NodeFox

Last updated: September 22, 2026

NODEFOX SUBPROCESSOR LIST

Version 1.1 | Effective Date: September 22, 2026 | Last Updated: September 22, 2026

Beta Status Notice: NodeFox is currently provided in beta. Features, behavior, documentation, and controls may change without notice. You must independently validate suitability for your use case and maintain your own safeguards.

© 2025–2026 NodeFox LLC. All rights reserved.


IMPORTANT NOTICE

THIS SUBPROCESSOR LIST ("LIST") IDENTIFIES THIRD-PARTY SUBPROCESSORS THAT NODEFOX LLC ("NODEFOX," "WE," "US," OR "OUR") MAY ENGAGE TO PROCESS PERSONAL DATA ON BEHALF OF CUSTOMERS IN CONNECTION WITH THE SERVICES.

THIS LIST IS INCORPORATED BY REFERENCE INTO THE NODEFOX DATA PROCESSING ADDENDUM ("DPA") AND IS REFERENCED IN THE PRIVACY POLICY. THIS LIST DOES NOT CREATE CONTRACTUAL OBLIGATIONS, SERVICE-LEVEL COMMITMENTS, WARRANTIES, OR GUARANTEES OUTSIDE THE DPA. IN THE EVENT OF CONFLICT BETWEEN THIS LIST AND THE DPA, THE DPA CONTROLS.

THIS LIST IS PROVIDED FOR TRANSPARENCY AND DISCLOSURE PURPOSES ONLY. THE ONLINE VERSION AT HTTPS://WWW.NODEFOX.AI/LEGAL/SUBPROCESSOR-LIST IS THE CONTROLLING CURRENT LIST, AND IT CONTROLS OVER ANNEX III TO THE DPA, WHICH REPRODUCES IT ONLY AS OF THE DPA'S EFFECTIVE DATE.

FOR CUSTOMERS SUBJECT TO A DPA, NOTICE AND OBJECTION RIGHTS REGARDING SUBPROCESSOR CHANGES ARE GOVERNED BY THE DPA, NOT THIS LIST.


SECTION 1. INTRODUCTION

1.1 Purpose. This List provides transparency regarding third-party service providers NodeFox may engage to process Customer Data, enabling Customers to fulfill their own compliance obligations.

1.2 Scope.

This List reflects NodeFox's Subprocessors as of the Last Updated date and may change. Not all Subprocessors process Personal Data for all Customers or Services. Certain Subprocessors are engaged only where Customers elect specific features.

Status labels. Each entry in Section 4 carries a status. In use means the vendor is engaged today. Used or planned means the vendor is either in use or in the process of being onboarded; where a vendor is marked this way we describe the processing that will occur once it is live, so that Customers have notice in advance rather than after the fact. This List is reconciled against Annex III to the DPA; where the two differ, this List controls.

Local Client Execution. When the Services are utilized via the NodeFox Desktop Application or executed locally in the Customer's web browser via WebAssembly (WASM), processing occurs on the Customer's own device. The Customer's local hardware, operating system, browser, and local network infrastructure are entirely outside the scope of this List and are not NodeFox Subprocessors.

Independent Controllers. Some vendors listed herein may also process certain data as independent controllers for their own purposes (e.g., analytics providers for their own product improvement, auth providers for their own security operations). Those independent controller relationships are described in the Privacy Policy (/privacy). Listing a vendor here as a Subprocessor does not mean all processing by that vendor is conducted as a Subprocessor.

1.3 Definitions. Capitalized terms not defined here have the meanings in the DPA or Terms of Service. "Customer Data" means Personal Data NodeFox processes on behalf of a Customer as a Processor. "DPA" means the Data Processing Addendum. "DPF" means the EU-U.S. Data Privacy Framework (and UK Extension and Swiss-U.S. DPF where applicable). "IDTA" means the UK International Data Transfer Agreement or UK Addendum to EU SCCs. "SCCs" means the Standard Contractual Clauses (Commission Implementing Decision 2021/914) for international data transfers. "Subprocessor" means a third-party Processor engaged by NodeFox to process Customer Data.


SECTION 2. SUBPROCESSOR FRAMEWORK

2.1 Role. Subprocessors assist NodeFox with hosting, storage, authentication, security, payments, communications, analytics, and other operational functions. Access is limited to what is necessary for their function.

