Sub-processors
Who helps us run GatPilot, what data each one receives and where.
Last updated: 8 October 2026 · Version 1
In short
The list, in short
The summary helps you find what matters; the full text below is the one that applies.
The database is at Hetzner, on a server in Nuremberg, Germany.
OpenAI does the knowledge search on every plan and writes the answers on our model.
You choose the provider of your AI key, and the contract with it is yours.
Telegram and Viber deliver the messages under their own rules, as platforms you choose.
We announce a new sub-processor at least 30 days in advance.
We do not use advertising networks, nor programs that track people from one website to another.
01 · About
About this list
Who helps us run GatPilot and what data each one touches.
GatPilot is a service operated by TOPFED WEB S.R.L., a limited liability company registered in the Republic of Moldova under IDNO 1026023125543. The company's registered office is in Chișinău, Republic of Moldova.
The providers below help us run GatPilot. When they process personal data for us, they are our sub-processors under the Data Processing Agreement.
The table also shows the ones you choose, marked “chosen by you”. The last column says whether a provider receives the data we process for you: conversations, knowledge, team members, data from your systems.
02 · Providers
The providers and the data they receive
The complete list, read from the service's code, with each one's role.
| Provider | Role | Data it receives | Where | Receives customer data? |
|---|---|---|---|---|
| Hetzner Online GmbH | Sub-processor. The server that runs the websites, the dashboard, the API and the background processes, together with the database. | Everything in the database and in the server logs. | Germany (Nuremberg) | Yes |
| Cloudflare, Inc. | Sub-processor. DNS, delivery and protection of gatpilot.md and gatpilot.com: all traffic passes through Cloudflare. | All traffic to and from the websites, the dashboard, the API and the widget, with IP addresses, in transit. The visitor's country sets the currency on gatpilot.com. | US company, with a global network | Yes, in transit |
| OpenAI | Sub-processor. Turns chunks and questions into numerical vectors for search, on every plan. Writes the answers on our model: on Free, and on Custom without your key. | At indexing, the text of the sources; with every message to the Sales or Team Assistant, the question. For an answer on our model: the instructions, 5 chunks, the contact details shown to visitors, the current time and at most 20 recent messages. For the Management Assistant: the instructions, the date, the conversation and the query results. | United States | Yes |
| Sendinblue SAS (Brevo) | Sub-processor. Sends the product's and the website's emails: invitations, account codes and links, the alert when a customer is waiting for a person, the forms and internal notifications. It also keeps the newsletter subscriber list. | The recipients' names and addresses and the content of the emails. The alert contains the customer's question and the assistant's answer. | France | Yes, in the alerts |
| Google LLC (Firebase) | Sub-processor. Authentication for the dashboard and the GatPilot app. On Android, it also delivers the notifications received from Expo. | The email address, the password as a hash, the names of the people invited, sign-in times and the IP address. On Android, the notifications too. | United States | Only in notifications on Android |
| Google (Google Workspace) | Sub-processor. Our email inbox, info@gatpilot.com. | What you write to us, the website's forms and internal notifications: new account, plan request, with the company's phone number, and account closed. | US company, with data centres in several countries | No, unless you send them to us or we send you a copy of them |
| 650 Industries, Inc. (Expo) | Sub-processor. Delivers notifications to the GatPilot app, through Apple's notification service or, on Android, through Firebase. It also delivers the app's updates. | The app's token and the notification: the customer's name, or “Visitor” with two characters, plus at most 140 characters of the message. For updates, technical data about the app. | United States | Yes, in notifications |
| The provider of your AI key: OpenAI, Anthropic, Google or DeepSeek | Chosen by you, on Pro and Custom; not our sub-processor. Writes the answers with your key. | The instructions, 5 chunks, the contact details shown to visitors, the current time and at most 20 recent messages. For the Management Assistant: the instructions, the date, the conversation and the query results. | Under your contract with it | Yes, under your contract with it |
| Telegram | Chosen by you and by the people who write to you; not our sub-processor. Delivers your bot's messages. | The messages of the conversations on Telegram, with the public name and the chat identifier, including the Management Assistant's reports. | Under Telegram's terms | Yes, under Telegram's rules |
| Viber | Chosen by you and by the people who write to you; not our sub-processor. Delivers your bot account's messages. | The messages of the conversations on Viber, with the public name and the user identifier, including the Management Assistant's reports. | Under Viber's terms | Yes, under Viber's rules |
| Your systems, on Custom: databases, WooCommerce, Google Sheets, 1C | Yours; the Management Assistant only reads from them. | The queries written by the GatPilot team and their parameters, for example the period. | Wherever you host them | No, we only read from them |
03 · Your key
The provider of your AI key
On Pro and Custom, you choose the provider and sign directly with it.
