EN
Language · same page NLNederlands/subverwerkers/ ENEnglish (UK)/en/sub-processors/ ESEspañol/es/subencargados/ We do not remember your choice and never redirect you automatically.
DOC.L1 · sub-processors register version 1.2 · 18 August 2026

Sub-processors: who works on our instructions

We do not do all of the work ourselves. For hosting, email, automation and AI we use other companies. This page says which ones, exactly what goes to each of them and where that happens. This list has been checked against the code of the site, not only against our own file.

Read the processing agreement What we process checked against the code of the site, not only against our own file
DOC.L1a · What this page covers

Why this list exists

The facts on this page do not change with the language, and we have not changed them. A supplier is where it is whatever language you read about it in. One thing does change, and it is the reason this is not a straight translation: if you are in the United Kingdom, the European Economic Area is abroad too. A Dutch reader sees "Ireland" and reads "inside the EEA, nothing to assess". A reader in the United Kingdom looking at the same row is looking at a transfer out of their own jurisdiction. So the location column below says which side of both borders a party sits on, and the open point about the route out of the United Kingdom is named rather than papered over.

If we process personal data on your behalf as a client, we are the processor and you are the controller. We record that in our data processing agreement. In it you give general authorisation for the parties we engage, and those parties are listed here. That way you know at any moment who is in the chain without having to ask for a list.

There are two kinds of party on this page, and the difference matters:

  • Sub-processors. They work on our instructions and may use the data only for the task we give them. We conclude a processing agreement with them. With one exception: for SerpApi that agreement is not in our file, and that is said in as many words in the table and in the open points at the bottom.
  • Other recipients. They decide in part for themselves what they do with data. For that part they are responsible themselves and their own terms apply alongside ours. Calling them a sub-processor would make the picture prettier than it is.

This page covers the website theseo.nl and the free tools on it, plus the software we build. For a live engagement a party may be added that applies to you alone. We put that in the order confirmation, not here.

DOC.L1b · Sub-processors

The parties that work on our instructions

These are the parties the site and the free tools actually call. We did not take them from a template: they are here because they appear in the code of the Worker that runs this site.

The table below is arranged per party. The figure is arranged the other way round, because that is usually the question: I do something on this site, where does it end up.

FIG.L1five routes, from what you do to who sees itsheet 1/2 · read from left to right, the party you meet first is on the left
Route 1 · you open a page
Your browserIP address, page, time
Cloudflarehosting and network · worldwide
Microsoft Claritymeasurement without cookies · Azure, EU contract
Route 2 · you fill in a generator
Your inputcompany, trade, town, contact if you give it
Our serverchecks it, then passes it on
Makeswitchboard · EU
OpenAIwrites the text · Ireland for the EEA
Google Sheetsrecord of the request
Route 3 · you request a website scan
The web addressthat you enter yourself
Our serverfetches the page, your browser does not
CloudflareDNS lookup · worldwide
Resendonly for an in-depth request, for the email · US
Route 4 · you run the local visibility check
Company name and townas a search query
Our serverassembles the query
SerpApithe map block · US
Google Placesdoes the business profile exist · US
Route 5 · what you entered lands in our own system
Your input and the resultplus origin and device type
Our serverthe only party with the key
Supabaseour database · project region Ireland

# A dashed frame is our own server: nothing goes outward from there by itself.
# Route 5 does not run separately but alongside routes 2, 3 and 4: every tool on this site records its request there. Your browser never talks to that database directly.
# The moving dot is the request travelling, and it is the whole subject of this figure.