2.2 Subprocessor vs. Independent Controller. Some third parties interacting with Customer Data act as independent controllers, not Subprocessors. In particular:

  • Third-party AI providers connected via Customer's own API keys are generally NOT Subprocessors. They act as independent controllers under their own terms. See Section 7.
  • User-configured API destinations (webhooks, databases, SaaS platforms, external HTTP endpoints) that Customers configure Workflows to interact with are NOT Subprocessors. NodeFox acts as the routing engine; recipient destinations of user-configured requests are outside NodeFox's Subprocessor obligations.
  • Public package registries (NPM, PyPI, CDNs) accessed when Customers execute code nodes that dynamically import external dependencies are NOT Subprocessors.
  • Open-source frameworks and gateways (e.g., Model Context Protocol components) that natively interact with package registries or default endpoints are inherent to the open-source architecture; such entities are not Subprocessors.

2.3 NodeFox Affiliates. NodeFox may utilize wholly-owned affiliates, subsidiaries, or authorized contractors for engineering, maintenance, and support. All operate under confidentiality obligations and the security standards in the DPA.

2.4 Sub-tier Processors. NodeFox's primary Subprocessors may engage their own downstream sub-tier processors — most importantly, Supabase hosts the NodeFox database on Amazon Web Services infrastructure in US West (Oregon, us-west-2). AWS is therefore a sub-tier provider of Supabase rather than a Subprocessor NodeFox engages directly. Downstream delegation is governed by the primary Subprocessor's own data processing agreements. NodeFox relies on the primary Subprocessor's contractual guarantees regarding downstream vendor management.


SECTION 3. COMMITMENTS

NodeFox seeks to implement the following practices, proportionate to the beta nature, scale, and risk profile of the Services:

3.1 We seek to enter into written agreements with Subprocessors imposing data protection obligations no less protective than the DPA.

3.2 We typically conduct risk-based due diligence prior to engagement.

3.3 We seek to limit Subprocessor access to what is necessary.

3.4 Where Subprocessors are outside the EEA/UK/Switzerland, we seek to implement appropriate transfer mechanisms as required by applicable law.

3.5 We provide email notice of Subprocessor changes to every DPA Customer, by default and without any subscription requirement, as described in Section 9.

3.6 DPA Customers may object to new Subprocessors as described in Section 10.

3.7 We may monitor Subprocessor compliance on a risk-based basis.

3.8 NodeFox's liability for Subprocessor acts/omissions is as described in the DPA and Terms of Service.


SECTION 4. CURRENT SUBPROCESSORS

Infrastructure and Hosting

SubprocessorPurposeData ProcessedLocationTransfer MechanismStatus
Netlify, Inc.Website and web application hosting, edge network, CDN. Netlify Forms receives and stores the submissions you send through our contact form and email-capture forms. Netlify Edge Functions run an authentication and session check for the applicationIP addresses; request metadata; session cookie; session data; logs; cached content; contact and email-capture form submissions (name, email address, message content, and any other field you complete)United States (global edge network)SCCs; DPF where applicableIn use
Supabase, Inc.Database (PostgreSQL), authentication, real-time subscriptionsUser account data; hashed credentials; Workflow metadata; application dataUnited States (Oregon, us-west-2)SCCs; DPF where applicableIn use

Sub-tier infrastructure. Amazon Web Services, Inc. (AWS) is not engaged directly by NodeFox. Supabase hosts the NodeFox database on AWS infrastructure in US West (Oregon, us-west-2) under Supabase's own agreements with AWS. We name it here for transparency; for the purposes of this List, AWS is a sub-tier processor of Supabase (Section 2.4), not a NodeFox Subprocessor.

No object storage. NodeFox does not operate storage buckets on this backend. Files you add to a Workflow are processed in your browser and sent directly to the destination you configure. The exception is cloud workspace sync, where the workflow blob is encrypted in your browser before it is stored, and Enterprise audit records, which are sealed client-side to the organization administrator's key — NodeFox stores both but cannot read either.

NodeFox does not host the Services on Vercel. Any reference to Vercel in an earlier version of this List or in Annex III to the DPA is superseded by this entry for Netlify.

