Subprocessors
Effective 14 August 2026 · Version 3.0
NovaBuild uses a small set of infrastructure providers to run agents, sandboxes, databases, hosting, email and payments. This page lists them, what each one processes, where processing happens, and the transfer mechanism we rely on. It is the authoritative list referenced by Annex 3 of the Data Processing Addendum.
Plain language summary
- Model providers receive prompts and the file context needed to answer them.
- The sandbox provider receives project files in order to install, typecheck, run and build them.
- The database provider stores accounts, projects, chat history, encrypted credentials and the credit ledger.
- We give workspace owners at least 30 days notice before adding a subprocessor that touches customer data.
The summary is for orientation only. The numbered sections below are the operative text.
1. How to read this page
A subprocessor is a company that processes data on our behalf so that we can deliver the service. For each entry we show the purpose, the data categories involved, the primary processing regions, and the mechanism used for transfers out of the European Economic Area and the United Kingdom. Where a provider is covered by an adequacy decision we say so, and otherwise we rely on the Standard Contractual Clauses with the UK Addendum.
2. Model providers
A model provider receives the prompt, the relevant slices of the project file tree, tool results and conversation history for the run routed to it. Routing depends on the model you or your workspace selects. Provider agreements are configured to exclude our traffic from provider model training where the provider offers that control.
| Provider | Purpose | Data processed | Regions | Transfers |
|---|---|---|---|---|
| Anthropic | Claude models for planning and code generation | Prompts, file context, tool output | United States | SCCs and UK Addendum |
| OpenAI | GPT models for planning, code generation and embeddings | Prompts, file context, tool output | United States, European Union | SCCs and UK Addendum |
| Gemini models for planning, code generation and multimodal input | Prompts, file context, images you attach | United States, European Union | SCCs and UK Addendum | |
| OpenRouter | Routing layer for additional models you select | Prompts, file context | United States | SCCs and UK Addendum |
3. Compute and sandboxes
| Provider | Purpose | Data processed | Regions | Transfers |
|---|---|---|---|---|
| E2B | Isolated containers that install dependencies, run dev servers, typecheck and build projects | Project files, environment variables injected at run time, build logs | United States, European Union | SCCs and UK Addendum |
Sandbox contents are ephemeral. When a machine is stopped by you or by the idle reaper, its file system is discarded. Only what is stored in your project file tree or a connected database persists.
4. Database, authentication and storage
| Provider | Purpose | Data processed | Regions | Transfers |
|---|---|---|---|---|
| Supabase | Managed Postgres, authentication, row level security and object storage | Accounts, workspaces, projects, files, chat history, agent logs, encrypted credentials, credit ledger, audit log | European Union or United States depending on project region | SCCs and UK Addendum where applicable |
| Amazon Web Services | Underlying infrastructure for the managed database and storage layer | Encrypted data at rest and in transit | European Union, United States | SCCs and UK Addendum |
5. Hosting, delivery and domains
| Provider | Purpose | Data processed | Regions | Transfers |
|---|---|---|---|---|
| Cloudflare | Edge hosting of the platform, content delivery, DNS, custom domain verification, TLS termination and abuse protection | Request metadata, IP address, user agent, deployed static assets | Global edge network | SCCs and UK Addendum |
6. Transactional email
| Provider | Purpose | Data processed | Regions | Transfers |
|---|---|---|---|---|
| Resend | Sending account, security, deployment and referral emails | Email address, display name, message content, delivery and bounce status | United States, European Union | SCCs and UK Addendum |
We send service and security notices on the basis of contract, and product marketing only with consent. Delivery metadata is retained so we can prove that a security notice was sent.
7. Payments and tax
| Provider | Purpose | Data processed | Regions | Transfers |
|---|---|---|---|---|
| Payment processor | Card and wallet processing, subscription billing, invoices, tax calculation and fraud checks | Name, billing address, email, tax identifier, partial card metadata, transaction history | United States, European Union | SCCs and UK Addendum |
Full card numbers never reach NovaBuild systems. The processor acts as an independent controller for fraud prevention and regulatory duties, and as our processor for billing on our behalf.
8. Monitoring and product analytics
| Provider | Purpose | Data processed | Regions | Transfers |
|---|---|---|---|---|
| Error and performance monitoring | Capturing stack traces, request timings and platform health | Error messages, stack traces, request path, coarse location, pseudonymous identifier | European Union, United States | SCCs and UK Addendum |
| First party product analytics | Aggregate measurement of flows, failures and adoption | Event names, timestamps, pseudonymous identifier, country | European Union | Adequacy or SCCs |
We do not send prompts, project source code or credential values to monitoring or analytics providers. Stack traces are scrubbed of obvious secret patterns before they leave the platform.
9. Internal tools with incidental access
- Support desk and email, which holds correspondence you send us.
- Version control and issue tracking, which may contain a redacted extract you attach to a bug report.
- Identity and device management for staff, which holds no customer data.
These tools are bound by confidentiality and data protection terms and are used on a need to know basis.
10. When you bring your own provider
If you store your own model provider key, database connection string or deployment token, the provider you chose acts under your own account and their terms apply directly to you. In that arrangement they are your subprocessor rather than ours, and we act on your instruction to use the credential.
11. Notification of changes and objection
We update this page whenever the list changes, and workspace owners are notified at least 30 days before a new subprocessor begins processing customer data where that is feasible. You may object on reasonable data protection grounds by emailing privacy@novabuild.dev within the notice period. If we cannot offer a practical alternative you may terminate the affected part of the service and receive a pro rata refund of prepaid fees for the unused period.
12. How we vet a subprocessor
Before onboarding
- Review of their security documentation, certifications and public incident history.
- Confirmation of a data processing agreement with terms no less protective than our own addendum.
- Confirmation of a lawful transfer mechanism and of processing locations.
- Assessment of data minimisation, so that a provider only receives what its function requires.
- Exit planning, so we can move away without losing your data.
While in use
- Periodic review of their security posture and any published incidents.
- Monitoring of availability and error rates, with failover where the architecture allows.
- Prompt reassessment after a material change of ownership or of subprocessing on their side.
13. Contact
Questions, objections or a request for the transfer paperwork for a specific provider: privacy@novabuild.dev.
This document is published by the NovaBuild team as general information about the service. It is not legal advice, and it is not a certification or an independent audit of NovaBuild or of any third party. If anything here is unclear, or you need a countersigned copy for procurement, email legal@novabuild.dev.