Skip to content
eu/jev.
PlaygroundEU hostingDocs
Log inGet an API key
EU/JEV / LEGAL
LegalImpressumPrivacy policyTerms of ServiceData Processing AgreementSubprocessors

Subprocessors

Last reviewed: 30 September 2026

These providers support the deployed eu/jev service. The first group processes customer API data on our behalf. Other providers below have different roles. Our public API connects directly to the Hetzner deployment in Germany. Separate DNS, sign-in and request-form services can involve processing outside the EEA.

Customer-data subprocessors

Hetzner Online GmbH

Industriestr. 25, 91710 Gunzenhausen, Germany

Service
Infrastructure hosting for the application, PostgreSQL database and GPU inference worker.
Personal data
API inputs and outputs during processing; account, credential hashes, usage, security and agreement records on the origin server.
Location
Origin hosting and model execution in Germany. Provider administration and any onward processing are governed by the applicable hosting agreement.
Processing and transfer safeguards
Bevel has accepted Hetzner’s Article 28 processing agreement. The German origin hosting does not itself require a third-country transfer mechanism. Any onward transfer requires a separate valid Chapter V basis.

Provider processing terms · Provider’s onward subprocessors

Google sign-in and request forms

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and relevant Google affiliates provide Google account sign-in. Google acts under its own account and identity terms; this is not an API-inference subprocessor. Google receives sign-in interactions and sends us a verified identity, name and email. eu/jev does not send API prompts or outputs to Google for inference.

The waitlist and extra-usage form belongs to Bevel’s Google Workspace and opens only when you follow its link. Google Workspace processes submitted contact and project details on Bevel’s behalf under its processing terms. Bevel is the controller for reviewing these requests. This form storage is separate from the customer API processing covered by our DPA. Google also receives interaction and technical data when you use its form.

Google’s published contracting entity for Workspace customers in Germany is Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland, subject to the applicable Workspace agreement.

Google operates internationally, so these interactions are not promised to remain in the EEA. See Google’s privacy policy and the Google Workspace processing terms. Google’s processing terms include safeguards for applicable international transfers; this page does not promise EU-only form storage. Do not send sensitive API content through the request form or support email. Email correspondence also involves the sending and receiving mail providers.

DNS

Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States, provides authoritative DNS for our domain. The jev.bevel.software record is DNS-only: website and API HTTPS traffic goes directly to our Hetzner deployment. Cloudflare does not terminate that HTTPS traffic or receive its API inputs and outputs.

DNS still involves processing domain queries and resolver connection metadata on Cloudflare’s international network. This is separate from API-content processing. See Cloudflare’s privacy policy.

Deployment and software providers

Coolify is self-hosted on our Hetzner server; we do not use Coolify Cloud to operate this deployment. GitHub hosts source code and deployment integration, outside the customer inference request path. Neither is an API-data subprocessor in this setup. Model and package distributors provide software and weights, not hosted inference for this deployment.

The current default inference worker runs locally in the Hetzner deployment. Scaleway and TypeSafe are not configured as providers for that request path. Historical benchmarks and optional adapters in this repository do not mean those providers receive production requests.

Changes and objections

The initial customer-data subprocessor list is included in each accepted DPA. We will notify DPA customers by their agreement contact email at least 30 days before adding or replacing a customer-data subprocessor, with an opportunity to object on data-protection grounds. The public list is not a substitute for that notice.

For an objection, processing information or provider evidence, write to juan@bevel.software. This list identifies recipients; it is not a GDPR certification or proof that every required operational control has been verified.

eu/jev.
ImpressumDocumentationLegal
by BevelNot affiliated with TypeSafe AI.