Authentication and Identity

SubprocessorPurposeData ProcessedLocationTransfer MechanismStatus
Supabase, Inc.Authentication, session management, identity (same entity as above)Email addresses; hashed passwords; auth tokens; session data; login metadataUnited StatesSCCs; DPF where applicableIn use
Google LLC (Google Sign-In)OAuth authentication only (optional; only where Customer/users elect Google Sign-In). Drive, Sheets, and Gmail access is a separate grant made when connecting those integrations — see "User-Authorized Integration Providers" belowGoogle account ID; email; name; profile picture (as user-authorized)United States (global infrastructure)SCCs; DPF where applicableIn use

Payment Processing

SubprocessorPurposeData ProcessedLocationTransfer MechanismStatus
Stripe, Inc.Payment processing on Stripe-hosted Checkout and billing portal pages, subscription billing, invoicingName; email; billing address; payment card data (processed directly by Stripe); transaction historyUnited States (global infrastructure)SCCs; DPF where applicableIn use

Note: Checkout and billing management take place on Stripe-hosted pages, where Stripe sets its own cookies under its own policies. Stripe is PCI DSS Level 1 certified. Payment card data is processed directly by Stripe. NodeFox does not access or store full card numbers; NodeFox receives only last four digits, card type, expiration, and billing postal code.

Communication Services

SubprocessorPurposeData ProcessedLocationTransfer MechanismStatus
Resend, Inc.Transactional email delivery (notifications, password resets, alerts)Email addresses; email content; delivery metadataUnited StatesSCCs; DPF where applicableUsed or planned — Resend is being onboarded as our transactional email provider. Until that is complete, transactional email may be sent through the default mail infrastructure of our authentication provider

Analytics and Monitoring

SubprocessorPurposeData ProcessedLocationTransfer MechanismStatus
Google LLC (Google Analytics)Website and application analytics to understand usage patterns and operate the ServicesIP address (may be anonymized); device/browser info; pages visited; session duration; usage eventsUnited States (global infrastructure)SCCs; DPF where applicableUsed or planned — Google Analytics is being onboarded. Where it is live, the Google Analytics script is loaded only when a visitor enables the Analytics cookie category on our cookie banner; it is not loaded, and no _ga, _gid, or _gat cookie is set, for visitors who reject optional cookies or make no choice

Note: Because Google Analytics loads only on consent, declining the Analytics category on our cookie banner is the primary way to opt out (see the Cookie Policy, Section 16.2, for how to change a choice you have already made). You may also use browser settings or Google's opt-out tools (https://tools.google.com/dlpage/gaoptout). IP anonymization implemented where available.

Managed AI — Pre-Signup Website Demo Only

SubprocessorPurposeData ProcessedLocationTransfer MechanismStatus
Google LLC (Gemini API)Model inference for the public demo on the NodeFox website that visitors can try before creating an account. This is the one place NodeFox calls a model with its own key; the request is made server-side by a NodeFox functionThe prompt text the visitor types and the model's response. A hashed form of the visitor's IP address is stored by NodeFox (not sent to Google) to rate-limit the demoUnited States (global infrastructure)SCCs; DPF where applicableIn use — scoped to the pre-signup demo only

Note on the demo. The prompt and the response are cached by NodeFox in plain text so repeat requests can be served without calling the model again. Demo visitors are anonymous: nothing in the demo is linked to an account, because no account exists yet. The cache is kept for a limited period and purged periodically. Please do not enter personal information, credentials, or confidential material into the demo.

This does not describe the product. Inside the Services, inference runs from your own browser against your own API keys. NodeFox does not proxy those requests and does not store your prompts or outputs server-side. See Section 7.

User-Authorized Integration Providers

These providers receive data only if you connect them and then run a Workflow node that uses the connection. NodeFox registers the connecting application with each provider; when you authorize it, the provider issues access and refresh tokens which NodeFox holds encrypted with AES-256-GCM and uses only to make the calls your Workflows make. Disconnecting an integration deletes the stored tokens; you can also revoke NodeFox's access in the provider's own settings.

