Draft. The list below is accurate for the product as designed. Processing regions are not yet stated and the data-processing agreements are not yet confirmed as executed. See the notes under the table. Both are completed as part of contracting.
A sub-processor is a third party that processes personal data on our behalf so that we can provide LynxSprint. This page is the authoritative list. It is short on purpose: every entry is a party that could hold data, and the smallest defensible list is the right one.
| Sub-processor | Purpose | Data it touches | Processing location |
|---|---|---|---|
| Cloudflare, Inc. | DNS, CDN, TLS termination, static site hosting, and the tunnel that publishes the API | Request metadata (IP address, user agent) in transit. No application data at rest. | Global edge network |
| Supabase | Authentication provider — sign-in, sessions and token issuance | Email address and authentication metadata. No employee, project or time data. | Not yet stated |
| Amazon Web Services (SES) | Transactional email — verification, invitations, reminders | Recipient email address and message content | Not yet stated |
| Hostinger | Human mailboxes for role addresses, and domain registration | Correspondence you send us | Not yet stated |
| Anthropic | Large-language-model provider for the optional AI features | Only what a permitted tool returns, for organizations that have opted in. Off by default; no data is sent when AI is disabled. | Not yet stated |
What is deliberately not on this list
- No analytics provider. This website loads no analytics and sets no cookies, and the product does not send usage data to a third party.
- No advertising or marketing-automation platform.
- No chat widget or support tool embedded in the site or the product.
- No CDN-hosted fonts or libraries. Everything is served from our own origin.
That is a shorter list than most products of this kind publish, and it is the direct consequence of a rule we hold ourselves to: no third-party JavaScript. It is what allows the site to declare a content-security policy that permits scripts only from its own origin, and to mean it.
Processing locations
We are not naming regions yet. Several are genuinely undecided, and a page that named the settled ones and estimated the rest would be wrong in a way a procurement review is designed to find. We would rather answer this once, correctly, than quickly now.
Locations will be stated per row above, together with the transfer mechanism relied on for any international transfer, before general availability.
The AI provider, specifically
The language-model provider is listed because it must be, but it is worth being precise about when it is engaged at all. AI features are an organization-level opt-in and are off by default. When they are off, no data reaches the provider. When they are on, only what a permitted tool returns is sent, sensitive fields are excluded before that point, and each run is recorded.
Our requirement of any model provider is that content is not retained beyond the request and is not used for training. We will confirm on this page when that is contractually in place rather than stated as a requirement.
Changes to this list
Adding a sub-processor is a change customers should hear about before it happens, not discover afterwards. Once LynxSprint has customers we will give advance notice of additions, with a defined notice period set out in the data-processing agreement.
In the meantime the effective date at the top of this page changes whenever the list does.
Questions
Email contact@lynxsprint.com. If you are assessing LynxSprint for procurement and need something this page does not answer, ask. We would rather tell you what is undecided than let you infer it.