Public register

Subprocessors

Providers that may process personal data on Ablo's behalf, including the external infrastructure used by Ablo-owned AgentContainer services.

Version
1.0
Last updated
2026-08-31
Reviewed
2026-08-31

Provider register

20 providers are covered by this policy.

Reviewed 2026-08-31

01

Convex Labs

Application database, backend functions and file metadata

Data handled
Account and organization records, projects, workspace state, conversations and task links, integration metadata, billing records, audit events and operational metadata.
Purpose
Store Ablo's product state and run the backend workflows that provide the service.
Processing locations
Ablo production deployments use Convex's EU region. Provider operations and subprocessors may involve other jurisdictions.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Retained while the organization is active. Active-system deletion must complete within 30 days; provider backup copies expire on the documented recovery schedule.
Controls and limitations
Ablo controls the selected deployment region and application access. Convex controls its infrastructure, support access and backup lifecycle.
Provider privacy information
02

Clerk

Authentication and organization identity

Data handled
Names, email addresses, authentication identifiers, sessions, organization membership and role information.
Purpose
Authenticate users, secure sessions and maintain organization membership.
Processing locations
Clerk and its subprocessors may process data in the United States and other published locations.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Identity data is retained while the account is active. Ablo removes active identity records through the deletion workflow; Clerk's DPA provides for deletion of remaining copies after service termination, subject to legal retention.
Controls and limitations
Ablo controls which identity and organization features it uses. Clerk controls authentication infrastructure, session security and its subprocessor chain.
Provider privacy information
03

Vercel

Web hosting, application delivery, analytics and AI gateway

Data handled
Web requests, IP and device data, route and performance metadata, error details, and AI content only when an AgentContainer tool uses the Vercel AI Gateway.
Purpose
Host and deliver the Ablo and AgentContainer web applications, measure service performance and support selected internal AI operations.
Processing locations
Vercel operates a global delivery network and may process data in the United States, EEA and other published subprocessor locations.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Ablo does not intentionally persist workspace content in web-hosting logs. Analytics and routine operational logs are normally limited to 90 days; AI content follows the configured gateway and model-provider policy.
Controls and limitations
Authenticated route identifiers and workspace content must not be sent to analytics. Vercel controls delivery-network and platform operational logs.
Provider privacy information
04

Hetzner

EU agent-execution infrastructure

Data handled
Task prompts and responses, runtime files, repositories, tool inputs and outputs, execution logs, Browserless sessions, Redis wake-up data and checkpoint images.
Purpose
Run isolated Coordinator and Coworker tasks and host Ablo-operated runtime services.
Processing locations
Verified EU-based Hetzner infrastructure. Browserless and the checkpoint registry are self-hosted on the same EU infrastructure.
Transfer safeguards
The production workload is pinned to an EU region. Provider contractual terms must cover any international support, account or subprocessor access.
Retention and deletion
Runtime data is retained only as required for active work, recovery and the agreed product history. Tasks, files and checkpoints are included in the 30-day active-system deletion policy.
Controls and limitations
AgentContainer, Browserless and the checkpoint registry are Ablo-owned components, not separate subprocessors. Hetzner supplies the underlying compute, network and storage infrastructure.
Provider privacy information
05

Railway

EU hosting for repositories and runtime coordination

Data handled
Customer integration repositories stored in Gogs, repository credentials, and short-lived Redis task wake-up and coordination data.
Purpose
Host Ablo's Gogs and Redis services used by agent work and runtime coordination.
Processing locations
Gogs and Redis run in Railway's EU region. Railway account, support and operational processing may occur outside the EEA.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Repositories are retained while the related project or integration needs them and are included in the 30-day deletion workflow. Redis data is transient; Railway backups follow its documented recovery lifecycle.
Controls and limitations
Gogs and Redis are self-hosted Ablo components. Railway supplies the underlying hosting platform and controls platform-level backups and operational logs.
Provider privacy information
06

Backblaze

B2 object storage

Data handled
Files and deliverables uploaded to or generated within customer projects, with associated object metadata.
Purpose
Store and deliver customer files and agent deliverables.
Processing locations
Ablo uses Backblaze B2 EU Central, located in Amsterdam. Account and service metadata may be processed in the United States.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Objects are retained while the customer needs them and are included in the 30-day deletion workflow. Remaining copies follow Backblaze's documented storage and backup lifecycle.
Controls and limitations
Ablo controls the bucket region, access credentials and object deletion. Backblaze controls physical storage and account-level operational metadata.
Provider privacy information
07