ProviderPurposeData ProcessedLocationTransfer MechanismStatus
Microsoft CorporationUser-authorized Microsoft integration nodesOAuth tokens (held encrypted by NodeFox); the content your Workflow sends or retrievesUnited States (global infrastructure)SCCs; DPF where applicableIn use — on user authorization
Discord Inc.User-authorized Discord integration nodesOAuth tokens (held encrypted by NodeFox); message and server content your Workflow sends or retrievesUnited StatesSCCs where applicableIn use — on user authorization
Slack Technologies (Salesforce, Inc.)User-authorized Slack integration nodesOAuth tokens (held encrypted by NodeFox); message and channel content your Workflow sends or retrievesUnited States (global infrastructure)SCCs; DPF where applicableIn use — on user authorization
GitHub, Inc.User-authorized GitHub integration nodesOAuth tokens (held encrypted by NodeFox); repository, issue, and related content your Workflow sends or retrievesUnited States (global infrastructure)SCCs; DPF where applicableIn use — on user authorization
Linear Orbit, Inc.User-authorized Linear integration nodesOAuth tokens (held encrypted by NodeFox); issue and project content your Workflow sends or retrievesUnited StatesSCCs where applicableIn use — on user authorization
Atlassian CorporationUser-authorized Atlassian integration nodes (e.g. Jira, Confluence)OAuth tokens (held encrypted by NodeFox); issue, page, and related content your Workflow sends or retrievesUnited States (global infrastructure)SCCs; DPF where applicableIn use — on user authorization
Dropbox, Inc.User-authorized Dropbox integration nodesOAuth tokens (held encrypted by NodeFox); file content and metadata your Workflow sends or retrievesUnited States (global infrastructure)SCCs; DPF where applicableIn use — on user authorization
Notion Labs, Inc.User-authorized Notion integration nodesOAuth tokens (held encrypted by NodeFox); page and database content your Workflow sends or retrievesUnited StatesSCCs where applicableIn use — on user authorization
Google LLC (Drive, Sheets, Gmail)User-authorized Google integration nodes. Where you grant them, the Google authorization can include Drive, Sheets, and Gmail scopes — including scopes that allow reading, composing, and sending mail on your behalfOAuth tokens and granted scopes (tokens held encrypted by NodeFox); file, spreadsheet, and mail content your Workflow reads, creates, or sendsUnited States (global infrastructure)SCCs; DPF where applicableIn use — on user authorization

Scopes are your choice. Google Sign-In used only to log in does not include Drive, Sheets, or Gmail access. Those scopes are granted separately, on Google's own consent screen, when you connect the corresponding integration. Review what you are granting before you accept, and revoke at https://myaccount.google.com/permissions at any time.

Who decides what is sent. For every provider in this table, the data that leaves NodeFox is determined by the Workflow you build. Once it arrives, that provider's own privacy policy governs it. See Section 12.3.

Peer-to-Peer Connectivity (STUN)

SubprocessorPurposeData ProcessedLocationTransfer MechanismStatus
Cloudflare, Inc.Public STUN server only (stun.cloudflare.com), used by your browser during WebRTC peer-to-peer file transfer to discover the network address needed to open a direct connectionPublic IP address and network candidate information of the participants, during the sessionUnited States (global anycast)SCCs; DPF where applicableIn use — STUN only
Google LLC (public STUN)Public STUN server only (stun.l.google.com), used for the same purpose as abovePublic IP address and network candidate information of the participants, during the sessionUnited States (global anycast)SCCs; DPF where applicableIn use — STUN only

Note on STUN. STUN servers help two browsers find each other. They see the participants' public IP addresses while a peer-to-peer session is being established. They do not receive the transferred files, which travel directly between the peers. Cloudflare's role for NodeFox is limited to this: Cloudflare does not act as our CDN, WAF, DNS, or bot-management provider, and earlier versions of this List that described it that way were inaccurate.

Support Services

NodeFox currently provides customer support directly via email. The infrastructure hosting corporate email communications (Google Workspace / Google LLC) may process Customer Data voluntarily submitted in support emails.

NodeFox may use support tooling vendors in the future. If those vendors process Customer Data as Subprocessors, they will be added to this List.

Support is discretionary. No guaranteed response times.


