Sub-processors

Last updated: 26 May 2026 · Version 1.0

This page lists the third-party sub-processors Koda uses to deliver the service. A sub-processor is any company we engage to process personal data on our behalf as part of providing Koda to you.

We carry out due diligence on each sub-processor before engaging them, including reviewing their security posture, certifications and data processing terms. We have signed Data Processing Agreements (DPAs) or equivalent contractual safeguards with every sub-processor that handles personal data.

Notification of changes: we will update this page at least 30 days before adding a new sub-processor that processes personal data. To receive email notifications, email [email protected] and ask to be added to the sub-processor change list.

Infrastructure & hosting

ProviderPurposeData processedLocationSafeguards
Railway Corp. Application hosting (compute, runtime, build pipeline) All Koda data in transit while served; logs USA (primary region) UK→US SCCs + UK Addendum; encrypted in transit (TLS 1.2+)
Cloudflare, Inc. CDN, DDoS protection, DNS, edge proxy IP addresses, request metadata, security telemetry Global edge; corporate USA UK→US SCCs + UK Addendum; Cloudflare DPA
Cloudflare R2 Object storage (images, brand-pack PDFs, generated report assets) Client media uploads, brand pack PDFs, org logos EU region preferred where available EU storage AES-256 at rest; signed S3-compatible access
Railway Postgres Primary application database All structured Koda data (users, clients, posts, captions, etc.) Same region as Railway compute (USA primary) UK→US SCCs + UK Addendum; encrypted at rest & in transit

AI & content processing

ProviderPurposeData processedLocationSafeguards
Anthropic, PBC Claude API: captions, brand voice analysis, brand pack parsing, report copy Client brand profile, post drafts, brand pack text, website scan text USA UK→US Anthropic Commercial Terms + DPA. No training on API traffic. 30-day operational retention max.
Automattic, Inc. (mShots) Public website screenshot rendering for brand scan Public URLs only — no Koda user data sent USA No personal data shared; public service

Email & transactional messaging

ProviderPurposeData processedLocationSafeguards
Resend, Inc. Transactional email delivery (sign-up, password reset, client reports, invites) Recipient email, sender details, email body, delivery metadata USA UK→US Resend DPA; SCCs + UK Addendum; TLS in transit

Payments

ProviderPurposeData processedLocationSafeguards
Stripe Payments UK Ltd Subscription billing, payment processing, customer portal Billing email, billing address, card last-4, payment metadata UK / EU / USA Stripe is its own controller for card data PCI-DSS Level 1. Koda never sees full card numbers.

Third-party platforms (user-initiated connections)

The following are not strictly sub-processors — they are platforms you choose to connect to Koda. Once you link an account, the platform processes data under its own terms in addition to ours.

ProviderPurposeData processedLocationSafeguards
Meta Platforms Ireland Ltd (Instagram Graph API) Posting, insights, DMs, comments, hashtag listening — for client IG accounts you connect OAuth tokens (encrypted), post metadata, insights, DM/comment content Ireland (EU) EU controller Tokens AES-256-GCM encrypted at rest in Koda. Subject to Meta Platform Terms.
Google LLC (Google OAuth) Sign-in with Google (optional) Google account email, name, profile picture URL USA / global UK→US Google Cloud DPA + SCCs

Internal monitoring

Koda does not currently use a third-party error tracker, product analytics service, or session-replay tool. Application logs are stored within Railway and retained for the lifetime of the deployment.

Questions

For questions about any sub-processor, our due-diligence process, or to request a copy of a DPA we hold with a sub-processor, email [email protected].