Combra — Sub-processors
Last updated: 6 July 2026
This page lists the third parties ("Sub-processors" and other service providers) that Fabrique-Futur LLC engages to process personal data in providing Combra. It supports our Privacy Policy and Data Processing Addendum. We may update this list; material changes to Customer Data sub-processors are notified as described in the DPA (at least 15 days' notice before a new Sub-processor begins processing, with an objection right).
- Default — "Core" means active for every account; "Conditional" means active only when you enable the related feature or connector.
- Transfer mechanism — the safeguard relied on for transfers from the EEA/UK/Switzerland: 2021 EU SCCs (with the UK Addendum/IDTA) as the primary mechanism, and the EU-US Data Privacy Framework (DPF) as an additional basis for certified vendors.
A. Sub-processors that process Customer Data
These process the content you submit or connect (and personal data it may contain).
| Sub-processor (entity) | Purpose | Customer Data processed | Location | Transfer mechanism | Default |
|---|---|---|---|---|---|
| DigitalOcean, LLC | Cloud hosting/compute; managed PostgreSQL; managed Valkey (cache/queue); Spaces object storage; GenAI/serverless inference for answer generation | All stored Customer Data, uploaded files, queries, and generated Output | United States (NYC region) | DPF (certified) + SCCs | Core |
| Jina AI GmbH | Embeddings and reranking of document text and queries | Document text and query text | European Union (Germany) | Intra-EEA processing; SCCs for any onward US transfer | Core |
| Cloudflare, Inc. | DNS, CDN, and edge/TLS proxy for combra.ai | Request data in transit, IP addresses, network metadata | United States / global edge | DPF (certified) + SCCs | Core |
| Slack Technologies, LLC / Salesforce, Inc. | Slack connector — ingest and answer in connected workspaces | Selected channel messages; Slack user name/email for attribution | United States (EU residency on certain Slack plans) | DPF (via Salesforce) + SCCs | Conditional (Slack connector) |
| Notion Labs, Inc. | Notion connector — import selected pages/databases | Content of pages/databases you share with the integration | United States (EU residency on Enterprise) | SCCs | Conditional (Notion connector) |
| Google LLC | Google Drive connector — import selected files | Files you select via the Drive picker (least-privilege drive.file scope; access token discarded after import) | United States / regional options | DPF (Google LLC certified) + SCCs | Conditional (Google Drive connector) |
| Sinch (Mailgun) | Transactional and inbound email delivery and parsing | Recipient email and system-email content; parsed inbound email when inbound email is enabled (may contain Customer Data) | United States or European Union (region-selectable) | SCCs (DPF where applicable) | Conditional (email features) |
B. Other service providers (account and usage data)
These process account, billing, or usage data that we control, not the substance of your Customer Data.
| Provider (entity) | Purpose | Data processed | Location | Transfer mechanism | Default |
|---|---|---|---|---|---|
| Stripe, Inc. | Subscription billing and payment processing | Billing contact, company name, seat count, subscription/payment metadata (card data handled by Stripe; we do not store it) | United States + international | DPF (certified) + SCCs | Conditional (paid plans) |
| PostHog, Inc. | Product analytics to operate and improve the Service | Product-usage/interaction events, pseudonymous identifiers; cookieless; autocapture and session recording disabled; not used to train PostHog's AI models; never document, query, or answer content | United States (PostHog Cloud US) | DPF (with UK Extension where applicable) + SCCs | Core |
| Self-hosted GlitchTip | Error monitoring | Error events with request correlation IDs; configured to exclude request bodies, cookies, and stack-frame locals (PII-minimizing) | Self-hosted on our DigitalOcean infrastructure (United States, NYC) | Same as DigitalOcean | Conditional (error monitoring) |
Notes
- Models behind DigitalOcean inference. Answer generation runs through DigitalOcean's GenAI/serverless inference, which serves models including Anthropic's Claude and open-weight models. These model providers are DigitalOcean's sub-processors, not direct sub-processors of Fabrique-Futur; we do not send Customer Data to Anthropic's API directly. Under the applicable commercial terms, these models are not trained on Customer Data.
- PostHog region. We use PostHog Cloud US, configured so our analytics data is not used to train PostHog's models. For transfers of EEA or UK personal data, PostHog states that it participates in the applicable Data Privacy Framework program where available, and SCCs (with the UK Addendum or IDTA) apply where required. PostHog receives product-usage metadata only, never the content of documents, queries, or answers; the integration is cookieless with autocapture and session recording disabled.
For questions about this list, contact [email protected].