SECTION 5. SUBPROCESSOR SUMMARY TABLE

SubprocessorCategoryLocationTransferStatus
Netlify, Inc.Infrastructure / CDN / Forms / Edge auth checkUS (global edge)SCCs; DPFIn use
Supabase, Inc.Infrastructure / Auth / DatabaseUS (Oregon, us-west-2)SCCs; DPFIn use
Stripe, Inc.PaymentsUS (global)SCCs; DPFIn use
Google LLC (Sign-In)Authentication (optional)US (global)SCCs; DPFIn use
Google LLC (Gemini API)Managed AI — pre-signup website demo onlyUS (global)SCCs; DPFIn use, demo-scoped
Google LLC (Workspace)Corporate Email / SupportUS (global)SCCs; DPFIn use
Cloudflare, Inc.WebRTC STUN server onlyUS (global anycast)SCCs; DPFIn use, STUN only
Google LLC (public STUN)WebRTC STUN server onlyUS (global anycast)SCCs; DPFIn use, STUN only
Microsoft, Discord, Slack, GitHub, Linear, Atlassian, Dropbox, Notion, Google (Drive/Sheets/Gmail)User-authorized integrationsUS (global)SCCs; DPF where applicableIn use — only on user authorization
Google LLC (Analytics)AnalyticsUS (global)SCCs; DPFUsed or planned; loads only on Analytics consent
Resend, Inc.EmailUSSCCs; DPFUsed or planned
Amazon Web ServicesSub-tier infrastructure of Supabase (not a direct NodeFox Subprocessor)US (us-west-2)Per Supabase's agreementsSub-tier only

The detailed per-vendor entries in Section 4 control if the summary table conflicts.


SECTION 6. COMPLIANCE CERTIFICATIONS

Certifications are as reported by the Subprocessor and may change. NodeFox does not independently certify or guarantee Subprocessor compliance status.

SubprocessorSOC 2ISO 27001PCI DSSOther
AWS (sub-tier, via Supabase)YesYesYesFedRAMP; HIPAA eligible*
SupabaseYes——HIPAA eligible*
StripeYesYesLevel 1—
CloudflareYesYesYes—
GoogleYesYes——
NetlifyYes———
ResendYes———

Certifications above are as published by each vendor; NodeFox has not independently verified them.

HIPAA Note: Vendor HIPAA eligibility refers to that vendor's own offering capabilities. NodeFox does not offer HIPAA processing and does not accept Protected Health Information (PHI) absent a separately executed Business Associate Agreement (BAA).

NodeFox Certifications. As of the Last Updated date, NodeFox has not obtained third-party certifications (SOC 2, ISO 27001). NodeFox may pursue certifications in the future at its discretion without commitment or timeline.


SECTION 7. THIRD-PARTY AI PROVIDERS — NOT SUBPROCESSORS

7.0 Scope of this Section. This Section is about AI providers you connect with your API keys inside the Services. It does not cover the pre-signup demo on our website, which uses a NodeFox-held key and where Google (Gemini API) is a Subprocessor — see Section 4, "Managed AI — Pre-Signup Website Demo Only."

7.1 Third-party AI providers connected via Customer's own API keys are generally NOT Subprocessors. They act as independent controllers or processors under their own terms. Requests to them are made directly from the Customer's browser; NodeFox does not proxy them and does not log prompt or response content server-side.

7.2 When Customers execute Workflows calling AI providers: Customer provides their own keys; Input Data is transmitted to the provider; the provider processes under their own terms; NodeFox acts as a conduit.

7.3 Customer's relationship with each AI provider is governed by their agreement with that provider. NodeFox is not responsible for AI provider data practices, retention, or training policies. Providers' practices are outside NodeFox's control. Customers must not send secrets or credentials to AI providers unless intended.

7.4 Managed AI. Where NodeFox provides AI or model access under NodeFox's own credentials, that vendor is listed as a Subprocessor and is subject to the DPA's subprocessor notification framework. This is the case today for Google (Gemini API), scoped to the public pre-signup demo on our website and listed in Section 4. It is not the case for any logged-in product feature: those remain customer-key BYOK. If that changes, the vendor will be added to this List with notice under DPA Section 9.4 before it begins processing.

7.5 Common AI providers (examples only; may change):

ProviderPurposePrivacy Policy
OpenAIGPT models, DALL-E, embeddingshttps://openai.com/privacy
AnthropicClaude modelshttps://www.anthropic.com/privacy
Google (Vertex AI / Gemini)Gemini modelshttps://policies.google.com/privacy
Mistral AIMistral modelshttps://mistral.ai/privacy-policy/

SECTION 8. DATA TRANSFERS

8.1 Most Subprocessors are in the United States. For Personal Data from the EEA, UK, or Switzerland, we rely on applicable legal mechanisms:

  • DPF where the Subprocessor is certified.
  • SCCs (Commission Implementing Decision 2021/914) where DPF does not apply or as supplementary.
  • UK IDTA or UK Addendum for UK transfers.
  • Supplementary measures where required by transfer impact assessments.

