Subprocessors

Effective 14 August 2026 · Version 3.0

NovaBuild uses a small set of infrastructure providers to run agents, sandboxes, databases, hosting, email and payments. This page lists them, what each one processes, where processing happens, and the transfer mechanism we rely on. It is the authoritative list referenced by Annex 3 of the Data Processing Addendum.

Plain language summary

  • Model providers receive prompts and the file context needed to answer them.
  • The sandbox provider receives project files in order to install, typecheck, run and build them.
  • The database provider stores accounts, projects, chat history, encrypted credentials and the credit ledger.
  • We give workspace owners at least 30 days notice before adding a subprocessor that touches customer data.

The summary is for orientation only. The numbered sections below are the operative text.

1. How to read this page

A subprocessor is a company that processes data on our behalf so that we can deliver the service. For each entry we show the purpose, the data categories involved, the primary processing regions, and the mechanism used for transfers out of the European Economic Area and the United Kingdom. Where a provider is covered by an adequacy decision we say so, and otherwise we rely on the Standard Contractual Clauses with the UK Addendum.

2. Model providers

A model provider receives the prompt, the relevant slices of the project file tree, tool results and conversation history for the run routed to it. Routing depends on the model you or your workspace selects. Provider agreements are configured to exclude our traffic from provider model training where the provider offers that control.

ProviderPurposeData processedRegionsTransfers
AnthropicClaude models for planning and code generationPrompts, file context, tool outputUnited StatesSCCs and UK Addendum
OpenAIGPT models for planning, code generation and embeddingsPrompts, file context, tool outputUnited States, European UnionSCCs and UK Addendum
GoogleGemini models for planning, code generation and multimodal inputPrompts, file context, images you attachUnited States, European UnionSCCs and UK Addendum
OpenRouterRouting layer for additional models you selectPrompts, file contextUnited StatesSCCs and UK Addendum

3. Compute and sandboxes

ProviderPurposeData processedRegionsTransfers
E2BIsolated containers that install dependencies, run dev servers, typecheck and build projectsProject files, environment variables injected at run time, build logsUnited States, European UnionSCCs and UK Addendum

Sandbox contents are ephemeral. When a machine is stopped by you or by the idle reaper, its file system is discarded. Only what is stored in your project file tree or a connected database persists.

4. Database, authentication and storage

ProviderPurposeData processedRegionsTransfers
SupabaseManaged Postgres, authentication, row level security and object storageAccounts, workspaces, projects, files, chat history, agent logs, encrypted credentials, credit ledger, audit logEuropean Union or United States depending on project regionSCCs and UK Addendum where applicable
Amazon Web ServicesUnderlying infrastructure for the managed database and storage layerEncrypted data at rest and in transitEuropean Union, United StatesSCCs and UK Addendum

5. Hosting, delivery and domains

ProviderPurposeData processedRegionsTransfers
CloudflareEdge hosting of the platform, content delivery, DNS, custom domain verification, TLS termination and abuse protectionRequest metadata, IP address, user agent, deployed static assetsGlobal edge networkSCCs and UK Addendum

6. Transactional email

ProviderPurposeData processedRegionsTransfers
ResendSending account, security, deployment and referral emailsEmail address, display name, message content, delivery and bounce statusUnited States, European UnionSCCs and UK Addendum

We send service and security notices on the basis of contract, and product marketing only with consent. Delivery metadata is retained so we can prove that a security notice was sent.

7. Payments and tax

ProviderPurposeData processedRegionsTransfers
Payment processorCard and wallet processing, subscription billing, invoices, tax calculation and fraud checksName, billing address, email, tax identifier, partial card metadata, transaction historyUnited States, European UnionSCCs and UK Addendum

Full card numbers never reach NovaBuild systems. The processor acts as an independent controller for fraud prevention and regulatory duties, and as our processor for billing on our behalf.

8. Monitoring and product analytics

ProviderPurposeData processedRegionsTransfers
Error and performance monitoringCapturing stack traces, request timings and platform healthError messages, stack traces, request path, coarse location, pseudonymous identifierEuropean Union, United StatesSCCs and UK Addendum
First party product analyticsAggregate measurement of flows, failures and adoptionEvent names, timestamps, pseudonymous identifier, countryEuropean UnionAdequacy or SCCs

We do not send prompts, project source code or credential values to monitoring or analytics providers. Stack traces are scrubbed of obvious secret patterns before they leave the platform.

9. Internal tools with incidental access

  • Support desk and email, which holds correspondence you send us.
  • Version control and issue tracking, which may contain a redacted extract you attach to a bug report.
  • Identity and device management for staff, which holds no customer data.

These tools are bound by confidentiality and data protection terms and are used on a need to know basis.

10. When you bring your own provider

If you store your own model provider key, database connection string or deployment token, the provider you chose acts under your own account and their terms apply directly to you. In that arrangement they are your subprocessor rather than ours, and we act on your instruction to use the credential.

11. Notification of changes and objection

We update this page whenever the list changes, and workspace owners are notified at least 30 days before a new subprocessor begins processing customer data where that is feasible. You may object on reasonable data protection grounds by emailing privacy@novabuild.dev within the notice period. If we cannot offer a practical alternative you may terminate the affected part of the service and receive a pro rata refund of prepaid fees for the unused period.

12. How we vet a subprocessor

Before onboarding

  • Review of their security documentation, certifications and public incident history.
  • Confirmation of a data processing agreement with terms no less protective than our own addendum.
  • Confirmation of a lawful transfer mechanism and of processing locations.
  • Assessment of data minimisation, so that a provider only receives what its function requires.
  • Exit planning, so we can move away without losing your data.

While in use

  • Periodic review of their security posture and any published incidents.
  • Monitoring of availability and error rates, with failover where the architecture allows.
  • Prompt reassessment after a material change of ownership or of subprocessing on their side.

13. Contact

Questions, objections or a request for the transfer paperwork for a specific provider: privacy@novabuild.dev.

This document is published by the NovaBuild team as general information about the service. It is not legal advice, and it is not a certification or an independent audit of NovaBuild or of any third party. If anything here is unclear, or you need a countersigned copy for procurement, email legal@novabuild.dev.