, replaced or removed — the 14-day notification is therefore not triggered. |
| 1.2 | 5 September 2026 | e-mail dispatch clarified: the dispatch path is a platform-wide operational setting; note on the delivery log without message text added. Added retroactively on 12 September 2026 — this row was previously missing. |
| 1.3 | 6 September 2026 | e-mail dispatch named: Microsoft Ireland Operations Limited with address, place of processing and transfer mechanism. This is the addition of a subprocessor; the 14-day notification was therefore triggered. Added retroactively on 12 September 2026; whether the notification was given is to be clarified outside this document. |
| 1.4 | 12 September 2026 | GlitchTip (error tracking) identified as self-operated. No subprocessor added, replaced or removed — the 14-day notification is therefore not triggered. |
| 1.5 | 14 September 2026 | users' own AI applications connected by them identified as not subprocessors. No subprocessor added, replaced or removed — the 14-day notification is therefore not triggered. |
| 2.0 | 25 September 2026 | list converted to the field structure of the contract template and condensed. netcup GmbH is named with address, seat of the operator in Germany, server location Vienna, contract date and its own subprocessors (Anexia Holding GmbH, Anexia Cloud Solutions GmbH) — previously it read "expected, please confirm". The host had been listed as a subprocessor since version 1.0; none was added, replaced or removed — the 14-day notification is therefore not triggered. References to the DPA updated to its new section numbers. |
| 2.2 | 5 October 2026 | Feedback via the own helpdesk instead of GitHub: in-app feedback is no longer transferred to GitHub but handled in the self-operated helpdesk; only cleaned technical error descriptions go to GitHub. Hetzner Online GmbH added as provider of the servers for the self-operated language model used in support handling — this is the engagement of a subprocessor, the 14-day notice is triggered. |
| 2.1 | 4 October 2026 | Own dispatch path per tenant: the Customer can have mail for its tenant sent through its own mail system or switch dispatch off; its mail system is listed as a system of the Customer (section 5). No subprocessor added, replaced or removed — the 14-day notice is therefore not triggered. |
Related documents
- Privacy Policy
- Terms of Service
- Data Processing Agreement
- Technical and Organisational Measures
- Imprint
Deutsche Fassung (maßgeblich): Unterauftragsverarbeiter
© 2026 roleALPHA GmbH