8.2 SCCs/IDTA specifics are governed by the DPA. This section is a summary only.

8.3 Transient Edge Caching. NodeFox utilizes a global edge network through Netlify. Transient copies of data, cached assets, or API responses may be temporarily routed or cached at edge nodes outside the primary storage jurisdiction. Such transient caching does not constitute a permanent geographic data transfer and is necessary for global delivery of the Services.


SECTION 9. SUBPROCESSOR CHANGE NOTIFICATION

9.1 NodeFox may add or remove Subprocessors as business needs evolve. NodeFox operates two notification mechanisms, both of which exist today:

  1. Email to every Customer subject to the DPA. Under DPA Section 9.4, NodeFox sends email notice to the Customer's Account or designated contact address at least thirty (30) days before a new or replacement Subprocessor begins processing Customer Data. This is the default; no subscription or opt-in is required.
  2. Update to this List. NodeFox updates this List and its Last Updated date when a Subprocessor is added, removed, or materially changed. This is a supplementary channel, not a substitute for the email notice.

9.2 Customers who want notices sent to a different address (for example a compliance or security distribution list) may set or change that address by emailing legal@nodefox.ai with subject "Subprocessor Notification Address," including company name, contact name, and notification email. Failing to do so does not remove the entitlement to notice; it only means notice goes to the Account address.

9.3 NodeFox does not operate an RSS feed, webhook, or self-service notification portal for Subprocessor changes. The two mechanisms in Section 9.1 are the complete list.

9.4 NodeFox may add or replace a Subprocessor on shorter notice where necessary to respond to a security incident, comply with a legal requirement, or avoid service disruption. In that case NodeFox gives email notice as soon as practicable, and the Customer's objection period under the DPA runs from that notice.

9.5 All notification mechanics, timelines, and obligations are governed by the DPA. This List does not expand or modify DPA notification obligations.


SECTION 10. OBJECTION TO SUBPROCESSORS

10.1 DPA Customers may object to new Subprocessors on data protection grounds by submitting a written objection to legal@nodefox.ai within the period specified in the DPA.

10.2 Objections must include: the specific Subprocessor; data protection grounds; and any alternative arrangements acceptable.

10.3 NodeFox may consider objections and may, in its discretion, provide additional information, offer alternatives, or implement additional safeguards. NodeFox is not obligated to accommodate objections.

10.4 If the objection cannot be resolved, either party may terminate the affected Services per the DPA. Termination is Customer's sole and exclusive remedy.

10.5 If Customer does not object within the DPA-specified period, Customer is deemed to have accepted the new Subprocessor, where permitted by applicable law and the DPA.

10.6 All objection mechanics, timelines, and remedies are governed by the DPA. This List does not create independent objection rights.


SECTION 11. SUBPROCESSOR REQUIREMENTS

NodeFox seeks to require Subprocessors to contractually commit to, as appropriate under our agreements:

11.1 Confidentiality of Personal Data and personnel obligations.

11.2 Appropriate technical and organizational security measures, including industry-standard encryption at rest.

11.3 Assistance with data subject requests, security incidents, and impact assessments as required under our agreements and applicable law.

11.4 Audit rights (NodeFox typically retains audit rights; Customer audit rights are per the DPA).

11.5 Return or deletion of Personal Data upon termination, subject to backups/legal holds.


SECTION 12. CUSTOMER RESPONSIBILITIES

12.1 Customers are responsible for reviewing this List and determining compatibility with their own compliance requirements.

12.2 Where Customers act as Controllers: lawful bases, data subject notices, data subject request responses, impact assessments, and compliance with applicable law remain Customer's responsibility.

12.3 Customers are solely responsible for third-party AI provider relationships, user-configured webhook/API destinations, and optional features — including which of the user-authorized integration providers in Section 4 they connect, which scopes they grant (notably Google Drive, Sheets, and Gmail), and what their Workflows send to them.

12.4 Customers should keep the Account (or designated) contact email current so that Subprocessor notifications reach the right person.


