Transparency register · v1.0

Service Providers, Subprocessors & AI Providers.

Public register: third parties materially involved in customer/user data, delivery of Herm, or AI functionality.

[copy TBC — legal review] Standfirst: what this register is, who it is for, and the fact that it is published for transparency and enterprise due diligence rather than because a specific rule requires it.
01 · About this register

One factual database, several policies.

[copy TBC — legal review] Purpose of the register, and the statement that this is the single source of truth for vendor disclosure across Herm — one factual database with several policies explaining its legal significance.
What this page is

A transparency register, not a dump of Herm's entire technical stack.

What this page is not

The public register does not include every npm package, Python dependency, API endpoint, internal developer tool, database component or operational SaaS account.

Why we publish it
[copy TBC — legal review] Why the register exists: transparency, enterprise due diligence and governance — and how it relates to, without overstating, Article 28 and the EU AI Act.
How the policies reference this register
Privacy Policy → “For our current list of service providers that process personal data, see our Service Providers, Subprocessors & AI Providers register.”
GDPR Compliance → Explains Article 28, DPAs, international transfers and subprocessor governance, then references the same register.
AI Policy → “Our current third-party AI providers are maintained in our Service Providers, Subprocessors & AI Providers register.”
DPA / B2B terms → Incorporates the Subprocessors portion of that register by reference and specifies the notification/objection mechanism.
◍ herm · how to read a row
Data Protection Role — the legal classification depends on the actual processing relationship rather than the name of the vendor.
AI providers — an AI provider does not automatically become a GDPR processor/subprocessor merely because Herm uses its API.
An em dash — means the field is not yet completed. Rows expand for the full field set.
02 · Personal data processors & subprocessors

Where services actually process personal data.

[copy TBC — legal review] Scope of this register, and how the controller / processor / subprocessor relationship is determined for a given row.
● active — not completed + expand row
Provider · servicePurposeHerm service Data protection roleStatus
Amazon Web Services, Inc. AWS EC2 / RDS / S3 Hosting and storage Consumer Herm / GEO / Website Processor ● Active
Provider legal entity
Amazon Web Services, Inc.
Data processed
Account data, purchase data
Processing location
Frankfurt, Germany
International transfer
None
Retention
Last updated
18 August 2026
PostHog Product analytics ● Active
Provider legal entity
Data processed
Processing location
International transfer
Retention
Last updated
18 August 2026
Sentry Error monitoring ● Active
Provider legal entity
Data processed
Processing location
International transfer
Retention
Last updated
18 August 2026
Google ● Active
Provider legal entity
Data processed
Processing location
International transfer
Retention
Last updated
18 August 2026

Role values: Processor · Subprocessor · Independent controller. The legal classification depends on the actual processing relationship rather than the name of the vendor.

03 · AI & model providers

The AI services Herm uses, and what reaches them.

AI Providers: third-party AI services Herm uses to provide or operate its products. An AI provider does not automatically become a GDPR processor/subprocessor merely because Herm uses its API.

[copy TBC — legal review] How to read this section: what "personal data sent", "customer content" and "data used for provider model training" mean, and the anonymised-product-information case.
Provider · serviceHerm usePersonal data sent Provider trainingStatus
OpenAI API Product/brand matching; GEO generation ● Active
Herm product
Consumer backend / GEO
Customer content
Processing region
Service
API
Model
Various models
Last updated
18 August 2026
Anthropic API ● Active
Herm product
Customer content
Processing region
Service
API
Model
Various models
Last updated
18 August 2026
Google API ● Active
Herm product
Customer content
Processing region
Service
API
Model
Various models
Last updated
18 August 2026
AWS Bedrock API ● Active
Herm product
Customer content
Processing region
Service
API
Model
Various models
Last updated
18 August 2026
xAI API ● Active
Herm product
Customer content
Processing region
Service
API
Model
Various models
Last updated
18 August 2026
Perplexity API ● Active
Herm product
Customer content
Processing region
Service
API
Model
Various models
Last updated
18 August 2026
OpenRouter API ● Active
Herm product
Customer content
Processing region
Service
API
Model
Various models
Last updated
18 August 2026
Qwen API — contracted provider to be named ● Active
Herm product
Customer content
Processing region
Service
API — contracted provider to be named
Model
Various models
Last updated
18 August 2026
On model versions

Models used: Various models offered by the provider. Herm may change individual model versions as models are evaluated, updated or deprecated.

