HostAgentics Docs

Subprocessors

Last updated: 2026-08-09

HostAgentics uses a small number of third-party subprocessors to operate the platform. This page lists them as required for transparency and for our data-processing agreements. This page is linked from our privacy policy and DPA pages; it is intentionally not featured elsewhere in the product.

A **subprocessor** is a third party that processes customer data on our behalf. We review each subprocessor's security practices before engaging it, contractually bind them to process data only for the purposes we specify, and update this page when the list changes. For questions, contact [email protected].

Current subprocessors

| Subprocessor | Service | What it processes | Where data is stored |

| ---------------- | ------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |

| **Contabo GmbH** | Customer runtime compute and object storage ("HostAgentics Cloud") | OpenClaw, Hermes, and n8n containers; runtime volumes and environment configuration; encrypted backup objects. | The current launch region is the European Union. See <https://contabo.com>. |

| **Railway PBC** | Control-plane application hosting | HostAgentics API/web/worker services and platform PostgreSQL/Redis data. It does not host customer runtime containers or their runtime volumes. | European control-plane deployment. See <https://railway.app>. |

| **Stripe, Inc.** | Payment processing | Payment card details are processed by Stripe; HostAgentics does not store card numbers. Stripe also receives billing metadata (plan, amounts, invoice details) and processes invoices on our behalf. | See Stripe's privacy policy: <https://stripe.com/privacy>. |

| **Resend** | Transactional email | Email delivery: notifications, invoices, security alerts, and account emails sent to the address on your account. Email content may include your runtime name and plan details; it never includes plaintext secrets. | See Resend's documentation and privacy policy: <https://resend.com> and <https://resend.com/legal/privacy>. |

| **OpenRouter** | Model routing for HostAgentics AI | When you use HostAgentics AI credit (or included credit) for model access from your runtimes, requests are routed through OpenRouter. Prompts, tool calls, and model responses pass through OpenRouter's API; usage is metered against your credit balance. When you bring your own keys (BYOK), your traffic goes directly to the provider you configure and is not routed through OpenRouter. | See OpenRouter's privacy policy: <https://openrouter.ai/privacy>. |

Notes

  • **Infrastructure hosting**: Customer runtimes are hosted on Contabo infrastructure; Railway hosts only the HostAgentics control plane. HostAgentics remains responsible for runtime configuration, container/network isolation, encryption, backups, and monitoring. This page is the one place where infrastructure providers are named, as legally required; elsewhere the platform is referred to as HostAgentics Cloud.
  • **Model providers**: When you use HostAgentics AI credit, the underlying model providers (accessed via OpenRouter) may process your prompts and responses. The specific model providers available are shown in your dashboard; their processing is subject to their own terms, which are linked from OpenRouter at the time of use. BYOK usage goes directly to the provider you choose.
  • **Cloudflare** is used for DNS and certificate management for runtime domains (it operates the DNS records and TLS certificates, not the runtime data itself).
  • **Changes**: If we add or replace a subprocessor, we will update this page and notify customers whose agreements require it before the new subprocessor processes data.
  • Contact

    Privacy inquiries: [email protected]. Legal entity details are shown on invoices and in the privacy policy.