SECTION 13. DATA RETENTION AND SECURITY

13.1 Each Subprocessor has its own retention policies. We seek to require retention only as long as necessary and deletion upon instruction, subject to backups and legal holds. NodeFox's own retention is expressed as criteria rather than fixed automated periods; see Privacy Policy Section 30.2. Integration tokens are deleted on disconnection or Account deletion; the pre-signup demo cache is purged periodically.

13.2 Upon termination or Customer request, we instruct Subprocessors to delete Customer Data per the DPA, where applicable and technically feasible.

13.3 SOC 2 reports and audit reports for Subprocessors may be available to DPA Customers under NDA in NodeFox's discretion, subject to Subprocessor restrictions. Contact legal@nodefox.ai.


SECTION 14. GEOGRAPHIC INFORMATION

14.1 Customer Data is generally stored and processed in the United States. The primary database is hosted in US West (Oregon, us-west-2). Some Subprocessors have global infrastructure and may process data in additional locations subject to transfer safeguards; STUN servers in particular are anycast and the node answering you may be outside the United States, though it receives only connection metadata and never file content.

14.2 Enterprise customers may request information about regional data processing options. Contact sales@nodefox.ai. Availability not guaranteed.

14.3 NodeFox does not intentionally store or process data in sanctioned jurisdictions. See the AUP (/legal/acceptable-use-policy).


SECTION 15. GENERAL

15.1 NodeFox's liability for Subprocessor acts/omissions is per the DPA and Terms of Service. Liability limitations in those agreements apply.

15.2 NodeFox may modify this List at any time. The Last Updated date indicates the most recent revision. Previous versions may be available.

15.3 This List is informational. It does not constitute legal advice. Customers should consult their own counsel.


SECTION 16. CONTACT

PurposeContact
Subprocessor Questions / Objections / Notificationslegal@nodefox.ai
Privacy Inquiriesprivacy@nodefox.ai
Data Protection Officerdpo@nodefox.ai
Security Questionssecurity@nodefox.ai
Enterprise Data Residencysales@nodefox.ai

NodeFox may respond to inquiries; no guaranteed response time.

Mailing Address (send all correspondence here): NodeFox LLC, PO Box 1667, Ross, CA 94957, United States.

Principal Place of Business (no mail delivery): NodeFox LLC, a California limited liability company, 2108 N St, Suite N, Sacramento, CA 95816, United States.

EU Representative: Euverify Ltd (Ireland), Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork T23 AT2P, Ireland. Email: gdpr@euverify.com.

UK Representative: Euverify Ltd (UK), 3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom. Email: gdpr@euverify.com.

GDPR Request Portal: https://gdpr.euverify.com/verify/40de1847-966c-42c5-bc95-9ad6c91c3348


IMPORTANT NOTICES

Beta Status. The Services are in beta. This List may change as the Services evolve.

Third-Party AI Providers. AI providers connected via Customer's own API keys are NOT Subprocessors.

Managed AI. Where NodeFox provides AI access under its own credentials, that vendor is listed here. Today that is Google (Gemini API), scoped to the pre-signup demo on our website only.

User-Authorized Integrations. Nine providers receive data only when you connect them and run a Workflow that uses them. See Section 4.

No Warranties. This List does not create service-level commitments, warranties, or guarantees.

No Legal Advice. Consult your own counsel regarding compliance obligations.


DocumentURL
Legal Center (index of all documents)/legal
Terms of Service/terms
Privacy Policy/privacy
Data Processing Addendum/legal/data-processing-addendum
Cookie Policy/legal/cookie-policy
Acceptable Use Policy/legal/acceptable-use-policy
EULA/legal/end-user-license-agreement
Marketplace Terms/legal/marketplace-terms
IP & DMCA Policy/legal/ip-dmca-policy

ACKNOWLEDGMENT

This Subprocessor List is provided for transparency. For DPA Customers, Subprocessor engagement, notice, objection, and related rights are governed by the DPA.


END OF SUBPROCESSOR LIST

© 2025–2026 NodeFox LLC. All rights reserved.

NodeFox LLC, a California limited liability company | Mailing address: PO Box 1667, Ross, CA 94957, United States | Principal place of business: 2108 N St, Suite N, Sacramento, CA 95816, United States | https://www.nodefox.ai