---
title: "Sub-processors"
description: "This page lists the companies that process Customer Data for Caveman Cloud and the vendors Caveman Labs, Inc. uses for its own operations: what each one does, what data it handles and where. It is Ann"
canonical: https://caveman.so/legal/subprocessors
last-updated: 2026-10-06
status: "draft, not yet in effect"
version: "2026-10-06"
publisher: "Caveman Labs, Inc."
contact: "contact@caveman.so"
---

# Sub-processors

This page lists the companies that process Customer Data for Caveman Cloud and the vendors Caveman Labs, Inc. uses for its own operations: what each one does, what data it handles and where. It is Annex III of the Data Processing Agreement.

## Summary

This summary is for convenience only. The full text below and the [Data Processing Agreement](/legal/dpa) govern.

- This page lists the companies that process Customer Data on our behalf when we run Caveman Cloud. It is Annex III of the Data Processing Agreement.
- Customer Data is hosted on Google Cloud in the Netherlands. Cloudflare runs a global network, so traffic can pass through locations outside the EEA.
- Model Providers you reach with your own API keys or accounts are not on this list, because you engage them, not us. Nor are services you connect yourself, such as GitHub.
- A second table lists vendors we use for our own operations, such as hosting the website and staff email. They do not process Customer Data.
- We give 30 days' notice before adding or replacing a sub-processor, and you can object.

## How to read this page

### Sub-processors

A sub-processor is a company that Caveman Labs, Inc. ("Caveman", "we") engages to process Customer Data on our behalf, while we act as your processor under the Data Processing Agreement. The first table below lists them. The Data Processing Agreement's rules on sub-processors, including notice and your right to object, apply to them.

### Caveman's own vendors

Some vendors support Caveman's own operations: the Website, our waitlist, staff email, meeting booking and product analytics. For that data Caveman is the controller, and our [Privacy Policy](/privacy) explains how we use it. These vendors do not process Customer Data. We list them in the second table so you can see every company involved.

### Model Providers are not sub-processors

Caveman Cloud is bring-your-own-key (BYOK). When the gateway forwards a request to a Model Provider, such as an AI model API you have chosen, it does so with your own API key, on your instruction, under your own agreement with that provider. That makes the Model Provider your own processor or an independent controller, not our sub-processor. We do not contract with Model Providers on your behalf, and we do not resell their tokens. Their terms decide where they process your data and whether they keep it.

The same applies to other services you connect yourself, such as GitHub, Google sign-in or your own identity provider. For example, on hosted Caveman Cloud the optional GitHub integration uses Caveman's GitHub App, which you install on the repositories you choose in your own GitHub account. GitHub holds that repository data under your own agreement with GitHub, so it is a service you connect, not our sub-processor for Customer Data.

## Sub-processors of Customer Data

| Company | What they do | Data | Location | Status |
|---|---|---|---|---|
| Google Cloud | Hosts Caveman Cloud: Kubernetes (GKE), Cloud SQL for PostgreSQL, Memorystore (Valkey), Cloud Storage, Cloud KMS, Artifact Registry, logging and metrics. | All Customer Data the Services store, including Usage Metadata, Payloads (stored by default), compression recovery originals, cached responses, agent-run artifacts and stored Model Provider keys, encrypted. | europe-west4 region (the Netherlands) | Active |
| ClickHouse Cloud | Managed database for usage and performance telemetry. Runs on Google Cloud and is reached only over private connectivity. | Usage Metadata; redacted prompt snippets and embeddings derived from Payloads; and the redacted log bodies, exception messages and stack traces of imported logs. | Google Cloud, europe-west4 region (the Netherlands) | Active |
| Cloudflare | DNS, reverse proxy, TLS, DDoS protection, web application firewall and rate limiting for caveman.so, app.caveman.so and api.caveman.so. Turnstile checks sign-ups for bots. | All traffic to the Services passes through it, including Payloads in transit, IP addresses and request metadata. For Turnstile, the IP address and browser signals of the person signing up. | Global network. We have not verified EU-only processing, so traffic may be handled at locations outside the EEA. | Active |
| Resend | Transactional email: sign-in, password reset, invitations, digests, spend alerts and billing-limit warnings. | Recipient email address, and the content and metadata of these account emails. | Not yet confirmed. We treat it as a transfer outside the EEA. | Active |

Google Cloud and Cloudflare also handle load balancer and edge request logs, including IP addresses. Caveman processes these logs as a controller to keep the Services secure, and our Privacy Policy covers them.

