Subprocessor List
This is the single canonical list of third parties that process personal data on our behalf. The Privacy Policy and the DPA reference this document rather than repeating it, so there is only one list to keep accurate.
The most important thing on this page
No subprocessor on this list receives your cluster data.
KubeManta is self-hosted. Your workloads, logs, metrics, configuration and secrets stay in your cluster and are never transmitted to us — so they are never transmitted to anyone acting for us. Everything below relates to account, billing, licensing and website data only.
The one route by which cluster-derived content can leave your cluster is an AI provider that you configure yourself. Such a provider is not our subprocessor — the data goes from your cluster to them, under your own account and contract, never through us. See Privacy Policy §5 and §3 below.
1. Current subprocessors
| Provider | Purpose | Personal data it receives | Notes |
|---|---|---|---|
| Paddle (Paddle.com Market Ltd) | Payments, Merchant of Record, invoicing, global tax | Name, email, billing address, country, tax ID, payment card details, transaction history | Acts as Merchant of Record — the seller of record. Paddle holds card data; we never receive or store it. Paddle also acts as an independent controller for its own payment/tax compliance. |
| Keygen | License issuance and validation | Email and name attached to a license record; license key; Cluster Fingerprint (a random UUID — see below); optional node-count telemetry (size counts and timestamps only, disableable) | The in-cluster calls transmit the license key, the fingerprint, and — unless switched off — the node-count report. No cluster content, no names, no workload data. See Privacy Policy §3.3. |
| Resend | Transactional email delivery — license-key emails and contact-form forwarding | Recipient email address, name, license key, and the content of a contact-form message | Used for outbound transactional mail only. Not used for marketing campaigns. |
| Zoho (Zoho Corporation) | Our business mailboxes (support@, security@) | Anything you put in an email to us — name, email, message content, any attachments | Where support correspondence is received and stored. |
| Cloudflare | DNS, TLS termination, network tunnel, and edge delivery for our public hostnames | IP addresses and standard request metadata for visitors to our sites | Handles kubemanta.com, api.kubemanta.com, registry.kubemanta.com, analytics.kubemanta.com. |
| Amazon Web Services (AWS) | Encrypted off-site backup storage | Encrypted backups of our lead and analytics databases — which contain signup emails, names and attribution data | Backups are GPG-encrypted before upload; the decryption key is held offline, not on the backup host, so AWS holds ciphertext it cannot read. |
| Our own infrastructure | Hosting the website, billing bridge, licensing bridge, lead database, and self-hosted analytics | All the categories in Privacy Policy §3 | Operated by us, not a third party. Listed for completeness so this page is a full picture of where data lives. |
On Umami (website analytics)
We use Umami for website analytics, but it is self-hosted by us on our own infrastructure — it is software we run, not a service a third party operates. No analytics data is sent to a third party. It is cookieless: no tracking cookies, no cross-site tracking, no advertising identifiers.
It is therefore not a subprocessor, and is listed here only to prevent the reasonable question "where is your analytics vendor?" from going unanswered.
On the Cluster Fingerprint
Where the table says Keygen receives a "Cluster Fingerprint", that is the
metadata.uid of your cluster's kube-system namespace — a random UUID Kubernetes
generated when the cluster was created. It identifies that a cluster is the same
cluster as last time. It conveys nothing about the cluster's size, name, contents,
cloud, or workloads. Whether it constitutes personal data at all is arguable; we
list it for transparency rather than argue the point.
2. What we do NOT use
Stated explicitly, because their absence is a deliberate choice:
- ❌ No third-party advertising or marketing trackers — no Google Analytics, no advertising pixels, no data brokers.
- ❌ No CRM or marketing-automation platform holding your data.
- ❌ No third-party product telemetry or crash-reporting service. The Software sends no feature-adoption metrics, error reports or crash dumps anywhere. The one usage figure it does report is your node count, sent to our licensing provider (Keygen, §1) as product telemetry — a number only, never workload data, never used to calculate a charge (pricing is per admin seat), and disableable. See Privacy §3.3.
- ❌ No third-party session recording or heat-mapping.
- ❌ No AI provider as our subprocessor. See §3.
3. AI providers are not our subprocessors
This deserves its own section because it is the question a careful reviewer will ask.
If your administrator configures a third-party AI provider (for example Anthropic or OpenAI), prompt content — which may include cluster context — is sent from your cluster directly to that provider, under your API key and your contract with them.
- It does not pass through our infrastructure.
- We have no contract with that provider covering your data.
- We never see the prompt or the response.
In data-protection terms, you are the controller of that transfer and that provider is your processor, not ours. You should assess their terms yourself.
If you would prefer that no prompt content leaves your network at all, the Software supports a local-only mode pointing at a model you run in your own cluster, plus a deny-by-default outbound-domain allowlist. See Privacy Policy §5.3.
4. Changes to this list
Before we add a new subprocessor that processes personal data, we will update this page and increment its document version.
Customers with a signed DPA may subscribe to change notifications and have the objection rights set out there. To subscribe, email [email protected].
5. Contact
Questions about this list, or to request change notifications: [email protected].
Related: Privacy Policy · DPA · Security & Trust