← Previous version

Subprocessor List

Effective August 26, 2026
Version 1.3 · Last updated August 26, 2026
Controller: Kirill Maximenko (Cyprus self-employed entity, TIN 60056031S)
3 Evagora Pitali, 4040 Germasogeia, Limassol, Cyprus
info@toolum.ai

1. About this document

This Subprocessor List identifies the third-party service providers ("Subprocessors") that Toolum engages to process Personal Data on behalf of its users. We publish this list to give Builders — the people who create digital products with Toolum — clear visibility into where their data travels and under what protections.

This document is a companion to our Privacy Policy and our Data Processing Addendum (the "DPA"). Where definitions in this list overlap with those documents, the Privacy Policy and DPA prevail for binding legal interpretation; this list serves as the authoritative inventory of currently engaged Subprocessors.

Service. "Toolum" or "the Service" refers to the Toolum platform operated by Kirill Maximenko (Cyprus self-employed entity, TIN 60056031S), accessible at https://toolum.ai. Toolum is an AI-powered no-code builder for digital products, enabling users ("Builders") to design and generate application mockups, design systems, content, and exportable code through natural-language prompts and visual editing.


2. What is a Subprocessor

Under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), a "Subprocessor" is a third party engaged by the data controller (Toolum) or a primary processor to carry out specific processing activities on behalf of the controller. Subprocessors process Personal Data only on documented instructions from Toolum and under contractual safeguards that include the GDPR Article 28 obligations.

In plain terms: when you use Toolum, your data passes through services we rely on to deliver the platform — for example, the database that stores your projects, the AI providers that generate code, and the payment processor that handles your subscription. Each of these is a Subprocessor. We pick them carefully, contract with them on terms that protect you, and disclose them here.


3. General authorization for Subprocessor engagement

By using Toolum, you provide a general written authorization for Toolum to engage the Subprocessors listed in Section 5 below, and to add or replace Subprocessors as the Service evolves. This authorization is recorded in our Terms of Service and DPA and is consistent with GDPR Article 28(2).

We commit to:

  1. Keeping this list current. When we add a new Subprocessor that processes Personal Data, or replace an existing one, we will update this page and revise the "Last Updated" date at the top.

  2. Notifying you of material changes. For Subprocessors handling sensitive categories of data (for example, payment processing or AI inference involving your prompts and content), we will provide notice through one of the following channels at least fourteen (14) days before the change takes effect:

    • An update to this page (recommended: subscribe via RSS or check this page periodically)
    • An email to the address on your Toolum account
    • An in-product notification
  3. Respecting your objection right. If you object to a Subprocessor change on reasonable grounds, you may terminate your Toolum subscription before the change takes effect and request a pro-rata refund of unused credits per our Refund Policy.

We have chosen general written authorization rather than a fixed thirty-day approval window because:


4. How we evaluate Subprocessors

Before engaging a Subprocessor that processes Personal Data, we review:

We maintain records of each Subprocessor's DPA and applicable transfer safeguards. These are available to enterprise customers under NDA on request to info@toolum.ai.


5. Current Subprocessors

The following ten (10) Subprocessors are currently engaged by Toolum. Each entry lists the Subprocessor's identity, the processing activity it performs, and its primary processing location. The transfer mechanism that applies when Personal Data leaves the EEA is set out in Section 8 of our Data Processing Addendum; Toolum maintains a record of the specific mechanism for each Subprocessor (see Section 4 above).

5.1 AI inference providers

Toolum routes user prompts and content to AI inference providers through a fallback chain to maintain Service availability. Anthropic is the primary provider for most Builder interactions; OpenAI and Google serve as fallbacks during Anthropic outages or rate-limit events. All three providers are engaged from the date this list is first published, regardless of fallback activation frequency in any given period.

#SubprocessorRolePrimary Location
1Anthropic, Inc.AI inference (Claude models — primary)United States
2OpenAI, Inc.AI inference (GPT models — fallback)United States
3Google LLC (Google Cloud / Gemini API)AI inference (Gemini models — fallback)United States

About AI processing of your data. When you submit a prompt or content to Toolum, the relevant portions are transmitted to the active AI inference provider for that request. Toolum has configured each provider to:

Detailed AI processing behavior is described in our AI Transparency Statement and our Privacy Policy.

5.2 Infrastructure and platform services

#SubprocessorRolePrimary Location
4Supabase, Inc.Database, authentication, file storageIreland (EU-West-1)
5MVPS.netApplication hosting (virtual private server)Germany
6Hostinger International Ltd.Domain registrarCyprus

5.3 Communications and operations

#SubprocessorRolePrimary Location
7Resend, Inc.Transactional email deliveryUnited States
8Stripe Payments Europe Ltd.Payment processing, subscription billingIreland

Note on Stripe: Payment processing is active. Toolum uses Stripe to process subscription payments; when you subscribe to a paid plan, your payment data is transmitted to and processed by Stripe as described in this list.

5.4 Analytics and observability

#SubprocessorRolePrimary Location
9PostHog Inc. (PostHog UK Ltd. for EU customers)Product analytics, error tracking, AI generation tracing (includes the content of generation requests and responses — Customer Content)European Union (PostHog EU Cloud: eu.posthog.com)
10Functional Software, Inc. (Sentry)Error monitoring and crash reportingEuropean Union (Sentry EU region); entity incorporated in the United States

6. What each Subprocessor receives

Different Subprocessors receive different categories of data. The following summary indicates the typical scope; the Privacy Policy describes data flows in full detail.


7. Data Subject Rights and Subprocessors

Under GDPR Articles 15-22, you have rights to access, rectify, erase, restrict, port, and object to processing of your Personal Data. When you exercise these rights with Toolum, we forward applicable requests to relevant Subprocessors and obtain confirmation of their action.

For data held by AI inference providers specifically: due to the technical nature of large language model APIs, individual prompt deletion within retention windows is generally automatic at the end of each provider's retention period (typically 30 days). Toolum will confirm to you when the retention window has elapsed for any specific request.

To exercise any data subject right, contact info@toolum.ai. We respond within thirty (30) days under GDPR Article 12(3).


8. Changes to this list

The Subprocessor List is a living document. We update it whenever we engage, replace, or remove a Subprocessor.

For material changes affecting your data, see Section 3 above on our notification commitments.


9. Contact

For questions about this list, our Subprocessors, or your data rights:

For enterprise customers requiring a custom DPA review, evidence of specific Subprocessor agreements, or audit documentation, please indicate the request type in your email subject line.


This Subprocessor List is published by Toolum (Kirill Maximenko, Cyprus self-employed entity). It is informational and forms part of the contractual framework defined in the Toolum Terms of Service, Privacy Policy, and DPA. Where this list and any of those documents conflict, the Privacy Policy and DPA prevail.

Document version 1.3. Effective August 26, 2026.