SUBPROCESSORS · v1.0 · 2026-05
Subprocessors
A subprocessor is a third party that processes personal data on bidyou.ai's behalf as part of providing the service. We list every one of them here, with what they do and where they do it. We notify active customers at least 30 days in advance of any addition or replacement.
1. In production today
| Subprocessor | Role | Purpose & data scope | Location | Transfer |
|---|---|---|---|---|
| CRM-Line, Lda. | Operator + EU hosting | Production servers, GPU inference, database, backups, mail. Sole hosting operator. | EU (Estoril, Portugal) | Intra-EU only |
| Cloudflare, Inc. | Marketing CDN + anti-spam + analytics | CDN, DNS, anti-spam (Turnstile) and cookieless web analytics for the bidyou.ai marketing site only. No customer bid data, drawings, pricing or credentials transit Cloudflare. | Global edge | Standard Contractual Clauses (Module 3) where applicable; minimal scope |
2. Planned for public beta
The following subprocessors will be activated when the SaaS multi-tenant backend goes public. We will publish 30-day advance notice on this page and email active customers before any becomes operational.
| Subprocessor | Role | Purpose & data scope | Location | Transfer |
|---|---|---|---|---|
| Resend (Resend, Inc.) | Transactional email | Account activation emails, password reset emails, billing notifications. Sender domain bidyou.ai with SPF + DKIM + DMARC. No marketing emails. | US (transmits to recipient mailbox provider, EU storage where available) | SCCs + DPA executed before activation |
| Stripe Payments Europe, Ltd. | Subscription billing | Pro and Enterprise tier billing. Receives billing data only (name, email, VAT, card token via Stripe.js). Never receives bid data, drawings, supplier prices or product output. | EU (Ireland) | Intra-EU |
| Brave Search (Brave Software, Inc.) | Marketplace lookup search | Fan-out queries to whitelisted retailers when our cache is empty. Each query is the item description plus country code — never customer name, project name, or bid data. | US | SCCs + supplementary measures (no PII transmitted) |
3. Affiliate networks
Affiliate networks rewrite outbound retailer URLs with a tracking parameter when a user clicks through to a retailer that participates in that network. They do not receive customer personal data, project data or bid data. They observe only that an outbound click occurred from bidyou.ai to a retailer URL. See Affiliate Disclosure for the mechanics.
- Skimlinks — Aggregator: hundreds of retailers under one tracking layer
- Awin — Direct enrollment with selected retailers (PT, UK, EU)
- TradeDoubler — Direct enrollment with selected retailers (Nordics, DE)
- CJ Affiliate — Direct enrollment with selected retailers (US, UK)
4. Notification policy
We notify active customers at least 30 days in advance of any addition or replacement of a subprocessor. Notification channels:
- Email to the billing contact and any DPO contact on the customer record;
- This page (date stamp at the top updated);
- Banner on the customer dashboard for 14 days from publication.
A customer who objects on reasonable data-protection grounds and whose objection cannot be resolved by mutual agreement may terminate the Principal Agreement without penalty for the affected portion of the service, in accordance with §6 of the Data Processing Agreement.
5. What is not a subprocessor
- Your own integrations (e.g., a Stripe account you connect, a Google Drive you authenticate, your supplier's catalogue) — these are independent controllers, not bidyou.ai subprocessors.
- End-user web analytics on the marketing site — Cloudflare Web Analytics is cookieless and does not constitute personal-data processing in the GDPR sense for the marketing surface.
- Public retailers and marketplaces queried by the marketplace lookup feature — they receive only the item description and country code, no PII.
6. Changes log
| Date | Change |
|---|---|
| 2026-05-10 | Initial publication: CRM-Line + Cloudflare in production. Postmark/Resend, Stripe, Brave Search and affiliate networks listed as planned. |
7. Contact
Questions or objections: privacy@bidyou.ai. We respond within one business day.