PartyWhat they do for usWhat goes thereWhere, and on what basis
Cloudflare, Inc. · cloudflare.comHosting the site and the code behind the tools, plus the network in front of it. Also does the DNS lookups the website scan usesEvery request your browser makes: IP address, browser, page requested and time. For the scan also the web address you enter yourselfWorldwide network, established in the United States. Outside the EEA and outside the United Kingdom. Transfer under standard contractual clauses or the Data Privacy Framework
Make, part of Celonis · make.comThe generators for ad copy, review replies and business profile posts, and the AI brand checkEverything you enter in that form, plus your email address and telephone number if you give them, and the address of the page you filled it in onEuropean Union, recognisable by the hook address beginning with hook.eu1. Inside the EEA, which for a reader in the United Kingdom is still a transfer abroad
OpenAI · openai.comWrites the texts in those generators, through Make. Also queried directly in the model comparison on the AI brand checker page. That block is switched off today and only opens with ?multimodel=1 in the address; whoever opens it and presses the button does send the question to OpenAIThrough Make: what you enter in the form. Directly from our server: only the trade and the town. Your company name does not go there, it stays with us and is used only to compare the answerOpenAI Ireland for the EEA, with international sub-contractors. Transfer under standard contractual clauses
Google, for Gemini · ai.google.devAnswers the same question as the other models in the model comparison. That block sits on the AI brand checker page, is switched off today and only opens with ?multimodel=1 in the address. If it is used, the question really does go to GoogleOnly the trade and the town you enter. Your company name does not go thereDepends on the business contract chosen and the region. Transfer under standard contractual clauses or the Data Privacy Framework
Perplexity · perplexity.aiAnswers the same question as the other models in the model comparison. This also runs through the AI brand checker page, where the block is switched off today and only opens with ?multimodel=1 in the address. If it is used, the question really does go to PerplexityOnly the trade and the town you enter. Your company name does not go thereUnited States, with international sub-contractors. Outside the EEA and outside the United Kingdom. Transfer under standard contractual clauses
SerpApi · serpapi.comThe part about the local map block in the local visibility checkThe company name and the town you enter, as a search queryUnited States and the cloud providers they use. Note: there is no processing agreement with SerpApi in our file, and therefore no transfer safeguard such as standard contractual clauses. While that is the case, this party sits here as an open point and not as a recorded sub-processor, and only the search query you typed yourself goes there
Resend · resend.comSends the email when you request a manual scan: the one to us and the confirmation to youYour name, email address, telephone number, the address of your website, your message and the scores of the automatic scanUnited States, storage may take place there. Outside the EEA and outside the United Kingdom. Transfer under standard contractual clauses or the Data Privacy Framework
Supabase · supabase.comOur own database. Every request and every tool use from this site lands there, so that a request does not disappear into four separate listsWhat you entered in the form, what the tool gave back, the page you filled it in on, the referring site without the query string, the campaign code and the device type. No IP address and no cookieProject region Ireland, so inside the EEA. Sub-processors of Supabase may sit outside it; the standard contractual clauses from their processing agreement apply to those
# OPEN POINT
The date each supplier was taken into use belongs in this table. Our file does not record that date per supplier, so it is not in there: not yet established per party, on the basis of the signed processing agreement. The same holds for the exact contracting entity at Google, where the service and the account type decide which Google company you have a contract with.

Two things you rarely see in a table like this, but that hold here. The three language models at the top belong to the model comparison on the AI brand checker page. That block is switched off today: it is invisible while the switch in that page is off, and it only opens with ?multimodel=1 in the address.

Open it and press the button and the question really does go out to every model whose key sits on our server; if there is no key for any model, a message comes back and nothing goes outward. That is why we name them as a sub-processor now and not only once that switch is flipped. And the map block at SerpApi works only if a key has been set for it: if there is none, we skip that part and say in the result that it was not measured, rather than pretending you are not in it.

The website scan also fetches the page you enter yourself, including the robots file and the sitemap of that site. That is not a supplier of ours but the address you give, and that traffic comes from our server and not from your browser.

DOC.L1c · The chain behind Make

What happens inside Make

Make is not an endpoint for us but a switchboard. The generators send your input to a scenario in Make, and two things happen there. A language model from OpenAI writes the text, and the request is recorded in a spreadsheet at Google. Those two parties are therefore sub-contractors within that step.

If you enter no email address, that record stays limited to what you entered about your business. If you do enter one, you know it is a request and that we may follow it up. That is also stated at the form.

We deliberately send the webhook from our own server and not from your browser. That way the hook address is not sitting in the page for everyone to reach, and we can check your input first.

