Serialoom Subprocessor List
| Field | Value |
| Version | 2026-08-05-draft.1 |
| Effective date | [EFFECTIVE DATE] |
| Last updated | 2026-08-05 |
Only providers verified as wired or configured in the Serialoom codebase / infra are listed as active. Potential future providers are marked *candidate*.
Active / infrastructure
| Entity (public name) | Service | Data categories | Purpose | Location (typical) | Notes |
| Hetzner Online GmbH (or contracting Hetzner entity) | Cloud VM / hosting | Account, content, logs DB/Redis as deployed | Host application & database | DE (fsn1 example) | Confirm contracting entity on invoice |
| Cloudflare, Inc. (R2) | Object storage | Media objects, exports | Store/serve assets when STORAGE_PROVIDER=r2 | Cloudflare regions | Inactive when local storage only |
| Paddle.com Market Limited (and affiliates) | Merchant of Record | Buyer identity, payment, tax | Checkout, subscriptions, invoices, refunds | UK/EEA/global as Paddle operates | Independent controller for MoR payment data |
| Luma Labs (Dream Machine API) | Video generation | Prompts, refs, outputs | Video jobs when live video enabled | Provider cloud | Live adapter present |
| ElevenLabs | TTS API | Script text, voice_id, audio output | Voice synthesis when live voice enabled | Provider cloud | TTS only in current adapter |
| NVIDIA (NIM API endpoint) | Text generation | Prompts/text | Text when configured | Provider cloud | |
| Google (Gemini API) | Text generation | Prompts/text | Text fallback when configured | Provider cloud | |
Auth (when enabled)
| Entity | Service | Data categories | Purpose | Location | Notes |
| Google Firebase Authentication (Google LLC) | Social login | Email, name, provider uid | Optional Google/GitHub/Apple sign-in when configured | Provider cloud | Active only if Firebase env configured |
Candidates (not active subprocessors until wired)
| Candidate | Purpose | Status |
| Transactional email ESP (TBD) | Auth/billing email | Not selected |
| Error monitoring SaaS (TBD) | Crash reporting | Not in studio deps |
| Product analytics SaaS (TBD) | Funnels | Not in studio deps; first-party product_events used instead |
Change process
- Update this list with version + date.
- Notify business customers who opted into subprocessor notices at least [NOTICE DAYS — counsel, often 15–30] before enabling a material new subprocessor where required by DPA.
- Keep version history under
legal/archive/.
Privacy links: see each provider’s public privacy notice. Serialoom does not republish their full policies.
*Counsel-ready draft — 2026-08-05. Legal entity names should be confirmed against contracts/invoices before launch.*