sessiontwin

Data Processing Terms & Sub-processors

Last updated: 30 July 2026 · Draft for legal review

Draft — not yet reviewed by a lawyer. This page explains when sessiontwin acts as a processor on your behalf and lists the sub-processors it relies on. A signable Data Processing Agreement (DPA) with the required GDPR Article 28 terms should be prepared by counsel; this page is the factual basis for it.

Roles

Current build note. Today, access to code uses the operator's own GitHub credentials rather than each user connecting their own repository, so the "you are the controller of the repo data" scenario is limited in practice. This page is written to be correct once per-user repository connection ships; counsel should confirm the current-build position.

Processor commitments (to be formalised in a DPA)

Where sessiontwin acts as your processor, it will: process personal data only on your documented instructions; keep it confidential; apply appropriate security; engage sub-processors only as listed here and pass down equivalent terms; assist you with data-subject requests and breach notifications; and delete or return the data on termination, subject to the immutability of the signed ledger described in the Privacy Policy.

Sub-processors

sessiontwin relies on Base44 (Wix) for hosting, and Base44 in turn relies on the sub-processors below (from Base44's published DPA Exhibit C, retrieved 30 July 2026). Because sessiontwin runs entirely on Base44, these are effectively sessiontwin's sub-processors. In addition, sessiontwin's front end loads the Base44 SDK from the esm.sh CDN and is served via Cloudflare.

Sub-processorPurposeLocation
MongoDBData storage and hostingUS
SendGridEmail transmissionUS
LangfuseLLM loggingGermany
LogfireLoggingUK
RenderServer servicesUS
Google Cloud (GCP)Analytics servicesUS
OpenAILLM API callsUS
AnthropicLLM API calls (sessiontwin's models run here)US
Wix.com Ltd.Providing and improving the servicesIsrael
SupabaseMedia hostingUS
DataDogLoggingUS
CloudflareCDN / edge delivery and real-user monitoring (added by sessiontwin)Global
esm.shCDN serving the Base44 browser SDK (added by sessiontwin)Global CDN

Discrepancy to resolve: Base44's public Trust Center additionally lists AWS and Modal as providers, which do not appear in Exhibit C. The authoritative set must be confirmed with Base44.

Changes to sub-processors

Base44's DPA provides for notice of new sub-processors (seven days) and a right to object. We will maintain this list and note material changes here.

Open questions for counsel

  1. Prepare a signable DPA with full Article 28(3) terms for customers whose repo data includes third-party personal data.
  2. Confirm the authoritative Base44 sub-processor list (Exhibit C vs Trust Center: AWS, Modal) and each one's role and region.
  3. Confirm the transfer mechanism relied on for onward US transfers (EU-US DPF and/or SCCs) and document it.
  4. Confirm the controller/processor mapping for the current build (operator-token access) and for the future per-user-repo model.
  5. Decide whether product-improvement / model-training on repo contents is a separate controller activity needing its own basis and disclosure.