ClusterFast Legal

Subprocessor Register

Last updated: 18 June 2026

ClusterFast uses the subprocessors below to operate the service. This register is referenced from our Privacy Policy and may be updated as providers change. Privacy contact: support@clusterfast.app.

ProviderPurposeData categoriesLocation / transferSafeguards
OpenAILLM inference for briefs, segmentation, research, and campaign generationPrompts, structured context, generated outputs, usage metadataUnited StatesAPI terms, data processing agreement where available, prompt minimization, no training opt-out where supported
Google OAuthOptional client authenticationEmail, name, Google subject identifier, OAuth tokens during loginUnited States / globalOAuth 2.0, limited scopes, state signing
Meta Graph APIOptional ad account connection and campaign launch when enabled by the userMeta user ID, ad account/page identifiers, encrypted access tokens, campaign payloadsUnited States / globalUser-initiated connection, encrypted token storage, disconnect and erasure workflows
CityHost VDSApplication hosting, database hosting, backupsAll service data stored for production operationUkraine / EU region depending on provider configurationPrivate network exposure, encrypted secrets, restricted SSH access
GitHub ActionsCI testing and deployment automationSource code, build logs, deployment metadataUnited States / globalRepository access controls, secret management, least-privilege deploy keys