Data used for provider model training
YesNoNot applicable
[copy TBC — legal review] What "training/secondary use: not permitted" records, and which contract or configuration it refers to.
04 · Other material third-party services

External dependencies that are material to the service.

External dependencies that are material to the service but are not necessarily processors or AI providers. Classification: Integration · Infrastructure · Authentication · Analytics · AI · Communications.

[copy TBC — legal review] Why these are listed separately, and the point that an OAuth identity provider should not be shoehorned into "subprocessor" when the actual legal relationship is more nuanced.
Provider · serviceClassificationPurpose Personal data involvedStatus
Google Google OAuth / Gmail API Authentication ● Active
Herm service
Processing location
Last updated
18 August 2026
Apple Apple Sign-In Authentication ● Active
Herm service
Processing location
Last updated
18 August 2026
To be named Authentication provider Authentication ● Active
Herm service
Processing location
Last updated
18 August 2026
To be named Email delivery Communications ● Active
Herm service
Processing location
Last updated
18 August 2026
To be named CDN / network services Infrastructure ● Active
Herm service
Processing location
Last updated
18 August 2026
To be named App distribution / build infrastructure Infrastructure ● Active
Herm service
Processing location
Last updated
18 August 2026
To be named External APIs / integrations Integration ● Active
Herm service
Processing location
Last updated
18 August 2026
05 · GEO measurement platforms

Measured, not supplied.

GEO Measurement Platforms: AI services against which Herm may measure a brand's visibility, such as ChatGPT, Claude, Gemini, Perplexity and Grok. These are distinct from the AI providers in section 03, which Herm uses to provide or operate its products.

[copy TBC — legal review] The clarification that appearing here does not mean the platform receives personal data — worded so it cannot be read as a data-sharing disclosure.
◍ herm · measurement panel five models · equal weight · personalisation off
PlatformPersonal data sentRelationship
ChatGPT Measured
Claude Measured
Gemini Measured
Perplexity Measured
Grok Measured

└ A platform can appear in section 03 and in section 05 for different reasons: once as a service Herm uses, once as a service Herm measures.

06 · International data transfers

Every transfer has a stated mechanism.

Each row in section 02 states its international transfer position: None / SCCs / UK IDTA / DPF / adequacy.

[copy TBC — legal review] Herm's transfer position: which mechanisms are relied on, how transfer assessments are handled, and what is available to customers on request.
Mechanisms used in this register
None No international transfer for the processing described in the row.
Adequacy Adequacy decision.
SCCs Standard Contractual Clauses.
UK IDTA UK International Data Transfer Agreement.
DPF EU–US Data Privacy Framework.
07 · Changes to providers and subprocessors

Notice before, not after.

[copy TBC — legal review] Framing for this section, including how it relates to general subprocessor authorisation under Article 28.
Changes to subprocessors

Where required by our contractual or data-protection obligations, we will provide customers with notice before engaging a new subprocessor that will process personal data on their behalf.

Objection mechanism
[copy TBC — legal review] How notice is given, the notice period, and how a customer may object — to match the notification/objection mechanism in the DPA.
08 · Contact

Questions about a row.

[copy TBC — legal review] Who to contact, for what, and the route for enterprise security review or a DPA question.
Contact points
Privacy and data protection enquiries
Security review and questionnaires
Data controller entity
EU / UK representative, where applicable

Service provider register v1.0, last updated 18 August 2026 · Policies