Subprocessor List
Last updated: July 20, 2026
Scope
Plus Ultra Industries, LLC uses the vendors below to operate Kanvify. This list includes processors, customer-directed recipients, and supporting service providers that may receive Customer Personal Data or related network data. A vendor is used only for the feature and purpose described.
“Optional” means a customer can avoid that vendor’s feature-specific processing by not enabling or consenting to the feature. It does not mean every other part of Kanvify can operate without the vendor.
Current Vendors
| Vendor and contracting entity | Function | Data categories | Primary processing location | Use |
|---|---|---|---|---|
| Stripe, LLC (United States) | Usage billing, credits, invoices, taxes, and compute or storage meter reporting | Account identifier and name, owner email, usage-subscription data, metered quantities, invoice, tax, transaction, and payment metadata; Stripe directly handles payment-card data | United States, with additional processing locations used by Stripe | Required for usage billing |
| Anthropic, PBC (United States) | Customer-provided Anthropic LLM route | Provider credential supplied by Customer, prompts, context, request parameters, responses, model and request metadata | United States | Optional; only when Customer configures an Anthropic route |
| OpenAI OpCo, LLC (United States) | Customer-provided OpenAI LLM route | Provider credential supplied by Customer, prompts, context, request parameters, responses, model and request metadata | United States | Optional; only when Customer configures an OpenAI route |
| Hetzner Online GmbH (Germany) | Application and sandbox compute | Customer code, active sandbox filesystems, environment data, workload input and output, inside-sandbox process data, network-policy configuration, and operational metadata | Germany, European Union | Core infrastructure |
| Neon, Inc. (United States) | Managed PostgreSQL database hosted on AWS | Account and workspace records, configuration, credential hashes and encrypted credentials, usage and billing metadata, activity records, cached LLM request and response data, and other application database data | AWS us-west-2, United States | Core infrastructure |
| Cloudflare, Inc. (United States) | R2 object storage and content delivery network | Stored objects and object metadata; website and asset requests; IP address, user agent, request headers, and delivery or security metadata | R2 in configured Cloudflare storage and Cloudflare’s global CDN | Core storage and delivery |
| AC PM, LLC, doing business as Postmark (United States) | Transactional email | Recipient name and email, message content and metadata for magic links, invitations, and service messages, plus delivery events | United States | Core account communications |
| Google LLC — Tag Manager and Google Analytics (United States) | Consent-gated tag delivery, traffic analytics, and product measurement | IP address, browser and device data, page URL, referrer, cookie or device identifiers, timestamps, events, and interaction metadata | United States and Google’s global processing locations | Optional; analytics consent required |
| Meta Platforms, Inc. (United States) | Consent-gated Meta Pixel campaign and conversion measurement | IP address, browser and device data, page URL, cookie or device identifiers, events, and campaign or conversion metadata | United States and Meta’s global processing locations | Optional; analytics consent required |
| FullStory, Inc. (United States) | Consent-gated product analytics and session replay | IP address, browser and device data, page and interaction events, rendered-page or session-replay data, and identifiers used for analytics | United States | Optional; analytics consent required |
| BunnyWay d.o.o. — Bunny Fonts (Slovenia) | Web-font delivery | IP address, user agent, referrer, requested font asset, and delivery metadata | European Union and Bunny’s delivery network | Used when a page requests hosted fonts |
| Google LLC — Google Sign-In (United States) | Optional single sign-on | Google account identifier, email address, name, avatar, OAuth tokens, authentication events, and related metadata | United States and Google’s global processing locations | Optional; only when Customer uses Google sign-in |
| GitHub, Inc. (United States) | GitHub integration and managed runner coordination | GitHub organization, repository, installation, workflow, job, commit, runner, and delivery metadata; short-lived tokens and data needed to execute Customer-configured jobs | United States and GitHub’s global processing locations; Kanvify runner compute remains in the configured sandbox region | Optional; only when Customer enables GitHub features |
Anthropic and OpenAI are bring-your-own-provider routes. Customer supplies the provider credential, contracts with the provider, and pays the provider directly. Plus Ultra does not provide or bill the LLM. Kanvify uses the credential to keep it out of the sandbox and route Customer-selected requests.
Google Tag Manager, Google Analytics, Meta Pixel, and FullStory are nonessential analytics or measurement tools. Their full measurement features are intended and required to be activated only after analytics consent as described in the Privacy Policy.
Change Notice and Objections
Plus Ultra will post an addition or replacement at least 30 calendar days before the provider begins processing Customer Personal Data and will make reasonable efforts to notify affected customers through available account or email channels. The posting date begins the notice period.
Customers may object during the notice period on reasonable data-protection grounds by emailing privacy@plusultra.industries. We will work in good faith on a reasonable solution, which may include avoiding or disabling the affected feature. If no reasonable solution is available, the customer may terminate the affected Service before the change takes effect.
An urgent security, availability, legal, or provider event may require a faster replacement. In that case, we will post and provide reasonable notice without undue delay and explain why advance notice was impracticable.
Change History
| Date | Change |
|---|---|
| 2026-07-20 | Initial complete publication covering infrastructure, billing, customer-provided LLM routes, email, analytics, measurement, fonts, sign-in, and GitHub runners |
Contact
Subprocessor and privacy questions: privacy@plusultra.industries
Contract notices: legal@plusultra.industries