DOC.L1d · Other recipients

Parties that decide in part for themselves

These parties also receive data, but not as our sub-processor. They have their own purposes and their own terms. We name them separately because putting them in one list with the rest would give a false picture of who is answerable for what.

The difference between the two lists is not one of size, of importance, or of how much we trust a party. It is a single question, and the answer decides who you can turn to when something goes wrong. That is why we draw it instead of defining it.

FIG.L2: the question that decides which list a party lands insheet 2/2 · one question, two different consequences for you
Who decides what your data is used for over there?not who is bigger, and not whose name you happen to know
▶ WE DECIDEsub-processor · belongs in the table above Cloudflare Make OpenAI Google, for Gemini Perplexity SerpApi Resend Supabase They work on our instructions and for our purpose. We chose them, we can replace them, and we answer for what they do with your data. If something goes wrong there, you write to us.
◀ THEY DECIDEcontroller in their own right · belongs in the table below Google, for Calendar and Meet Google, for Maps and Places Stripe GitHub Microsoft, for Clarity They have their own purposes and their own terms, and those terms apply to you directly. We cannot change what they do and we cannot promise anything on their behalf. For a right over that data, they are the party you address, and we tell you which one it is.
The right-hand column is the one that surprises people. It holds parties you deal with yourself: you fill in Google's appointment page, or you pay on Stripe's own page. Those pages are not ours, which is why we cannot govern what happens inside them. Saying so is less comfortable than one long list, and it is the only version that tells you who to turn to.
PartyWhere you meet itWhat goes thereWhere
Google, for Calendar and Meet · calendar.google.comThe Book a call button, and the calendar on the scheduling page. There are two routes: the calendar on our own page, and Google's appointment page that the button still leads to on most pagesThrough our own page: your name, email address, company name, the chosen time and what the call is about, passed on from our server to create the appointment and the Meet meeting. Through Google's appointment page: what you enter there yourself, usually your name, email address and the chosen time; that page belongs to Google, not to us. In both cases the appointment lands in our calendar and Google sends you the invitationIreland and the United States
Google, for Maps and Places · developers.google.com/mapsThe local visibility check, which looks up whether your business has a Google Business ProfileThe company name and the town you enter, as a search query from our serverUnited States and worldwide
Stripe · stripe.comThe payment buttons on the pages about our link building platformWhat you enter on Stripe's own payment page. That page belongs to Stripe, not to usUnited States and Ireland
GitHub · github.comLinks to our public repositories with skills and codeOnly what your browser passes on if you follow such a link. There is no client data and there are no keys in our public repositoriesInternational
Microsoft, for Clarity · clarity.microsoft.comThe usage measurement that runs on every page, in cookieless mode. Nothing is placed on your device or read from it, and every page view counts as a separate sessionPage views, click, scroll and mouse movement and technical data such as browser, device and country. What you type into input fields is masked and does not go along. Microsoft keeps recordings for 30 days and aggregated click and heatmap data for 13 monthsMicrosoft's Azure cloud. For the EU the contracting party is Microsoft Ireland Operations Limited; processing in the United States falls, according to Microsoft, under the standard contractual clauses between the Microsoft companies

Microsoft is in this list and not with the sub-processors, because Microsoft regards itself as a controller for Clarity and processes the measurement data partly under its own terms. That is why we deliberately keep what goes there small: no cookies, masked input fields, and nothing that follows you across pages. How that measurement is set up exactly is on the cookie page.

On some pages we link to mansotti.com. That is not a third party: Mansotti is the company TheSEO is a trading name of, so that is a reference to ourselves.

DOC.L1e · Software

The suppliers behind our software

Alongside the website we build software: the MyParcel Dashboard, Jarvis and LinkLoop. That comes with a chain of its own. The parties below sit in the architecture of those products. So they do not automatically process data of every client: what applies in your case is in the annex to your processing agreement and in your order confirmation.

If you take out Jarvis, the trust centre sets out briefly which parts of this list apply to Jarvis. This list stays the leading text; that page is the explanation next to it.

