Sub-processors
Every third party that may process personal data for Gheima, what it does and where it does it.
Version 0.1 · Last updated September 19, 2026
These documents are a first published draft. They describe what the platform actually does today, but they have not yet been reviewed by a lawyer. We are publishing them because billing customers with no terms at all is worse; expect the wording to change once counsel has been through it.
Who processes data for us#
A sub-processor is a third party that may handle personal data in the course of us running the platform. This is the complete current list. We update it before adding anyone, and account holders are notified by email at least thirty days before a new sub-processor starts processing — see section 6 of the Data Processing Agreement.
The list#
| Sub-processor | What it does for us | Where |
|---|---|---|
| Hostinger International Ltd | Rents us the servers that run the eu-1 region and, today, the control plane. It has no application-level access; data on the disks is ours. | European Union |
| Oracle Corporation | Provides the cloud region af-casablanca-1, which hosts the ma-1 region, and the object storage holding that region's offsite backups. The facility is operated with N+ONE Datacenters. | Casablanca, Morocco |
| Cloudflare, Inc. | Authoritative DNS for gheima.ma, and routing for inbound email to our support address. Traffic to residency regions is deliberately not proxied through Cloudflare, so that TLS for those regions terminates in-country. | Global network; company in the United States |
| Resend (Plus Five Five, Inc.) | Delivers transactional email — sign-in links, invitations, invoices, deploy and alert notifications. Receives the recipient address and the message. | United States |
| YouCan Pay | Processes card payments and subscriptions in dirhams. Receives the billing email and the amount; card details go to it directly and never reach us. | Morocco |
| GitHub, Inc. | Source of the repositories you choose to build, through the GitHub App you install, and an identity provider if you sign in with GitHub. Receives the repository and commit references we act on. | United States |
GitLab is not on this list. GitLab support works with an access token you paste for your own instance, which means the instance is yours and we are not sending your data to a GitLab we chose. The same is true of any self-hosted Git host you connect.
Things that look like sub-processors and are not#
- Geolocation for analytics is resolved from an offline country database that ships inside our own containers. No request data leaves the platform to resolve a country.
- Search, queues, object storage, logging and metrics are all self-hosted on our own infrastructure. They are not third-party services.
- We do not use a third-party product-analytics or session-recording tool in the dashboard, and we do not run advertising trackers.
- Error reporting to a third party is configurable but is currently switched off in production. If we turn it on, this page changes first.
Questions#
To object to a sub-processor, or to ask what a specific one receives, write to hello@gheima.ma.