OpenRouter

AI request routing

Data handled
AI prompts, responses, model and routing preferences, token usage, latency, cost and request metadata.
Purpose
Route AI completion requests to an enabled inference provider that satisfies Ablo's privacy requirements.
Processing locations
OpenRouter and the selected inference provider may process requests outside the EEA. Ablo does not claim EU-only AI processing.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Prompt and response logging is disabled and requests require Zero Data Retention. OpenRouter retains operational request metadata that excludes prompt and response content.
Controls and limitations
Ablo requires account-level ZDR plus provider.zdr = true and provider.data_collection = "deny" on every request. OpenRouter controls endpoint policy classification and operational metadata retention.
Provider privacy information
08

Amazon Web Services

Amazon Bedrock model inference through OpenRouter

Data handled
AI prompt and response content and inference metadata.
Purpose
Provide model inference when selected by compliant OpenRouter routing.
Processing locations
The region depends on the Bedrock endpoint selected by OpenRouter and may be outside the EEA.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Prompt and response content must use a Zero Data Retention endpoint and must not be used for training. Operational, security and billing metadata may be retained under the provider's applicable terms.
Controls and limitations
Routing is allowed only when the endpoint satisfies provider.zdr = true and provider.data_collection = "deny". Availability and exact processing location depend on the selected model and compliant endpoint.
Provider privacy information
09

Google Cloud

Vertex AI model inference through OpenRouter

Data handled
AI prompt and response content and inference metadata.
Purpose
Provide model inference when selected by compliant OpenRouter routing.
Processing locations
The region depends on the Vertex AI endpoint selected by OpenRouter and may be outside the EEA.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Prompt and response content must use a Zero Data Retention endpoint and must not be used for training. Operational, security and billing metadata may be retained under the provider's applicable terms.
Controls and limitations
Routing is allowed only when the endpoint satisfies provider.zdr = true and provider.data_collection = "deny". Availability and exact processing location depend on the selected model and compliant endpoint.
Provider privacy information
10

Microsoft

Azure model inference through OpenRouter

Data handled
AI prompt and response content and inference metadata.
Purpose
Provide model inference when selected by compliant OpenRouter routing.
Processing locations
The region depends on the Azure endpoint selected by OpenRouter and may be outside the EEA.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Prompt and response content must use a Zero Data Retention endpoint and must not be used for training. Operational, security and billing metadata may be retained under the provider's applicable terms.
Controls and limitations
Routing is allowed only when the endpoint satisfies provider.zdr = true and provider.data_collection = "deny". Availability and exact processing location depend on the selected model and compliant endpoint.
Provider privacy information
11

xAI

Model inference through OpenRouter (provider label: SpaceXAI)

Data handled
AI prompt and response content and inference metadata.
Purpose
Provide model inference when selected by compliant OpenRouter routing.
Processing locations
The endpoint location is controlled by xAI and OpenRouter and may be outside the EEA.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Prompt and response content must use a Zero Data Retention endpoint and must not be used for training. Operational, security and billing metadata may be retained under the provider's applicable terms.
Controls and limitations
Routing is allowed only when the endpoint satisfies provider.zdr = true and provider.data_collection = "deny". Availability and exact processing location depend on the selected model and compliant endpoint.
Provider privacy information
12

Groq

Model inference through OpenRouter

Data handled
AI prompt and response content and inference metadata.
Purpose
Provide model inference when selected by compliant OpenRouter routing.
Processing locations
The endpoint location is controlled by Groq and OpenRouter and may be outside the EEA.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Prompt and response content must use a Zero Data Retention endpoint and must not be used for training. Operational, security and billing metadata may be retained under the provider's applicable terms.
Controls and limitations
Routing is allowed only when the endpoint satisfies provider.zdr = true and provider.data_collection = "deny". Availability and exact processing location depend on the selected model and compliant endpoint.
Provider privacy information
13

MiniMax

Model inference through OpenRouter

Data handled
AI prompt and response content and inference metadata.
Purpose
Provide model inference when selected by compliant OpenRouter routing.
Processing locations
The endpoint location is controlled by MiniMax and OpenRouter and may be outside the EEA.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Prompt and response content must use a Zero Data Retention endpoint and must not be used for training. Operational, security and billing metadata may be retained under the provider's applicable terms.
Controls and limitations
Routing is allowed only when the endpoint satisfies provider.zdr = true and provider.data_collection = "deny". Availability and exact processing location depend on the selected model and compliant endpoint.
Provider privacy information
14

Moonshot AI

Model inference through OpenRouter

Data handled
AI prompt and response content and inference metadata.
Purpose
Provide model inference when selected by compliant OpenRouter routing.
Processing locations
The endpoint location is controlled by Moonshot AI and OpenRouter and may be outside the EEA.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Prompt and response content must use a Zero Data Retention endpoint and must not be used for training. Operational, security and billing metadata may be retained under the provider's applicable terms.
Controls and limitations
Routing is allowed only when the endpoint satisfies provider.zdr = true and provider.data_collection = "deny". Availability and exact processing location depend on the selected model and compliant endpoint.
Provider privacy information
15

Composio (Sampark Inc.)