PartyWhat forWhere
Cloudflare, Inc.Hosting, network and security of the applicationsWorldwide network
SupabaseSign-in, database, storage and background functionsProject region in the EU. Sub-processors of Supabase may sit outside the EEA
StripeCheckout, invoices, subscription status and fraud preventionEEA, United States and worldwide
ResendTransactional email from the applicationsUnited States
OpenAIAI functions in Jarvis and in the generatorsOpenAI Ireland for the EEA
MyParcel B.V.The official shipping data and the API the dashboard readsAccording to the contract you have with MyParcel

Two things we say out loud alongside it. The MyParcel connection runs through your own account and your own permissions: the dashboard is a separate product and has no relationship with MyParcel B.V. And for as long as a product is not yet running in production, the supplier that belongs to it is not processing client data either.

The eight free WordPress plugins: no party sits in between

On tools and plugins there are eight plugins you can download: the heatmap and scrollmap, the Core Web Vitals plugin, the AI crawler log, the accessibility statement, the local schema with company and VAT number, the AI transparency label, the llms.txt generator and the AI snippet previewer. They belong here because people rightly ask about them, and the answer is short: installing these plugins does not make TheSEO a processor and does not add a sub-processor. The software runs on your server, in your WordPress, under your control. Not a single request comes to us, we get no notice of an installation and we cannot reach the data the plugin records.

With six of the eight, nothing goes outward at all. The heatmap and the Core Web Vitals plugin write only to your own database, the AI crawler log writes only what arrived at your own server, and the llms.txt generator, the local schema and the AI transparency label read only your own settings. For those six, a search for wp_remote_, curl_init and file_get_contents in the zip established that there is no outbound request in them at all; that check was done on 19 August 2026 and returns zero hits.

The accessibility plugin is the seventh and it only talks to you: in page mode it fetches your own page from your own domain in order to judge the page language, the page title and the viewport. No party comes in between and nothing goes to another domain; in content mode, which is the default, it does not even do that.

The eighth has a switch with a consequence, and that is why it is listed here: if you put your own OpenAI key into the AI snippet previewer, your server sends the page title, up to eight thousand characters of page text, the context you entered yourself and the measured figures to OpenAI. That traffic runs on your account and at your expense.

In that chain you are the controller and OpenAI is your processor; we are not a party to it and see nothing of it. So if you process personal data on such a page, that is your assessment and your processing agreement with OpenAI. Without a key that plugin makes a single request: from your server to your own published page, to see whether there is structured data in it.

DOC.L1f · Outside Europe

Data that leaves the EEA, and what that means from the United Kingdom

Some of the parties above sit in the United States. For transfers there, the European Commission's standard contractual clauses apply, or the EU-US Data Privacy Framework where the party in question is certified under it. Both are recognised safeguards under the GDPR. Where needed, additional measures come on top, such as encryption and limiting the fields we send along.

Make runs on a European environment, so that step does not leave the EEA.

# OPEN POINT, AND IT IS THE ONE A READER IN THE UNITED KINGDOM SHOULD SEE FIRST
Everything in the paragraph above describes the European route. If your own transfer starts in the United Kingdom, the United Kingdom's own transfer regime applies to it, which is a separate instrument with its own paperwork. Which instrument fits our chain, and what that means for a route running from the United Kingdom into the European Union, is a question for a lawyer and not one to fill in on instinct. We name it as open rather than answering it with a European clause wearing a British label. What we can already tell you is exactly where every party sits, and that is the table above.

Below is what the arrangement with each party rests on. These agreements are in our own supplier register, with version and date.

