This list identifies providers used by Rowsh to process Customer Personal Data for the Service. A provider is a Rowsh subprocessor only to the extent it processes that data on Rowsh's behalf. Payment providers and customer-directed integrations may instead act as independent controllers or as the customer's own processors for some activities.
1. Core service subprocessors
- Contabo GmbH — infrastructure hosting. Hosts the Rowsh application, PostgreSQL databases, service logs, and the self-hosted real-time calling service. Core production processing is in the European Economic Area.
- Cloudflare, Inc. — encrypted object storage and bot protection. Cloudflare R2 stores customer-uploaded objects, and Turnstile processes limited device, network, and challenge signals on protected public forms. Rowsh encrypts production uploads at the application layer before storage. Cloudflare operates globally and may process limited account, security, and service data in the United States and other locations described in its service terms.
- Mailgun Technologies, Inc. (Sinch) — transactional email. Delivers account, security, billing, workspace, and support messages. Rowsh uses Mailgun's EU regional service endpoint; limited delivery, support, and subprocessor handling may occur in other locations under Sinch's data-protection terms.
- Functional Software, Inc. (Sentry) — error and performance diagnostics. Receives limited server-side operational errors and sampled performance data. Optional browser diagnostics are sent only after the user allows them in Rowsh's privacy choices. Default personal-data collection is disabled in Rowsh's SDK configuration. The active Sentry project uses Sentry's Germany data region; limited support and subprocessor handling may occur elsewhere under Sentry's data-protection terms.
2. Conditional AI subprocessor
- OpenAI OpCo, LLC and its disclosed affiliates and subprocessors. Processes prompts, authorised workspace context, generated output, embeddings, images, or audio only when an authorised user invokes a Rowsh feature that uses the platform OpenAI service. Processing may occur in the United States and other locations in OpenAI's published subprocessor list. OpenAI's services DPA incorporates the UK Addendum for UK data.
If a customer supplies its own provider key or selects a self-hosted model, the provider and data path are controlled by that configuration. The customer must review the provider terms that apply to its account and instructions.
3. Provider used for Rowsh controller operations
- GoDaddy.com, LLC — business mailbox service. Hosts Rowsh's public contact mailbox and may process messages sent directly to Rowsh, including support, security, and privacy correspondence. It generally supports Rowsh's own controller operations rather than processing workspace content as a DPA subprocessor.
4. Payment providers
Stripe and JazzCash support the billing paths identified at checkout. The provider and group entity identified in the applicable checkout and merchant terms may act as an independent controller for payment credentials, identity verification, fraud prevention, and regulatory compliance, and as a processor for limited payment services. Rowsh receives transaction, customer, subscription, invoice, tax, and payment-status data rather than full payment-card or wallet credentials. JazzCash availability for Pakistan-based purchases does not change ROWSH LTD's country of incorporation.
5. Customer-directed integrations
When a customer enables an integration or supplies provider credentials, that provider may receive data at the customer's direction and may be the customer's processor or an independent controller. The customer is responsible for the integration's permissions, provider terms, lawful use, retention, and data location. Rowsh processes the connection and exchanged data only as needed to provide the enabled integration.
6. International transfers
Rowsh relies on UK adequacy regulations where they cover the destination. Where an applicable transfer is not covered by adequacy, Rowsh uses the provider's binding data-protection terms incorporating the UK International Data Transfer Agreement, the UK Addendum to approved standard clauses, or another lawful safeguard, and completes the required data-protection test. Contact Rowsh through the data-protection request path to request information about the safeguard relevant to a particular service.
7. Changes and objections
Rowsh gives reasonable advance notice before a material new or replacement subprocessor begins processing Customer Personal Data, normally by updating this page and notifying the customer's workspace contact. A customer may object on reasonable data-protection grounds before the change takes effect. If an immediate replacement is reasonably necessary for security, availability, or legal compliance, Rowsh may make the change first and give notice without undue delay. If the parties cannot resolve an objection, either party may terminate the affected Service as the agreement permits.