Subprocessors
Version 3.0 · Effective 5 October 2026
Cyberinfra Limited ("ScreenJournal", "we") uses the subprocessors below to provide the ScreenJournal service. This page lists only third parties that process customer personal data as our processors. Vendors we use for our own marketing website process visitor data on our behalf; we are the controller of that data and they are covered by the Privacy Policy and Cookie Policy.
This page is incorporated into any Data Processing Agreement we enter into as the list of authorised subprocessors. From this version onward we post a new or replaced subprocessor on the Legal page's change list at least thirty (30) days before it starts processing customer data, and organisations may object within that period. Organisations that want direct notice of changes can ask support@screenjournal.ai to be added to a notification list. An organisation may object to a change, on reasonable data-protection grounds, within thirty (30) days of a posted change, to support@screenjournal.ai.
Version 3.0 of this list records changes already made — our move to Hetzner, and the use of Google Cloud Storage and Vertex AI since August 2026 — for which advance notice was not given; those entries are listed on the Legal page's change list with the dates we can establish.
AI processing
Screen and audio analysis runs on Google Gemini models through Google Vertex AI. Report and timesheet narratives, alert evaluation and the assistant use Google Gemini models through Google's Gemini API.
| Vendor | Purpose | Data processed | Location | Transfer safeguard |
|---|---|---|---|---|
| Google (Vertex AI and the Gemini API, Gemini models) | Screen-content analysis and activity descriptions, audio transcription and activity-pattern checks (Vertex AI); report and timesheet narratives, alert evaluation and the assistant (the Gemini API) | Screen recordings from allowed applications (sensitive applications are excluded before capture); audio where the organisation enables it; derived timelines | Vertex AI global endpoint; Gemini API, Google-operated with no fixed region | Google Cloud's standard terms, which incorporate its Data Processing Addendum |
| DeepInfra, Inc. | Audio transcription fallback | Audio and transcripts, if enabled | United States | Set out in the change notice, if enabled |
| OpenAI | Model fallback for the assistant | Assistant prompts and the organisation data retrieved to answer them, if enabled | United States | Set out in the change notice, if enabled |
Google states that it does not use customer content submitted through Vertex AI to train its foundation models; see Google's published data-governance commitments for Vertex AI. For the Gemini API, Google's terms state that content submitted under its paid services is not used to improve Google's products; whether all of our usage falls under those paid-service terms is to be confirmed.
DeepInfra and OpenAI are not used in normal operation; each is available as a fallback and would be enabled only with notice under the change process above.
Hosting and infrastructure
| Vendor | Purpose | Data processed | Location |
|---|---|---|---|
| Hetzner Online GmbH | Our server: application containers, the PostgreSQL database and the report cache | All account, monitoring-metadata and report data | Germany (Falkenstein) |
| Cloudflare, Inc. | Domain name service, encryption in transit (TLS termination), protection against attacks | All traffic to and from the service, in transit | Global network, including the United States |
| Amazon Web Services, Inc. | Object storage (Amazon S3) for activity timelines, transcripts and metrics; read-only access to media stored before August 2026 | Activity time-series data and transcripts; older media | India (Mumbai, ap-south-1) |
| Google Cloud | Object storage (Google Cloud Storage) for screen video and audio: uploaded temporarily for analysis in the default capture mode, or stored where an organisation enables Record + Save or alert evidence (since August 2026) | Screen video and audio | Region to be confirmed |
| Vercel, Inc. | Hosting of the web application and our website | Requests to the web application and website | United States (to be confirmed) |
Billing and operations
| Vendor | Purpose | Data processed | Location |
|---|---|---|---|
| Paddle.com Market Ltd | Billing, as merchant of record | Administrator billing data | United Kingdom, European Union, United States |
| Resend, Inc. | Transactional email: sign-in links, invitations, reminders and alert emails | Names and email addresses, and the content of those emails | United States |
| Google (Google Workspace, Gmail) | Report emails | Names and email addresses, and the content of those emails, including weekly report figures | Google's data centres |
| Sentry (Functional Software, Inc.) | Desktop application crash and error reports | Device and application diagnostics, which may include window titles | United States (to be confirmed) |
| Telegram | Forwarding bug reports to our support team | Reporter email address and report text | Netherlands for accounts registered in the UK or EEA, per Telegram's privacy policy (section 4.1); Telegram does not publish the location for other accounts, and its group companies are in Dubai and the British Virgin Islands |
Transfers to the United States and other countries take place under each vendor's standard terms.
Not subprocessors
These parties are not our subprocessors, and we list them so the picture is complete:
- MaxMind GeoLite2. A local database on our servers that derives a country or region from an IP address at sign-in. No data is sent to MaxMind.
- Google and Microsoft sign-in. If a member chooses to sign in with Google or Microsoft, those companies act as independent controllers of their own sign-in data.
- AI tools an organisation connects through the integration feature. These receive data on the organisation's instruction. The organisation chooses them and is responsible for their terms.
- Marketing-site analytics vendors. These run only with a visitor's consent and process website-visitor data, not customer personal data; see the Cookie Policy.
Changes
This list is versioned. The version and effective date are shown at the top of this page. When the list changes, we post the change on the Legal page's change list as described above and publish a new version of this page. Prior versions are kept in the Legal archive.
Changes and previous versions
- 5 October 2026v3.0: list rebuilt for the current hosting (Hetzner, Cloudflare, AWS S3, Google Cloud, Vercel) and operational vendors; DeepInfra marked fallback-only.
Questions about this document: support@screenjournal.ai. Canonical URL: /legal/subprocessors.