Transparency
Sub-processors
In short
These are every third party that may process personal data on our behalf. The list is deliberately short, because the data your workflows actually handle never reaches us — it moves between your own Cloudflare account and the services you connected.
We notify customers 30 days before adding a new sub-processor that processes personal data.
This page is published under Article 28(2) of the GDPR and forms part of our Data Processing Addendum. “Sub-processor” means a third party we engage that may process personal data in the course of providing Nodes2Cloud to you.
1. Always engaged
These are engaged for every account. You cannot use Nodes2Cloud without them, because they are the infrastructure it runs on.
| Sub-processor | What it does for us | Data it may receive | Location |
|---|---|---|---|
| Cloudflare, Inc. | Hosting for the website, editor and API; all control-plane storage (D1, KV, Durable Objects); AI Gateway; WAF, DDoS mitigation and rate limiting. | Account details, session records (including IP address and user agent), workflow graphs, deployment records, billing references, audit logs. | Global edge network; data at rest in Cloudflare's distributed infrastructure |
| Zoho Corporation (ZeptoMail) | Delivery of transactional email — email verification codes, password reset codes and service notices. | Email address, name, one-time verification codes. | India (api.zeptomail.in) |
| Anthropic PBC | Powers the AI workflow assistant. Requests are routed through Cloudflare AI Gateway rather than sent to Anthropic directly. | The prompt you type and the workflow graph you are editing. Account identifiers are not sent. | United States |
| Stripe, Inc. | Payment processing for customers billed outside India. Card details are collected on Stripe's own hosted checkout and never reach our servers. | Name, email address, billing country, payment method details (held by Stripe, not by us), transaction records. | United States and global |
| Razorpay Software Private Limited | Payment processing for customers billed in India. Card and UPI details are collected on Razorpay's own hosted checkout and never reach our servers. | Name, email address, billing country, payment method details (held by Razorpay, not by us), transaction records. | India |
2. Only if enabled
Wired into the platform but dormant unless a specific configuration is enabled. Where disabled, no data reaches them at all.
| Sub-processor | What it does for us | Data it may receive | Location |
|---|---|---|---|
| Functional Software, Inc. (Sentry) | Application error reporting, used to diagnose faults. Disabled unless a reporting endpoint is configured; when disabled no data leaves our infrastructure at all. | Error type and message, and limited technical context attached to the error. Credentials and secret values are never included. | United States |
3. Only if you connect it
These receive data only if you choose to sign in with them or connect them as an integration. Disconnect the integration and the flow stops.
| Sub-processor | What it does for us | Data it may receive | Location |
|---|---|---|---|
| Google LLC | Sign-in with Google, and the Gmail, Sheets, Drive, Calendar, Docs, YouTube, Analytics, BigQuery and Firestore integrations. | For sign-in: your Google account email, name and profile picture. For integrations: an encrypted OAuth token, plus whatever data the integration you chose reads or writes. | United States and global |
| GitHub, Inc. (Microsoft) | Sign-in with GitHub, and the “push workflow to a repository” feature. | GitHub username and account id, email address, an encrypted OAuth token, and the workflow source you choose to push. | United States |
| Microsoft Corporation | Outlook, OneDrive and Teams integrations, when connected. | An encrypted OAuth token and the data the integration reads or writes. | United States and global |
| Salesforce, Inc. | Salesforce integration, when connected. | An encrypted OAuth token and the data the integration reads or writes. | United States and global |
| Dropbox, Inc. | Dropbox integration, when connected. | An encrypted OAuth token and the files the integration writes. | United States |
| LinkedIn Corporation (Microsoft) | LinkedIn posting integration, when connected. | An encrypted OAuth token, your LinkedIn profile identifier, and posted content. | United States |
| X Corp. | X (Twitter) integration, when connected. | An encrypted OAuth token and posted content. | United States |
4. What we do not use
Stated explicitly because it is unusual and easy to verify by inspecting the pages we serve. We run no analytics, advertising or product-telemetry vendor of any kind — not on this website, not in the editor, not in the API:
- Google Analytics / Google Tag Manager
- PostHog
- Plausible
- Mixpanel
- Amplitude
- Segment
- LogRocket
- Hotjar
- Microsoft Clarity
- Facebook / Meta Pixel
- Any advertising or retargeting network
5. Integrations you choose are not our sub-processors
Nodes2Cloud ships connectors for well over a hundred services — AWS, Slack, Notion, Airtable, Twilio, HubSpot, Shopify, OpenAI and many more. It is worth being precise about these:
- They are not our sub-processors. When your deployed workflow calls one, the call is made by your Cloudflare Worker using your credentials. We are not in the request path and receive nothing from it.
- You are contracting with them directly. If you need a data processing agreement with such a provider, it is between you and them.
- The providers listed in section 3 appear there only because they are involved in our own sign-in or connection flow, where we do handle the token.
6. How we vet sub-processors
Before engaging a sub-processor that will handle personal data, we:
- confirm they offer contractual terms that meet GDPR Article 28 and are compatible with the DPDP Act;
- check their security posture and published certifications, and their history of handling incidents;
- confirm an appropriate transfer mechanism is available for data leaving the EEA, the UK or India; and
- give them the minimum data needed for their function. Our email provider gets an address and a code, not your workflows.
We remain responsible to you for our sub-processors’ performance of their data-protection obligations.
7. When this list changes
- We give at least 30 days’ notice by email to account holders before a new sub-processor begins processing personal data.
- If you have a reasonable, data-protection-based objection, tell us within that period at privacy@nodes2cloud.com. We will work with you to find an alternative; if none exists, you may terminate the affected service and receive a refund of prepaid, unused fees.
- Emergency replacements — where a sub-processor fails or must be replaced for security reasons — may be made immediately, with notice as soon as practicable afterwards.
- The date at the top of this page reflects the most recent change.
8. International transfers
Several sub-processors are outside India, the EEA and the UK. Transfers rely on the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum, with the technical measures described on our Security page. Under the DPDP Act, transfers outside India are permitted except to countries restricted by government notification.
More detail is in section 9 of the Privacy Policy.
Questions, or want to be notified of changes to this list directly? Email privacy@nodes2cloud.com.