Aneo B.V.

Sub-processors

This page lists third parties that process personal data on behalf of Aneo B.V. as part of our products and services. It covers aneo.io and all subdomains and aliases, including examples such as app.aneo.io, api.aneo.io, docs.aneo.io, and status.aneo.io. This page was first published on 19 November 2025 and was last updated on 24 June 2026.

Last updated: 24 June 2026

1. How we use sub-processors

We engage specialist providers for hosting, storage, backups, authentication, AI model inference, databases, email, CRM, customer communication, analytics, security, and business operations.

We require appropriate data protection commitments and security measures from providers that process Customer Personal Data on our behalf. For customers on supported plans, we may offer EU data residency and a zero-retention option for certain AI data flows.

2. Aneo configuration note

Our primary processing locations for core product data are intended to be in the European Union where supported by the relevant provider and customer plan. Google Cloud Platform projects and Supabase databases may be provisioned in EU regions.

Processing locations reflect Aneo B.V. configuration where supported. Exact regions, retention settings, and provider use may change as configurations evolve, and this page will be updated accordingly.

3. Current sub-processors

The provider list below summarizes the main current or configured sub-processors and service providers used across aneo products, the public website, and business operations. Provider use may vary by product, plan, region, and customer configuration.

  • Google Cloud Platform (GCP): application hosting, Cloud Run, storage, backups, networking, logging, monitoring, and security services. Data types may include Customer Content, account data, logs, and backups. Processing locations are EU regions selected by Aneo B.V. where configured. Transfer mechanism is not applicable for EU-only processing, with SCCs used where applicable. Retention follows the Aneo retention schedule and rolling backup configuration.
  • Supabase: managed PostgreSQL database, storage, and related backend services. Data types may include Customer Content, account data, product metadata, questionnaire answers, incident records, and generated outputs. Processing locations are EU regions where configured, such as Frankfurt, Ireland, London, or Paris. Transfer mechanism is not applicable for EU-only processing, with SCCs used where applicable. Retention follows the Aneo retention schedule.
  • Firebase Authentication: user authentication, sign-in, identity, and session support. Data types may include email address, name, identity-provider claims, device and session tokens. Processing may be EU or global depending on configuration. Transfer mechanisms include SCCs where applicable. Session tokens are generally ephemeral; authentication records follow product configuration.
  • Google OAuth 2.0: federated login initiated by users. Data types may include profile data, email, and identifiers. Processing location and retention follow Google provider terms. Google may act as a separate controller for user-initiated authentication.
  • Microsoft Entra ID / OAuth: federated login initiated by users. Data types may include profile data, email, and identifiers. Processing location and retention follow Microsoft provider terms. Microsoft may act as a separate controller for user-initiated authentication.
  • LinkedIn OAuth: federated login initiated by users. Data types may include profile data, email, and identifiers. Processing location and retention follow LinkedIn provider terms. LinkedIn may act as a separate controller for user-initiated authentication.
  • OpenAI: model inference for AI-assisted product features. Data types may include prompts, model outputs, context, system metadata, ticket content, policy generation context, summaries, classifications, and mapping support. Processing locations follow provider configuration and terms. Transfer mechanisms include SCCs and provider processor terms where applicable. Customer Content is not used to train foundation models unless the customer opts in or agrees in writing.
  • Hostinger: marketing website hosting, DNS, domain services, and CDN features where used. Data types may include IP addresses, request logs, static site content, and DNS records. Processing may involve EU data centers and global CDN infrastructure according to provider configuration. Transfer mechanisms include SCCs where applicable. This provider may be limited to legacy website, domain, or DNS operations depending on the new Cloud Run deployment.
  • HubSpot: CRM, marketing, sales communication, support communication, and customer relationship workflows. Data types may include account and contact information, support interactions, sales notes, form submissions, and communication history. Processing may occur in EU and US locations depending on provider configuration. Transfer mechanisms include SCCs where applicable. Retention follows CRM settings. HubSpot is used for business operations, not core product data.
  • Google Workspace: business email, documents, internal collaboration, and operational administration. Data types may include names, business email addresses, support communications, attachments, documents, and internal records. Processing may occur in EU and US locations depending on configuration. Transfer mechanisms include SCCs where applicable. Retention follows administrator settings.
  • Google Analytics 4: website or product analytics where enabled and subject to consent where required. Data types may include usage events, device and browser data, referral data, and approximate technical information. Processing locations may be EU and global depending on configuration. Transfer mechanisms include SCCs where applicable. Retention follows GA4 retention settings. GA4 does not log or store IP addresses in the same way as earlier analytics products, according to Google documentation.
  • Payment gateway providers: checkout, payment processing, fraud checks, invoices, and billing metadata for online purchases where configured. Data types may include billing details, transaction references, payment status, invoice data, tax data, and fraud-prevention metadata. Processing location, transfer mechanism, certifications, and retention follow the relevant payment provider terms.

4. AI providers

AI providers may process prompts, context, uploaded text, generated outputs, and related metadata to deliver AI-assisted features. Aneo B.V. uses contractual and technical controls intended to protect Customer Content and limit unauthorized use.

Customer Content is not used to train foundation models unless the customer expressly opts in or agrees in writing.

5. Notice of changes

We will update this page in advance of adding or replacing a material sub-processor and will provide at least 15 days' prior notice by updating this page and, where practical or required, notifying customer administrators by email.

If you object to a change, contact legal@aneo.io within the notice period. The parties will discuss the objection in good faith. If unresolved, the customer's rights are handled under the applicable DPA, order form, or signed agreement.

6. International transfers

Some providers or support operations may process personal data outside the European Economic Area. Where required, Aneo B.V. uses safeguards such as Standard Contractual Clauses, the UK Addendum, the Swiss addendum, adequacy decisions, data processing agreements, and vendor due diligence.

7. Former sub-processors

There are no former sub-processors listed for the current public page. If a material provider is replaced or removed, we can list the former provider, purpose, active-until date, and replacement here where appropriate.

8. Contact

Questions or objections regarding sub-processors can be sent to legal@aneo.io.

Privacy questions can also be sent to privacy@aneo.io. General enquiries can be sent to hello@aneo.io.