On Pro and on Custom, the assistants can answer with your company's key from OpenAI, Anthropic, Google or DeepSeek, on the Economy or Advanced tier.
That provider receives only what it needs for an answer, under your company's contract with it. It is not our sub-processor, so it is not covered by the 30 days' notice.
With your key, the knowledge search stays with OpenAI, on GatPilot's account. Our model, on Free and on Custom without a key, is also from OpenAI.
What the provider does with the data it receives depends on its terms and on the type of your account. Read them before you choose.
04 · Channels
Messaging platforms
Telegram and Viber process the messages under their own rules.
On Pro and on Custom you can connect your assistants to Telegram and Viber, each with its own bot.
We work with them through their bot interfaces, with your bot's token, which we keep encrypted. When you disconnect the channel, we delete the token.
The messages pass through the platform because people choose to write there, and the platform processes them under its own rules. That is why Telegram and Viber are not our sub-processors.
WhatsApp and Messenger join this list from the moment they are connected.
05 · Your systems
The company's systems, on Custom
The Management Assistant only reads from them.
On Custom, the Management Assistant reads from PostgreSQL or MySQL databases, from WooCommerce, from Google Sheets and from 1C. All of them remain your company's, with your providers.
The GatPilot team writes the queries, and the assistant only chooses them and fills them in, for example with the period. The results go through the AI model that writes the answer or the report.
The connection details are kept encrypted. For a private Google spreadsheet we use a GatPilot Google service account, with read-only rights; otherwise we read only spreadsheets shared by link.
For your database, we recommend a separate user with read-only rights.
06 · Statistics
Website statistics
We count visits to gatpilot.md and gatpilot.com, without cookies.
We count visits with Plausible Analytics, from analytics.buum.md, without cookies. The script runs only on the marketing websites, not in the dashboard, in the app or in the widget on customers' websites.
The statistics concern the visitors of our websites, not the people who write to your assistants. What is counted is set out in the Cookie Policy.
07 · What we do not use
What we do not use
What is missing from the list is missing from the code too.
- Online payment is not live yet; we will contact you about activation and payment. That is why no payment processor receives data.
- We do not use advertising networks, nor programs that track people from one website to another, on the website, in the dashboard or in the app.
- The website's fonts are on our server, so a visit does not request them from other providers.
- We extract the text of uploaded files on our server, without an external service.
- Uploaded logos are kept in our database, not with a separate storage service.
08 · Changes
How we announce changes
At least 30 days in advance, on this page.
We add a new or replacement sub-processor to this page and inform you at least 30 days before it receives data.
You can object within this period, on data protection grounds, by writing to info@gatpilot.com. If we do not find a solution, you can close your account before the change.
A provider that leaves the list is removed from this page, and we record the change in the history.
09 · History
History of the list
Every change, with its date.
- : first publication of the list.
Documents
All GatPilot legal documents
The same company and the same rules on gatpilot.md and gatpilot.com.
Legal notice
Who operates GatPilot, how to contact us and where to turn.
Terms of service
The contract for GatPilot: account, plans and payment, your AI key, your content, liability and the applicable law.
Privacy Policy
What data we process, why, for how long and what rights you have.
Data Processing Agreement
How we process your customers' and employees' data on your behalf.
Sub-processors
The providers that help us run GatPilot and the data each one receives.
Cookies and local storage
What GatPilot keeps in your browser, why and for how long.
GatPilotBot
What our crawler reads and how to stop it.
Have a question about this document? Write to us at info@gatpilot.com.