Combra — Sub-processors
Last updated: 13 August 2026
This page lists the third parties ("Sub-processors" and other service providers) that Fabrique-Futur LLC engages to process personal data in providing Combra. It supports our Privacy Policy and Data Processing Addendum. We may update this list; material changes to Customer Data sub-processors are notified as described in the DPA (at least 15 days' notice before a new Sub-processor begins processing, with an objection right).
- Default — "Core" means active for every account; "Conditional" means active only when you enable the related feature or connector.
- Transfer mechanism — the safeguard relied on for transfers from the EEA/UK/Switzerland: 2021 EU SCCs (with the UK Addendum/IDTA) as the primary mechanism, and the EU-US Data Privacy Framework (DPF) as an additional basis for certified vendors.
A. Sub-processors that process Customer Data
These process the content you submit or connect (and personal data it may contain).
| Sub-processor (entity) | Purpose | Customer Data processed | Location | Transfer mechanism | Default |
|---|---|---|---|---|---|
| DigitalOcean, LLC | Cloud hosting/compute; managed PostgreSQL; managed Valkey (cache/queue); Spaces object storage | All stored Customer Data and uploaded files | United States (NYC region) | DPF (certified) + SCCs | Core |
| Google LLC (Gemini API) | Model inference — answer generation, query classification, fact extraction, and reading page images of uploaded documents | Retrieved document text, queries, page images, and generated Output | United States / global | DPF (Google LLC certified) + SCCs | Core |
| Anthropic PBC | Model inference — the cross-provider fallback for answer generation and fact extraction when the primary model provider is unavailable | Retrieved document text, queries, and generated Output | United States | SCCs | Core |
| Jina AI GmbH | Embeddings and reranking of document text and queries | Every ingested chunk, table row, and extracted fact statement; and every query at ask time | European Union (Germany) | Intra-EEA processing; SCCs for any onward US transfer | Core |
| Deepgram, Inc. | Speech-to-text for voice input | The audio you record, and the transcript returned | United States | SCCs | Conditional (voice input) |
| DuckDuckGo (Duck Duck Go, Inc.) | Public web search when no source in your workspace grounds the question | A short search query rewritten from your question. No document text is sent | United States | SCCs | Conditional (web fallback, when our own search backend is unavailable or returns nothing) |
| Cloudflare, Inc. | DNS, CDN, and edge/TLS proxy for combra.ai | Request data in transit, IP addresses, network metadata | United States / global edge | DPF (certified) + SCCs | Core |
| Slack Technologies, LLC / Salesforce, Inc. | Slack connector — ingest and answer in connected workspaces | Selected channel messages; Slack user name/email for attribution | United States (EU residency on certain Slack plans) | DPF (via Salesforce) + SCCs | Conditional (Slack connector) |
| Notion Labs, Inc. | Notion connector — import selected pages/databases | Content of pages/databases you share with the integration | United States (EU residency on Enterprise) | SCCs | Conditional (Notion connector) |
| Google LLC | Google Drive connector — import selected files | Files you select via the Drive picker (least-privilege drive.file scope; access token discarded after import) | United States / regional options | DPF (Google LLC certified) + SCCs | Conditional (Google Drive connector) |
| Sinch (Mailgun) | Outbound and inbound email delivery and parsing | Recipient email address and the content of system email. Digest email carries extracts of your own knowledge, so it is Customer Data in transit. Inbound email, when enabled, is parsed into Sources and may carry anything a sender writes | United States or European Union (region-selectable) | SCCs (DPF where applicable) | Core (transactional email); Conditional (digest, inbound email) |
B. Other service providers (account and usage data)
These process account, billing, or usage data that we control, not the substance of your Customer Data.
| Provider (entity) | Purpose | Data processed | Location | Transfer mechanism | Default |
|---|---|---|---|---|---|
| Stripe, Inc. | Subscription billing and payment processing | Company name, our internal company identifier, seat count, and subscription/payment metadata. Your billing email and card details are collected by Stripe's own hosted checkout page; we neither send nor store them | United States + international | DPF (certified) + SCCs | Conditional (paid plans) |
| PostHog, Inc. | Product analytics to operate and improve the Service | Product-usage/interaction events, pseudonymous identifiers; cookieless; autocapture and session recording disabled; not used to train PostHog's AI models; never document, query, or answer content | United States (PostHog Cloud US) | DPF (with UK Extension where applicable) + SCCs | Core |
| Self-hosted GlitchTip | Error monitoring | Error events with request correlation IDs; configured to exclude request bodies, cookies, and stack-frame locals (PII-minimizing) | Self-hosted on our DigitalOcean infrastructure (United States, NYC) | Same as DigitalOcean | Conditional (error monitoring) |
Notes
- Model inference. We call model providers directly, not through a hosting intermediary. Google (Gemini) serves answer generation, query classification, fact extraction, and vision reading of uploaded pages; Anthropic (Claude) is the cross-provider fallback that keeps the Service answering when Gemini is unavailable, and is therefore reached in normal operation. Both are direct sub-processors of Fabrique-Futur. We contract with both for business use of their APIs and do not permit either to use Customer Data to train its models; each provider's API terms govern data submitted to it.
- Jina AI. Jina's published terms reserve a right to use customer data in anonymized form to improve its own AI. We state this rather than claim a protection we do not hold. Jina is the one Core AI sub-processor for which we cannot assert a no-training position, and it is reached by every document you ingest.
- Bring your own key. A company can supply its own Google (Gemini) or Anthropic API key for answer generation and classification. When it does, the same two vendors receive the same content; what changes is that the call runs under your own account and your own agreement with that provider, so their terms with you govern it. Fact extraction, embeddings, and reranking always run on our platform keys, so this does not remove Google or Jina from the chain.
- Web search. When no source in your workspace grounds a question, the Service can answer from the public web. What leaves is a short search query rewritten from your question — never document text. The query goes to our own self-hosted search backend where one is configured, and to DuckDuckGo where it is not or where it returns nothing. The Service then fetches the public pages it cites directly from the sites that publish them, which see our request, not your identity.
- Self-hosted, not sub-processed. Our error monitoring (GlitchTip), our marketing-site analytics (Umami), and our search backend run on infrastructure we control. They are covered by the DigitalOcean row above rather than by a separate vendor.
- PostHog region. We use PostHog Cloud US, configured so our analytics data is not used to train PostHog's models. For transfers of EEA or UK personal data, PostHog states that it participates in the applicable Data Privacy Framework program where available, and SCCs (with the UK Addendum or IDTA) apply where required. PostHog receives product-usage metadata only, never the content of documents, queries, or answers; the integration is cookieless with autocapture and session recording disabled.
For questions about this list, contact [email protected].