Striive is run by Striive v/ Mathias Quist Michaelsen · Midgårdsvej 10, 8800 Viborg · CVR 46826159 · VAT no. DK46826159 · admin@striiveai.com
Sub-processors
Effective
This is a translation. The Danish version is the one that applies. Read the Danish version
1. For customers’ websites (Striive as processor)
These sub-processors process data that forms part of customers’ websites, under the data processing agreement. We give at least 30 days’ notice of changes by e-mail.
| Provider | Task | What it receives | Location and basis |
|---|---|---|---|
| Google Cloud EMEA Ltd. | Servers, database, media, backups and operational logs | All data on the website | EU (Stockholm) |
| Resend, Inc. | Sending e-mails | The recipient’s address and name, the e-mail’s content | Sending in the EU; account data, metadata and logs in the US. Standard contractual clauses |
| OpenRouter, Inc. | Relaying AI requests | Messages to the AI assistant and the content it works with | US. Standard contractual clauses |
| Anthropic PBC, Google LLC, OpenAI LLC | AI models | The same as OpenRouter, for the model used | US. EU-U.S. Data Privacy Framework or standard contractual clauses |
| Unsplash Inc. | Stock photos on published websites | Visitors’ IP address and browser details when the image is shown; no cookies | US. Standard contractual clauses |
2. For Striive’s own processing (Striive as controller)
These providers process data Striive is itself the controller for, as described in the privacy policy.
| Provider | Task | What it receives | Location and basis |
|---|---|---|---|
| Google Cloud EMEA Ltd. | Operating Striive | Accounts, sign-ups, sessions, audit log | EU (Stockholm) |
| Google Workspace (Google Cloud EMEA Ltd.) | Striive’s e-mail at striiveai.com | Enquiries and reports sent to us | EU and US. EU-U.S. Data Privacy Framework and standard contractual clauses |
| Google Ireland Limited (Google Analytics) | Visitor statistics on striiveai.com, only with the visitor’s consent | Page views, referring page, browser, device, language, approximate location and a random id from the cookie | EU and US (Google LLC). EU-U.S. Data Privacy Framework and standard contractual clauses |
| Stripe Payments Europe Ltd. | Payments, subscriptions, receipts and invoices | Name, e-mail, address, card details, payments | EU and US. EU-U.S. Data Privacy Framework and standard contractual clauses |
| Resend, Inc. | Sending the service’s e-mails | E-mail address, name, the e-mail’s content | Sending in the EU; account data, metadata and logs in the US. Standard contractual clauses |
| Metronome, Inc. | Measuring and billing AI usage | The website’s id and name, Stripe’s customer number, model name and token counts, no content | US. Standard contractual clauses |
| OpenRouter, Inc. and the AI providers | The AI assistant and extracting facts for demo sites | Messages and content to be processed | US. As above |
| JFreaks Software Solutions Pte. Ltd. (screenshotapi.net) | Screenshots of public websites for the reference library | The address of the public page; the screenshot may show people who appear on the page | Singapore; images stored with Wasabi in the EU (Frankfurt). Standard contractual clauses |
| Unsplash Inc. | Searching stock photos in the editor | The search words; when thumbnails are shown, the user’s IP address | US. Standard contractual clauses |
Simply.com and Let’s Encrypt are used for domains and HTTPS certificates. They receive only domain names, not personal data. Note that issued certificates, and so domain names, are public in certificate transparency logs.