LEGAL

Sub-processors

Last updated 2026-07-30 · Version 1.2

This page is the live register of every third party processing personal data on Onkydra's behalf under GDPR Article 28. Any addition, removal, or material change is notified to account administrators at least 30 days before it takes effect and recorded in the changelog below.

1. Purpose of this register

Onkydra is the data controller for personal data in the Service. Where we engage a third party to process personal data on our behalf, that third party is a sub-processor, and we engage them under data-processing terms that meet Article 28 of Regulation (EU) 2016/679 ("the GDPR").

This page exists so buyers, in particular the biotech security and privacy reviewers who assess Onkydra before onboarding, can see the full list, its changelog, and the international-transfer mechanism for each entry.

2. Current active sub-processors

  1. Google Cloud

    Sub-processor since 2026-06-01

    Purpose
    Application hosting (Cloud Run + Firebase App Hosting), primary database (Cloud SQL for Postgres), object storage (Cloud Storage), authentication (Firebase Authentication), and AI inference (Vertex AI: the Gemini family).
    Processing region
    Cloud SQL for Postgres in europe-west2 (London, UK), single zone, with no failover replica, and its automated backups in Google's EU multi-region rather than in the primary region. The App Hosting backend serving the site is in europe-west4 (Netherlands, EU). Object storage: the reference-data bucket is in europe-west4, and the Cloud Build staging bucket, which holds application source and build output rather than Service data, is in Google's US multi-region. Gemini inference runs against Vertex AI's global endpoint, which Google may serve from any supported region.
    Transfer mechanism
    UK: Commission adequacy decision 2021/1772. EU regions: no cross-border transfer. Global Vertex AI endpoint: Commission Implementing Decision (EU) 2021/914 Standard Contractual Clauses, as incorporated in the Google Cloud Data Processing Addendum.
    Provider DPA
    cloud.google.com
  2. Stripe Payments Europe, Limited

    Sub-processor since 2026-06-01

    Purpose
    Subscription billing, Checkout, invoicing, VAT handling, and the Customer Portal. Processes billing name and email, subscription state, and payment metadata (never card numbers).
    Processing region
    Ireland (EU) with US processing for card-network operations
    Transfer mechanism
    US: Commission Implementing Decision (EU) 2021/914 Standard Contractual Clauses, Module 3, Version 2.
    Provider DPA
    stripe.com
  3. Resend, Inc.

    Sub-processor since 2026-06-15

    Purpose
    Transactional email delivery: waitlist confirmations, receipts, product notifications, and password-reset messages. Processes recipient email addresses and the message body.
    Processing region
    United States (SES-backed infrastructure)
    Transfer mechanism
    US: Commission Implementing Decision (EU) 2021/914 Standard Contractual Clauses, Module 2, Version 2.
    Provider DPA
    resend.com
  4. Loops

    Sub-processor since 2026-07-13

    Purpose
    Waitlist and announcement CRM. Processes contact first and last name, email address, organisation, stated role, and the role-based user group that role maps to.
    Processing region
    United States
    Transfer mechanism
    US: transfers rely on the Standard Contractual Clauses published in Commission Implementing Decision (EU) 2021/914, under the provider's published data-processing terms.
    Provider DPA
    loops.so
  5. Cloudflare

    Sub-processor since 2026-07-17

    Purpose
    Cookieless analytics on every page of the site, including the signed-in workspace: page view, referrer, user agent, and coarse country derived from IP address. No cookie is set and no cross-site identifier is created.
    Processing region
    United States, served from a global edge network
    Transfer mechanism
    US and non-EEA edge locations: transfers rely on the Standard Contractual Clauses published in Commission Implementing Decision (EU) 2021/914, under the provider's published data-processing terms.
    Provider DPA
    www.cloudflare.com

3. International transfer safeguards

The primary database is stored in the United Kingdom, which the European Commission has recognised as offering adequate protection under Implementing Decision 2021/1772. Its automated backups are stored in Google's EU multi-region, so database contents leave the United Kingdom as part of the ordinary backup cycle. The App Hosting backend that serves the site, and the reference-data bucket it reads, sit in europe-west4 (Netherlands), inside the EEA. One further Google-managed bucket stages Cloud Build source and build output in Google's US multi-region; it holds build inputs and build output, not Service or workspace data, and is covered by the Google Cloud Data Processing Addendum. Personal data processed by Stripe, Resend, Loops, and Cloudflare outside the EEA, and any Gemini inference call routed by Google outside the UK or the EEA, is transferred under the Standard Contractual Clauses published in Commission Implementing Decision (EU) 2021/914, as incorporated in the data-processing terms each provider publishes.

We keep a copy of the data-processing terms and transfer safeguards relied on for each provider and will make them available to controllers on request, subject to reasonable confidentiality obligations.

4. Changelog

Every addition, removal, or material change is recorded below with a date and a short note. The version stamp at the top of this page moves in step with the log.

  • 2026-07-30updatedGoogle Cloud, Cloudflare

    Three corrections to entries published earlier the same day. The Google entry is now identified by product name only, because the contracting entity has not been confirmed from the order form and the register must not guess it. The Cloudflare processing scope is corrected from the public marketing pages to every page of the site, including the signed-in workspace, because the analytics beacon is declared in the root layout that every route nests inside. And the Cloud SQL backup location is now recorded: automated backups are stored in Google's EU multi-region, not in the primary europe-west2 region.

  • 2026-07-30addedLoops, Cloudflare

    Loops recorded as a sub-processor for waitlist and announcement CRM, processing from 2026-07-13. Cloudflare recorded for cookieless analytics on every page of the site, including the signed-in workspace, processing from 2026-07-17. Both were already in use when recorded here, and there were no account administrators to pre-notify during the waitlist period.

  • 2026-07-30updatedGoogle Cloud

    Processing region corrected. The register previously stated regional failover in europe-west1, which does not exist: the Cloud SQL instance is single zone in europe-west2 with no failover replica. The App Hosting backend serving the site is recorded as europe-west4; object storage is recorded as europe-west4 for the reference-data bucket and Google's US multi-region for the Cloud Build staging bucket, which holds application source and build output rather than Service data. The global Vertex AI endpoint used for Gemini inference is now stated explicitly.

  • 2026-07-04addedOnkydra sub-processor register

    Register established. Google Cloud and Stripe Payments Europe, Limited recorded as sub-processors effective from 2026-06-01. Resend, Inc. recorded from 2026-06-15.

5. Change notifications

Account administrators receive email notification of any planned addition, removal, or material change at least 30 days before it takes effect. Buyers who want to receive the same notifications without an active subscription can email hello@onkydra.com and ask to be added to the notification list.

If you object to a planned change, contact us at the same address before the effective date and we will either provide additional information or, where the objection is reasonable and the sub-processor is material to your use of the Service, work with you on a path forward that may include termination with pro-rated refund.

6. What is not on this list

Occasional third parties who do not process personal data on Onkydra's behalf are not sub-processors and are not listed here. Examples include the public sources we query or hold locally (cBioPortal, the API we fetch the DKFZ pediatric pan-cancer and CPTAC pediatric brain studies from, PubMed and CrossRef for citation resolution, and the locally seeded DepMap and LINCS tables), and the biology foundation-model providers whose weights we plan to run inside our own endpoints (scPRINT-2, AlphaGenome, MedGemma, Geneformer). These are data sources or software components, not controllers or processors of your personal data.

This register is maintained by Onkydra. For data-processing terms, transfer safeguards, or a customer copy of any of the above, contact hello@onkydra.com. See also our privacy policy.