legal / sub-processors
Sub-processors.
The providers Kehai uses, their access to personal data, and where they process it. Planned additions and replacements are announced at least 7 calendar days beforehand. Last updated 2026-09-13-r4. Questions go to privacy@kehai.io.
01
What this list is
A sub-processor processes personal data on behalf of Kehai when Kehai acts as a processor for a customer. This page also identifies providers used for accounts, payments, communication, and service monitoring, whose roles depend on the purpose of processing.
It covers two different relationships and says which is which. For visitors to a customer's registered sites, the customer is the controller and Kehai is their processor under GDPR art. 28; the companies below are then sub-processors, and the Data Processing Addendum governs them. For the operator's own data, such as an account, an invoice, or an inquiry, the operator is the controller. Providers may act as processors or as independent controllers for their own stated purposes. Each entry distinguishes those roles.
Planned additions or replacements of sub-processors are announced at least 7 calendar days beforehand, by email to account owners. A customer who objects on reasonable data protection grounds within that window may terminate without penalty for the remainder of the term.
Provider terms and processing arrangements: OVHcloud, Cloudflare, Resend, Stripe, Google, and Apple. Provider DPAs can form part of the accepted service terms without a separate signature. They define the processing covered by each service, including international transfers and the provider's own sub-processors.
02
Infrastructure
OVHcloud
The application and analytics database are hosted in Warsaw, Poland. Backups use OVH object storage. The object-storage location was verified as Warsaw on September 10, 2026. The security page describes backup expiration and the scope of recovery testing. Storage location does not mean that all authorized support access is confined to Poland. The published sub-processor list and OVHcloud DPA describe that separate scope.
03
Public traffic
Cloudflare, Inc.
Cloudflare provides Kehai's DNS and proxies service hostnames for TLS termination and protection against denial of service. It also runs human checks on the contact and newsletter forms and routes inbound mail sent to the domain to the operator's destination mailbox.
It terminates TLS, so it can read what passes through it. That includes the body of an analytics request, not only its metadata. Product copy therefore never claims that nothing leaves the operator's servers, because that would not be true.
Cloudflare may set the cf_clearance cookie when a security challenge is presented. It records that a browser passed the challenge. Under its Turnstile Privacy Addendum, Cloudflare also acts as an independent controller when using human-check signals to improve bot detection.
04
Plus Five Five, Inc. (Resend)
Transactional messages include invitations, password links, security notices, the contact form notification, and the alerts and digests an account has switched on. The operator's own replies leave the same way: a message written from hello@kehai.io is relayed by Resend, so its content and delivery record pass through the United States like every other outgoing message. The one marketing path is the newsletter, which a person asks for on the landing page and confirms from their inbox: Resend holds the list of confirmed addresses as an audience, sends the issues, and handles the one-click unsubscribe on each.
Mail is sent from the EU region, which is where it leaves from and not where it is kept: Resend stores message content and delivery logs in the United States. An alert or a digest can carry a site name, a filter, and analytics totals, which is what makes Resend a sub-processor rather than only a processor for the operator's own mail.
05
Payments
Stripe
Payment happens on Stripe's own hosted pages. Kehai never sees or stores a card number and receives confirmation of payment plus the invoice details it is required to keep.
For the Polish account, the Stripe Services Agreement identifies Stripe Payments Europe, Limited, with Stripe Technology Europe, Limited also a party where its Financial Services Terms apply. Stripe acts as a processor for parts of the payment service and as a controller for its own purposes, including fraud prevention and legal obligations. This concerns Kehai account and payment data, not the visitor analytics processing covered by the DPA.
06
Only when a customer connects them
The following product integrations are used only when an account enables the relevant feature. Sign-in and read-only imports do not receive Kehai's visitor event stream. A customer-directed Google Ads export is a separate, explicit disclosure of eligible conversion data.
Optional features include signing in with Google, importing history from Google Analytics, and reading a site's Search Console property so the queries Google sent sit beside the referrers. Analytics and Search Console request separate read-only scopes. Google's role in its source Analytics service follows that customer's Analytics terms. Reading that service does not appoint Google to process Kehai's visitor event stream.
Analytics import and Search Console credentials are encrypted before storage and request read-only scopes. Google sign-in tokens use the authentication library's storage without that additional encryption. These integrations do not send Kehai's event stream to Google.
Apple
One feature, optional. Signing in with Apple, offered beside signing in with Google so that a person is not forced to hold a password. Apple acts as an independent controller for its sign-in service under its sign-in privacy notice. The developer agreement is with Apple Inc., which is a different role from the regional controller of a person's Apple account.
A person who chooses to hide their address signs in under a relay Apple operates, and Kehai uses that relay address for the account and also stores the sign-in provider identifiers and tokens needed for authentication. Apple is never sent anything about a customer's visitors.
07
Optional commerce and advertising paths
A customer can connect its own Stripe account to import supported confirmed sales and refunds. That account and its payment data are governed by the customer's Stripe agreement. Kehai receives supported payment records and stores encrypted connection credentials. This is separate from Stripe processing the operator's own subscription payments. The WordPress plugin runs in the customer's hosting environment and sends enabled tracking and commerce data to Kehai. Installing it does not send Kehai's analytics to the WordPress Foundation or Automattic.
Customers may also authorize Wix or Squarespace as their own store data sources. Those accounts remain governed by the customer's provider agreements. Kehai reads supported store records and stores encrypted connection credentials; it does not send its visitor event stream back to those platforms. The PrestaShop module runs in the customer's hosting environment.
A customer can also export eligible conversions for Google Ads as a CSV file or enable a revocable feed URL. The customer chooses the destination and is responsible for its authority and applicable consent. The export includes eligible click identifiers and conversion values. It does not upload the complete visitor event stream. The Google Ads guide describes its scope and consent controls.
08
Other processing and local software
Operational monitoring uses UptimeRobot s.r.o., Slovakia to check public health endpoints and page availability and to alert the operator. It receives monitor URLs, response results and the operator's contact details. These checks do not send visitor event rows or customer account records. UptimeRobot is a processor for monitoring data and a controller for its own account purposes. Its DPA covers processing and transfers involving the EU, the United States and other listed locations.
Inbound mail routed by Cloudflare is received in the operator's Gmail mailbox. Google processes that correspondence under the applicable mailbox terms and privacy policy. Its retention is separate from Resend delivery records. The Privacy Policy describes the correspondence purpose and retention. A Gmail destination does not by itself establish a Google Workspace agreement or an EU-only storage setting.
Kehai runs its own analytics software. The software counting page views is Kehai itself, on infrastructure the operator rents and administers. Infrastructure providers process data needed to run the service. Customer-authorized sharing, exports, API access, and assistants are separate paths. Kehai does not sell analytics data.
Kehai does not embed advertising pixels, retargeting services or session recorders. Geolocation uses a local DB-IP Lite database, so no visitor address is sent to DB-IP for a lookup. Error reporting runs on the operator's own infrastructure. Provider sub-processor lists describe their onward processing separately from the features Kehai enables.