Sub-processors and security
Who processes your data, and where
The page a public buyer or an engineering office attaches to a purchase file. One table of every company that touches customer data on our behalf, the security measures in plain words, and a data processing agreement you can sign before paying.
Last updated 8 September 2026
Data processing agreement
A DPA you can sign before paying
Pre-filled under Article 28(3) GDPR with TerraLab as processor. Complete the controller block, sign, and send it back to the privacy contact below. The sub-processor list inside it points to this page, so it stays current without a new signature.
The founders complete the SIREN and address lines before countersigning. Bespoke terms take a call, not a form.
Sub-processors
Every company that processes customer data for us
Nobody else touches it. Sales and internal tools that never receive plugin or account data are not on this list. We train no model on your imagery and we sell it to no one.
| Purpose | Company | Country | Hosting region | Transfer mechanism | Retention |
|---|---|---|---|---|---|
| Database and authentication | Supabase | USA company, EU hosting | AWS Paris (eu-west-3) | Data stays in the EU | Life of the account, then a 15-day grace after deletion. Encrypted backups expire within 12 months |
| Images and files | Google Cloud Storage | USA company, EU hosting | Paris (europe-west9) | Data stays in the EU | Life of the account, erased on deletion or earlier on request |
| AI Segmentation inference | Google Cloud Run | USA company, EU hosting | Belgium (europe-west1) | Data stays in the EU | Processed in memory, no copy kept after the request. The upload staging area empties after 7 days |
| AI Agent language model | Microsoft Azure OpenAI | USA company, EU hosting | EU data zone (westeurope) | Data stays in the EU | No copy kept after the request; not used to train models |
| AI Edit image generation | fal.ai | USA | United States | Standard contractual clauses (2021/914) | Inputs kept about 30 days by fal, then erased |
| Website and API hosting | Vercel | USA company | Paris (cdg1) | EU-US Data Privacy Framework | Hosting only, no customer file stored on Vercel |
| Product analytics | PostHog | USA company, EU hosting | Frankfurt | Data stays in the EU | 24 months at most |
| Transactional and product emails | Loops | USA | United States | EU-US Data Privacy Framework | Contact erased with the account |
| Rate limiting | Upstash | USA company, EU hosting | Ireland | Data stays in the EU | One counter per key or IP address, kept 65 seconds |
| Website translation | Google Translate API | USA company | EU/US | EU-US Data Privacy Framework | Not stored; page text only, no customer data |
| Payments | Stripe | USA company, EU entity | EU/US | EU-US Data Privacy Framework | 10 years for invoices, French accounting law |
Change notice: any addition or replacement of a sub-processor is announced on this page 30 days before it takes effect. Customers with a signed DPA may object in writing within that period.
Security
The measures, in plain words
Every line here matches something in our code or our contracts. When the behaviour changes, this page changes with it.
Data location
Account data, imagery and inference run in the European Union: Paris for the database and files, Belgium for AI Segmentation, West Europe for the AI Agent model. Only AI Edit generation leaves the EU, under standard contractual clauses.
Encryption
TLS 1.2 or higher on every connection between the plugin, the website and each provider. Data at rest is encrypted by the provider (AES-256 on Supabase, Google Cloud and Azure).
Access
Two founders hold production access, with two-factor authentication on every provider console. No contractor, no offshore support, no shared account.
Deletion
You delete your account yourself from the dashboard. It stays recoverable for 15 days, then every row, file and email contact is erased and the erasure is verified.
Data export
The results you keep already live on your computer, in QGIS. Account and usage data are exported on request in JSON within 30 days.
Breach notification
A personal data breach is reported to the CNIL within 72 hours of discovery and to the affected customers without undue delay, with what happened, what data, and what we did.
Pro private tier
On the Pro private tier, no technical copy of your imagery or results is kept after the request, and nothing you send is used to improve any model.
Questions
Send this page to whoever signs off
Security questionnaires, a signed DPA or a supplier file go to yvann.barbot@terra-lab.ai. We answer within two working days.
yvann.barbot@terra-lab.ai