At the date of this version, Caveman does not use a model provider under its own account to process Customer Data on hosted Caveman Cloud. Before it does, it will list that provider here with the notice the Data Processing Agreement requires.

## Caveman's own vendors

| Company | What they do | Data | Status |
|---|---|---|---|
| Vercel | Hosts caveman.so and docs.caveman.so, behind Cloudflare. | Hosting logs: IP address, user agent and the URL requested. | Active |
| Supabase | Stores the Website waitlist, and receives `caveman` CLI usage telemetry through an Edge Function. Region per our project configuration. | Waitlist: email address, optional note and source. CLI telemetry: a random install ID, IP address and the event fields our Privacy Policy lists. IP addresses are cleared after 90 days and events are deleted after 13 months. Supabase's platform request logs also record IP address and approximate location. | Active |
| Stripe | Billing and payments for Pay-as-you-go: Checkout, holding the card on file and charging for usage. We report usage totals to Stripe periodically. | The billing email address, the Workspace ID and the usage total for each product, reported to Stripe's meters; and the card details Stripe collects itself. We never see the full card number. | Active for Pay-as-you-go |
| Google Workspace | Staff email, including the contact@caveman.so mailbox. | Emails you send us and our replies. | Active |
| Cal.com | Meeting booking at cal.com/caveman/chat. Its script loads only when a visitor hovers over, focuses or clicks a booking button. | The details you enter to book, and the request data your browser sends when the script loads. | Active |
| PostHog (EU Cloud) | Product analytics for caveman.so, including session replay and heatmaps. Cookieless; respects Do Not Track; full referring addresses, query strings and search terms are removed in the browser. Configured for app.caveman.so but not enabled there; always off for Enterprise Workspaces. | On caveman.so: pseudonymous usage events, clicks with element labels, session replays with every form field masked, page speed, script errors, approximate location from IP address (the address is discarded); for waitlist sign-ups and bookings, the email address or Cal.com booking the visit is linked to; names of crawlers and AI agents that read the site, without their IP address. Apart from that linked email address or booking, never content you type, form values, file paths or free text. | Active on caveman.so; not enabled in the dashboard |
| GitHub | Hosts Caveman's open-source code. When you visit the Website, your browser fetches public star counts directly from the GitHub API. If you sign in with GitHub or install Caveman's GitHub App, GitHub also exchanges data with Caveman Cloud, as a service you connect. | On the Website: your IP address and browser request data. If you sign in with GitHub: the name, email address and profile image GitHub shares with us. With the GitHub App: the installation, repository and pull request events GitHub sends us, and the repository content and history the App reads. GitHub handles this data under its own terms and your agreement with it. | Third party. GitHub is a service you connect, not our sub-processor for Customer Data. |

## Where data goes

Caveman Labs, Inc. is a US company, and our staff may access data from outside the EEA. Several of the vendors above are US companies. Where personal data is transferred out of the EEA, the UK or Switzerland, we use the EU Standard Contractual Clauses, with the UK Addendum and Swiss adaptations, or another lawful transfer mechanism. The Data Processing Agreement sets out the details.

This page covers hosted Caveman Cloud and the Website. A self-hosted deployment of Caveman Cloud sends Caveman no Customer Data, so these sub-processors are not involved.

## Changes and notice

We give at least 30 days' notice before a new sub-processor starts processing Customer Data or an existing one is replaced. We do this by updating this page and by emailing Workspace owners and anyone who has subscribed. To subscribe to change notices, write to [contact@caveman.so](mailto:contact@caveman.so).

You can object to a new sub-processor on reasonable data protection grounds by writing to [contact@caveman.so](mailto:contact@caveman.so) within the notice period. We will discuss the objection with you in good faith. If we cannot resolve it, you can terminate the affected Services and receive a pro-rata refund of prepaid fees for the unused period, as the [Data Processing Agreement](/legal/dpa) describes.

We update the second table when our own vendors change.
