# Subprocessors and Service Providers - Kanera

> Third-party providers used to operate hosted Kanera and the process for subprocessor changes.

Canonical page: https://www.kanera.app/subprocessors

Data protection

# Subprocessors and Service Providers

This page identifies third parties used to operate standard hosted Kanera and distinguishes customer-selected destinations.

Effective August 20, 2026 · Version 1

At a glance

Scope Providers process only the data needed for their contracted function.

Changes DPA customers receive advance notice of new subprocessors.

Contact hi@kanera.app

## Current named providers

Provider Service and data Processing location

Cloudflare, Inc. Network delivery and security, Turnstile challenges, IP address, request and device signals EEA and other Cloudflare locations under its data-processing and transfer terms

PostHog, Inc. · PostHog Cloud EU Optional website and product analytics, internal user and organisation identifiers, profile fields and allow-listed content-free events European Union

Stripe Payments Europe, Limited and Stripe group companies Checkout, subscriptions, invoices, tax, payment method and transaction processing EEA and other Stripe locations under its data-processing and transfer terms

## Hosted infrastructure and communications

Kanera also uses contracted hosting, storage, backup, monitoring, and email-delivery services to operate hosted Kanera in Ireland and Germany. Because the production deployment may change between equivalent EEA providers, the current legal entity, function, and location for any provider that processes Customer workspace personal data will be supplied to a DPA customer on request and included in advance notice before a new provider begins that processing.

This operational category does not authorise moving hosted workspace data outside Ireland and Germany. DPA customers can request the current legal entities at any time, and Kanera will provide the change notice required by the DPA before a new provider begins processing customer personal data.

## Customer-selected services

A provider selected and configured by Customer or an authorised user is not Kanera’s subprocessor for that destination. This includes SMTP or S3-compatible providers configured by Customer; Slack, Discord, Telegram or Zulip destinations; personal ntfy, Gotify or webhook destinations; managed webhooks; OAuth, MCP and API clients; GitHub and Trello features; and browser or operating-system push services.

Kanera sends only the information required for the configured action and granted permissions. Customer is responsible for its instructions, provider selection, scope, contractual terms, notices, and lawful basis.

## Change notifications

DPA customers may request subprocessor-change notices by emailing hi@kanera.app from their organisation contact address. Notice and objection rights are governed by the Data Processing Addendum. This list is version 1, reviewed August 20, 2026.

- [Data Processing Addendum](https://www.kanera.app/dpa)
- [Privacy Policy](https://www.kanera.app/privacy)

## Machine-readable resources

- [Kanera AI index](https://www.kanera.app/llms.txt)
- [Kanera documentation index](https://www.kanera.app/docs/llms.txt)
- [Agent discovery guidance](https://www.kanera.app/agents.md)
