Data Processing Terms & Sub-processors
Last updated: 30 July 2026 · Draft for legal review
Roles
- For your account data (email, name) and the missions you run, sessiontwin is a controller.
- Where you ask sessiontwin to work on a repository, and its contents include other people's personal data (for example, names and emails in commit history, code or comments), sessiontwin processes that data on your behalf: you are the controller and sessiontwin is your processor. In that case the Article 28 terms below apply.
- sessiontwin itself runs on Base44, which is sessiontwin's own processor; the vendors listed below are sub-processors.
Processor commitments (to be formalised in a DPA)
Where sessiontwin acts as your processor, it will: process personal data only on your documented instructions; keep it confidential; apply appropriate security; engage sub-processors only as listed here and pass down equivalent terms; assist you with data-subject requests and breach notifications; and delete or return the data on termination, subject to the immutability of the signed ledger described in the Privacy Policy.
Sub-processors
sessiontwin relies on Base44 (Wix) for hosting, and Base44 in turn relies on the
sub-processors below (from Base44's published DPA Exhibit C, retrieved 30 July 2026).
Because sessiontwin runs entirely on Base44, these are effectively sessiontwin's
sub-processors. In addition, sessiontwin's front end loads the Base44 SDK from the
esm.sh CDN and is served via Cloudflare.
| Sub-processor | Purpose | Location |
|---|---|---|
| MongoDB | Data storage and hosting | US |
| SendGrid | Email transmission | US |
| Langfuse | LLM logging | Germany |
| Logfire | Logging | UK |
| Render | Server services | US |
| Google Cloud (GCP) | Analytics services | US |
| OpenAI | LLM API calls | US |
| Anthropic | LLM API calls (sessiontwin's models run here) | US |
| Wix.com Ltd. | Providing and improving the services | Israel |
| Supabase | Media hosting | US |
| DataDog | Logging | US |
| Cloudflare | CDN / edge delivery and real-user monitoring (added by sessiontwin) | Global |
| esm.sh | CDN serving the Base44 browser SDK (added by sessiontwin) | Global CDN |
Discrepancy to resolve: Base44's public Trust Center additionally lists AWS and Modal as providers, which do not appear in Exhibit C. The authoritative set must be confirmed with Base44.
Changes to sub-processors
Base44's DPA provides for notice of new sub-processors (seven days) and a right to object. We will maintain this list and note material changes here.
Open questions for counsel
- Prepare a signable DPA with full Article 28(3) terms for customers whose repo data includes third-party personal data.
- Confirm the authoritative Base44 sub-processor list (Exhibit C vs Trust Center: AWS, Modal) and each one's role and region.
- Confirm the transfer mechanism relied on for onward US transfers (EU-US DPF and/or SCCs) and document it.
- Confirm the controller/processor mapping for the current build (operator-token access) and for the future per-user-repo model.
- Decide whether product-improvement / model-training on repo contents is a separate controller activity needing its own basis and disclosure.