PartyWhat the arrangement rests on
CloudflareThe Cloudflare Customer DPA version 6.4, with the standard contractual clauses in it, plus their own sub-processor list
MakeMake's processing agreement, with their description of measures, their sub-processor list and the standard contractual clauses for transfers arising inside their chain
OpenAIOpenAI's processing agreement with the accompanying sub-processor list, as recorded in our own supplier file. We could not read the version numbers and dates OpenAI gives it directly on their site when drawing up this page; so we do not name them here, and we will record them as soon as we can establish them at OpenAI itself
ResendResend's processing agreement with the standard contractual clauses, plus their sub-processor list
Google, for Places and for the spreadsheet behind MakeGoogle's own terms for those services, with the standard contractual clauses or the Data Privacy Framework according to Google itself
Google, for GeminiThe Google Cloud processing agreement for the service that falls under it. Which one that is depends on the account and the service chosen, and we record that before more than a trade and a town goes there
PerplexityPerplexity's processing agreement and API terms. While those are not in our file, only a trade and a town go there
SerpApiSerpApi's legal terms and privacy text, as recorded in our own supplier file. There is no suitable processing agreement in that file, and therefore no transfer safeguard either; that is why only the search query you type yourself goes there. Open point
StripeStripe's processing agreement of 18 November 2025. Per service it applies the standard contractual clauses or the Data Privacy Framework
SupabaseSupabase's processing agreement with their information on regions and sub-processors, as recorded in our own supplier file. We have not recorded the version number and date Supabase gives it; we will do that at the next update of this register

Where there is a choice between standard contractual clauses and the Data Privacy Framework, that is because the supplier arranges it per service. Which of the two applies in your case we record per service. That is not a loose end in the protection: both are recognised safeguards under the GDPR.

If you ask, we give the relevant information about a transfer or an available copy of the safeguard. We may redact confidential parts of it.

DOC.L1g · Dropped

What is no longer on this list

Google Fonts was on it until recently. The fonts were then fetched from Google at the moment you opened a page, which sent your IP address there without you doing anything. Those fonts now sit on our own server. We have gone through the code and there is no reference to Google Fonts left, in any file.

Beyond that there are no advertising pixels on this site. No Google Analytics and no pixels from Google, Meta or LinkedIn. The only measurement is Microsoft Clarity, in cookieless mode; that one is above with the other recipients. There is no cookie banner, because nothing is placed on your device that asks for consent. What we do and do not do exactly is in our privacy statement and on the cookie page.

DOC.L1h · Changes

What happens if a party is added

Suppliers change. We follow their announcements and update this list. If a new or replacement sub-processor comes in that will process client data, we give notice in principle at least 30 days in advance, as set out in the processing agreement.

If you are a client and you have a concrete privacy objection to that new party, you can raise it with us with reasons within that period. We then look for a reasonable solution together, for instance a different setting or an alternative. If that does not work, you may end the part it affects before the new party is taken into use.

If a supplier has to be replaced urgently for security or continuity reasons, that can go faster. We then let you know as soon as possible.

A supplier whose evidence has expired gets no new data from us until it has been assessed again. That is an internal rule, but it does decide what happens to your data in practice, so you may know it.

DOC.L1i · Open points

What is not complete here yet

What is still missing we would rather name. These points are not settled:

  • The start date per supplier, as soon as the processing agreement with that party has been signed and stored.
  • The exact contracting entity at Google, which differs per service and account type.
  • A direct link per supplier to its own sub-processor list. For now we point at the supplier's website, because we do not want to write down an address we have not checked.
  • The processing agreement with SerpApi. It is not in our file, and with it a transfer safeguard is missing too. That is why only the search query you type yourself goes there: a company name and a town. We do not pretend that automatically falls outside data protection law, because with a sole trader the company name is often a person's name.
  • The processing agreement and account evidence for Gemini and Perplexity. While those are absent, the model comparison stays limited to a trade and a town.
  • The inventory of the scenarios in Make, so that it is established per scenario exactly which fields pass through.
  • The transfer route out of the United Kingdom and the instrument that goes with it, named above and repeated here so it is not lost.

Questions about this list, or would you like a copy of a processing agreement with one of these parties? Email sales@theseo.nl with sub-processors in the subject line.

Register version 1.2 · last changed on 25 August 2026. Added in 1.2: Supabase as the database behind the site, with route 5 in the figure. Added in 1.1: Microsoft Clarity with the other recipients

Section · Next stepreachable 24/7
Book a call