Tracuto Subprocessor list
Effective date: May 10, 2026 Legal bundle version: 2026-05-10 Controller / Processor (as applicable): KOHA-TECH Sp. z o.o. (trade name Tracuto), ul. Nowy Świat 33/13, 00-029 Warszawa, Poland · KRS 0001183713 · NIP 5253054129 · REGON 542256381 · Share capital PLN 5,000
This page lists the third parties that process personal data on our behalf in connection with the Tracuto Service (subprocessors). It is read together with the Privacy Policy and Data Processing Agreement. Material changes are notified per the DPA Section 5 (currently 30 days’ prior notice with a right to object on data-protection grounds).
Note: Your own stack (your hosting, CDN, marketing tools, customer-support tools, AI providers, etc.) is not listed here. This list covers only KOHA-TECH’s vendors for operating Tracuto.
A. Production infrastructure (EEA)
| # | Subprocessor | Role | Location | Transfer mechanism |
|---|---|---|---|---|
| 1 | Hostinger International Ltd | Cloud hosting for the Tracuto Service. | Germany (EEA) | Intra-EEA — no Chapter V transfer. |
| 2 | Zoho Corporation B.V. (Zoho Mail) | Transactional and operational email — account verification, password reset, billing, breach and security notifications. | European Union | Intra-EEA where data is stored in the EU. |
Database and other storage layers are operated by KOHA-TECH itself within infrastructure provided by the subprocessors above and are therefore not separate subprocessors.
B. Billing
| # | Subprocessor | Role | Location | Transfer mechanism |
|---|---|---|---|---|
| 3 | Stripe, Inc. | Payment processing, billing portal, tax calculation (where enabled), invoices. | United States | EU SCCs (Module 2) + UK Addendum / Swiss adaptation per Stripe’s DPA. |
| 4 | Stripe Technology Europe, Ltd | Stripe services for customers in the EEA/UK depending on transaction routing. | Ireland / EEA | Intra-EEA where applicable; otherwise under Stripe’s SCC framework. |
C. AI / session intelligence
| # | Subprocessor | Role | Location | Transfer mechanism |
|---|---|---|---|---|
| 5 | Mistral AI | Session Intelligence (friction analysis) for organizations with EU data region — replay summaries and evidence packs only; no training on Customer Data per Mistral terms. | European Union (Mistral API, EU processing) | Intra-EEA for EU-region customers. |
| 6 | Anthropic PBC | Session Intelligence for global (non-EU) organizations. | United States | EU SCCs (Module 2) + supplementary measures; used only when regional routing selects Anthropic. |
Organizations default to EU region (ai_data_region=eu) and are routed to Mistral when MISTRAL_API_KEY is configured. Set ai_data_region=global on the organization for US and other non-EU routing to Anthropic.
D. Pending / planned
The following categories are planned but not yet active. We will give 30 days’ notice before any of them goes live, with the vendor name and region disclosed at that time:
- Observability / error tracking.
- Customer-support tooling.
E. Invoices and VAT
Paid subscriptions are billed through Stripe. Taxes (VAT, GST, sales tax) are calculated and shown at checkout by Stripe Tax where enabled. Polish customers are charged Polish 23 % VAT; EU B2B customers outside Poland with a valid VAT number receive a reverse-charge invoice. Invoices issued through Stripe reflect KOHA-TECH’s legal name, address, NIP and other tax details.
F. Customer’s right to object
Under the DPA §5, Controllers may object on documented data-protection grounds to any new or replacement subprocessor within 30 days of notice. Where parties cannot resolve the objection, the affected portion of the Service may be terminated with a pro-rata refund of prepaid fees.
G. Subscribe to changes
To receive change notifications, ensure that the billing/owner email of your Tracuto organisation is current and add a security contact in dashboard settings if available.