Managed OAuth, connected accounts and integration execution

Data handled
Connected-account identifiers and credentials, OAuth scopes, integration tool inputs and outputs, webhook payloads and execution logs.
Purpose
Connect customer-selected services, hold and refresh credentials, and execute approved integration actions.
Processing locations
Composio and its infrastructure providers may process data outside the EEA.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Credentials must be revoked and the connected account deleted immediately on disconnect or organization deletion. Payload-log retention is controlled by Composio unless a contractual or account-level control is available.
Controls and limitations
Ablo limits exposed integrations and tools. Composio-managed OAuth scopes and payload-log retention remain vendor-controlled limitations.
Provider privacy information
16

PostHog

Product analytics and operational telemetry

Data handled
Consented product events, user and organization identifiers, device and route metadata, and redacted application error and log information.
Purpose
Understand product use, measure reliability and investigate operational failures.
Processing locations
Ablo uses PostHog's EU cloud endpoint. Provider support and subprocessors may involve other published locations.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Product analytics and routine operational telemetry are normally retained for 90 days and are included in account-deletion requests.
Controls and limitations
Analytics requires consent. Session replay is disabled in authenticated areas, and workspace content and credentials must not be captured.
Provider privacy information
17

Polar

Subscriptions, checkout and billing operations

Data handled
Organization billing identity, subscription, checkout, order and refund references, product and amount information, and billing-event metadata.
Purpose
Sell subscriptions and credits, reconcile payments and administer billing.
Processing locations
Polar and its payment and infrastructure providers may process data in the United States, EEA and other published locations.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Product billing data is deleted with the organization unless required for accounting, tax, fraud or dispute obligations. Required primary accounting records may be isolated for at least five years.
Controls and limitations
Ablo does not store full payment-card details. Polar and its payment providers control payment processing and legally required transaction retention.
Provider privacy information
18

Resend

Transactional email delivery

Data handled
Recipient and sender addresses, message subject and body, delivery status, suppression records and email metadata.
Purpose
Deliver organization invitations, service notifications and other transactional email.
Processing locations
Resend and its email-delivery infrastructure may process data in the United States and other published locations.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Delivery and security records are normally limited to 90 days, except suppression records or legally required records needed to prevent unwanted delivery.
Controls and limitations
Ablo controls message content and recipients. Resend controls delivery infrastructure, bounce handling and suppression processing.
Provider privacy information
20

Cal.com

Call booking

Data handled
Name, business email address, organization details, scheduling preferences and information a visitor chooses to include in a booking.
Purpose
Arrange a sales, onboarding or support call requested by the visitor.
Processing locations
Cal.com and its subprocessors may process booking data in the United States, EEA and other published locations.
Transfer safeguards
Ablo requires applicable data-processing terms and a lawful transfer mechanism. For transfers outside the EEA this may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures where appropriate.
Retention and deletion
Booking information is kept only while needed to arrange and document the requested business conversation, subject to legal obligations and deletion requests.
Controls and limitations
Cal.com loads only after an intentional booking action. Visitors choose what information to submit in the booking form.
Provider privacy information

Ablo-owned components

These systems are part of Ablo and are not separate legal subprocessors. Their external infrastructure providers are included above.

AgentContainer

Ablo's owned execution system. It is part of the Ablo service and is not a separate legal subprocessor.

Gogs

An Ablo-operated repository service running in Railway's EU region. Railway is listed above as the infrastructure provider.

Redis

An Ablo-operated coordination service running in Railway's EU region. Railway is listed above as the infrastructure provider.

Browserless

An Ablo-operated browser service running on EU Hetzner infrastructure. Hetzner is listed above as the infrastructure provider.

Checkpoint registry

An Ablo-operated runtime checkpoint service running on EU Hetzner infrastructure. Hetzner is listed above as the infrastructure provider.

Other service classifications

Services used around Ablo that are not treated as subprocessors for customer workspace data under this policy.

GitHub

Used for Ablo source code and release artifacts. Customer workspace content is not intended to be stored there.

Customer-directed integrations

Services such as Google Workspace, Microsoft 365 and Slack are selected and controlled by the customer. They receive data only when the customer or an authorized agent uses the connected service.

Google Fonts

Ablo self-hosts product fonts, so Google Fonts does not receive visitor or customer requests.

Questions and changes

Questions about a provider or this register can be sent to privacy@ablo.no. Material changes are recorded in the Trust & Data change history.