Sub-processors

Effective date: 17 July 2026

Last updated: 17 July 2026

Version: 1.0

Perter Technology Solutions Private Limited ("Perter"), the company behind Grengin, engages a small number of third parties to help deliver its paid services and to operate grengin.com. A sub-processor is a third party that processes customer personal data on Perter's behalf in connection with a paid service, as defined in our Data Processing Addendum (DPA).

This page is the current sub-processor list referenced in Section 7 of the DPA. For transparency, it also lists the service providers that support our website and business operations, so every third party we work with is visible in one place.

Where Grengin uses no sub-processors

Most Grengin deployments involve no sub-processors at all. When you self-host Grengin, whether you build from source or launch the AWS or Azure Marketplace image in your own cloud account, the software runs entirely inside your tenant. It contains no telemetry, Perter is never in your data path, and no third party processes your workspace data on our behalf. Your cloud provider and the AI providers behind your own API keys work directly for you, under your agreements with them.

Sub-processors come into play only for the paid services that Perter operates: Managed Hosting, the Grengin Auth Proxy, and the Grengin LLM Proxy.

The following third parties process customer personal data on Perter's behalf in connection with the paid services described in the DPA. Perter engages each of them under a written contract with data-protection obligations no less protective than those in the DPA, and remains responsible to customers for their acts and omissions.

Sub-processors engaged for Grengin paid services, with purpose, location, and privacy links
Sub-processor Purpose Location Privacy and security
Cloudflare, Inc. Principal sub-processor. Content delivery network, DDoS protection, and web application firewall in front of Grengin services, plus the serverless runtime (Workers, Workers KV, D1, and R2) behind the Grengin Auth Proxy and the Grengin LLM Proxy. Certified to ISO/IEC 27001, SOC 2 Type II, PCI DSS Level 1, and ISO/IEC 27701. United States (global edge network)
Amazon Web Services, Inc. Cloud infrastructure (compute, storage, and networking) for Managed Hosting, engaged only where Perter operates the underlying AWS account on the customer's behalf. Customer-selected region
Microsoft Corporation (Azure) Cloud infrastructure for Managed Hosting, engaged only where Perter operates the underlying Azure account on the customer's behalf. Customer-selected region
Google LLC (Google Cloud) Cloud infrastructure for Managed Hosting, engaged only where Perter operates the underlying Google Cloud account on the customer's behalf. Customer-selected region
OVH Groupe SA (OVHcloud) Cloud infrastructure for Managed Hosting, engaged only where Perter operates the underlying OVHcloud account on the customer's behalf. Customer-selected region (headquartered in France)

Where Managed Hosting runs in a cloud account that you own, that cloud provider works directly for you under your own agreement with it and is not a sub-processor of Perter (DPA, Annex B.5).

Service providers for grengin.com and business operations

The following providers process personal data for which Perter is the controller, such as website visitor, customer, community, and support data. Their role is described in our Privacy Policy. Cloudflare appears in both lists because it serves both roles.

Service providers for the Grengin website and business operations, with purpose, location, and privacy links
Provider Purpose Location Privacy and security
Cloudflare, Inc. Content delivery network, DDoS protection, web application firewall, bot management, and cookieless Cloudflare Web Analytics for grengin.com. United States (global edge network)
Google LLC and Google Ireland Limited Google Analytics 4 for website usage measurement. Analytics cookies are set only after consent through our cookie banner, using Google Consent Mode v2. Google Ireland Limited serves visitors in the EEA, the UK, and Switzerland. United States and other countries
CookieYes Limited Cookie consent management on grengin.com: displays the consent banner and records visitor cookie preferences. United Kingdom
GitHub, Inc. Source-code hosting, issue tracking, and community discussions for the Grengin open-source project. Content posted in public community channels is public and is also processed by GitHub under its own privacy notice. United States

Third parties that are not sub-processors

For clarity, the following work directly for you and are not sub-processors of Perter under the DPA.

Your AI model providers

With bring-your-own API keys, and for the upstream providers you select behind the LLM Proxy (such as OpenAI, Anthropic, Google, AWS Bedrock, or Azure OpenAI Service), each provider acts as an independent controller or as your own processor under your direct agreement with it (DPA, Annex D.6).

Your identity provider

Google Workspace and Microsoft Entra ID remain independent controllers of the data they hold when the Grengin Auth Proxy brokers sign-in to your applications (DPA, Annex C.5).

Cloud marketplaces

AWS Marketplace, Microsoft Azure Marketplace and AppSource, Google Cloud Marketplace, and OVHcloud Marketplace act as billing agents and independent controllers for the transaction data they handle when you purchase through them.

Your own infrastructure

When you self-host Grengin, or when Managed Hosting runs in your own cloud account, your cloud provider is your vendor, not ours.

Changes to this list

Before adding or replacing a sub-processor, Perter will update this page and notify customers at least thirty (30) days in advance, by email to the registered DPA-notification address or by in-product notice. Customers may object on reasonable data-protection grounds within fifteen (15) days of the notification by writing to privacy@grengin.com. Section 7 of the DPA sets out the full notification, objection, and termination process.

Version history

  • Version 1.0 (17 July 2026): Initial publication.

Questions about our sub-processors?

Our data protection team can help with vendor due diligence, DPA questions, and objection notices.