Skip to content

Legal

Sub-processors

The third parties FRAPE engages to process personal data on behalf of our customers, what each one does, where it does it, and how we tell you before anything changes.

Our commitments

How the list works

When a customer uses FRAPE, the customer decides why and how its end users' data is processed (the controller), and FRAPE processes that data only on the customer's instructions (the processor). To run the service, FRAPE relies on a small number of other companies. Each one that processes customer personal data is a sub-processor and is listed below.

  • General authorisation. Our data processing agreement gives FRAPE a general written authorisation to use the sub-processors on this page. We bind each of them to data protection terms at least as protective as our own, and we remain responsible for their work.
  • 30 days' notice. We publish any new or replacement sub-processor here and notify subscribers at least 30 days before it starts processing customer data. In an emergency, for example to keep the service running or secure, we may make a change sooner and will tell you as soon as we reasonably can, with the reason.
  • Your right to object. During the notice period you can object on reasonable data protection grounds. We will work with you on a solution; if we cannot find one, you may end the affected part of the service.
  • How to subscribe. Email [email protected] from your business address with the subject “Subscribe: sub-processor updates”. We send change notices to that address and to your organisation's administrators.

Current list

Sub-processors

Entities marked as engaged by another sub-processor work under that sub-processor's contract; we list them so you can see the whole chain.

FRAPE sub-processors, version 0.2 (draft), last updated 2026-10-06
EntityPurposeData categoriesLocationTransfer mechanismApplies to
Google Cloud (Google Cloud EMEA Limited, Ireland)
To confirm
  • Confirm the contracting entity on FRAPE's billing account.
  • Confirm the locations of support access.
Hosting and infrastructure for the FRAPE service: compute, database, cache, messaging, storage, backups, secret storage, logs and monitoring.All customer data processed by the service: events sent for scoring, decisions, cases, lists, settings and customer user accounts.European Union (Belgium region). Backups and replicas stay in EU regions.Processing in the EU. Any transfer outside the EEA is covered by the provider's cloud data processing terms, which include the EU Standard Contractual Clauses.All customers
OpenRouter, Inc.
To confirm
  • Sign the provider's enterprise data processing agreement (flow-down, no training, zero data retention). FRAPE's requests already ask for zero data retention.
  • Confirm Data Privacy Framework participation.
Routes Decision Core requests to the hosted AI decision model and returns its answer. The answer is advice only; FRAPE's rules engine makes the final decision.Derived, pseudonymous event features: amount and currency, country codes, coarse network attributes (a truncated network prefix, network operator), coarse device facts derived from the browser agent (browser and OS family, primary language, yes/no flags for automation, emulator and time zone mismatch, and how often the device was seen before at the same organisation), risk scores, counts and yes/no flags. No names, email addresses, phone numbers, full IP addresses, card numbers or customer identifiers are sent, and no device identifier, browser fingerprint or user agent.United StatesEU Standard Contractual Clauses (processor to processor) with the UK Addendum; EU–US Data Privacy Framework if the provider participates.Organisations using Decision Core in shadow or inline mode (shadow is the default). Not used when an organisation turns Decision Core off.
Engaged by OpenRouter, Inc.TypeSafe
To confirm
  • Confirm the legal entity name, address and processing location.
  • Confirm requests are pinned to this host with no fallback.
Hosts and runs the AI decision model used by Decision Core, on requests routed by OpenRouter, Inc.The same derived, pseudonymous event features as above, processed transiently to produce an answer.To be confirmedContractual flow-down from OpenRouter, Inc. (to be confirmed).Same as OpenRouter, Inc.
Resend, Inc.
To confirm
  • Confirm this is the production email provider (the production configuration still uses a placeholder host).
Sends account emails: sign-up verification, invitations to the admin console, password and security notices, and service notifications.Customer users' names and email addresses, and the content of those emails.United StatesEU Standard Contractual Clauses with the UK Addendum; EU–US Data Privacy Framework if the provider participates.All customers

For completeness

Not on this list, and why

External IP reputation service
FRAPE can be configured to look up IP reputation with an external service, but no such service is part of the standard service today. If FRAPE enables one, it will be added to this list with notice before any customer data is sent to it.
Gravatar existence check
An optional check for whether a public Gravatar picture exists for an email address (Gravatar is operated by Automattic Inc.). It is off by default, cannot be turned on without legal review, and would also need each customer's opt-in. It will be listed here before it is offered.
Public domain lookups
To assess email domains, FRAPE queries public DNS resolvers (including Cloudflare's public resolver), the domain registries' RDAP services and the domain's own website. Only the domain name is sent, never the part of the address before the @, and never any link to a customer or a person. We do not treat these public lookups as sub-processing.
Billing
Invoices are issued manually today. If FRAPE adopts a payment provider such as Stripe, it would handle billing details of FRAPE's customers for FRAPE's own purposes (FRAPE as controller). That is covered by our privacy notice rather than this list.
Identity verification (coming soon)
When identity verification launches, the verification provider will be added to this list with notice before any customer data is sent to it.
This website
This marketing site is a static site served by a content-delivery provider. It sets no cookies and collects no customer data, so its host is not a sub-processor.

Changes

Version history

  1. · version 0.2 (draft)Clarified the data sent for Decision Core: it includes coarse device facts derived from the browser agent, never the device identifier, browser fingerprint or user agent. No new sub-processor.
  2. · version 0.1 (draft)First published draft of the list, pending counsel review.

For how FRAPE protects data inside the platform, see Security & privacy.