SUBPROCESSOR LIST

www.hookd.group

Document Set v1.2 · Effective: 2026-05-18

Supersedes: v1.1 (2026-05-18) and v1.0 (2026-05-15)

This document is part of the Hookd Group v1.2 legal pack, comprising: General Terms & Conditions, Privacy Policy, Cookie Policy, Refund Policy, Data Processing Agreement (DPA, Annex I to the Terms), and Subprocessor List. All documents in this set share the same effective date and must be read together. In the event of conflict between documents, the order of precedence is: (i) any individually-signed Order; (ii) the General Terms & Conditions; (iii) the Data Processing Agreement (for matters of personal-data protection, the DPA prevails over the Terms); (iv) the Refund Policy; (v) the Subprocessor List; (vi) the Privacy Policy; (vii) the Cookie Policy.

Hookd Group is the operating brand of OmnisMundi GmbH, a private limited company organised under the laws of the Federal Republic of Germany, with registered office at Kirchhainer Strasse 62, 60433 Frankfurt am Main, Germany, registered with the commercial register of the local court of Frankfurt am Main (Managing Director: Gerald Heydenreich). All references in this document to "Hookd Group", "the Company", "we", "us" or "our" mean OmnisMundi GmbH acting under the brand "Hookd Group". General contact: info@hookd.group. Data-protection enquiries: privacy@hookd.group. Web: https://www.hookd.group.

This Subprocessor List is referenced from Section 8 of the Hookd Group Data Processing Agreement (DPA) and from Section 6 of the Hookd Group Privacy Policy. It identifies the entities engaged by Hookd Group to process personal data on behalf of Hookd Group Clients (Controllers) in the course of providing the Hookd Group Service.

Subprocessor changes are notified to Controllers at least 14 days before they take effect. Controllers may object on reasonable data-protection grounds per DPA Section 8.4.

1. List of Subprocessors

NameRole / PurposeLocationData CategoriesTransfer MechanismStatus
Polar Software, Inc.Payment processor (Merchant of Record) — billing, recurring charges, refunds, invoicingUSABilling-contact name, business address, VAT ID, tokenised payment-card metadata, transaction historySCCs Module 2 + DPF (where applicable)Live
Brevo SASTransactional + marketing email delivery; integrated outbound email channel where Client activates email featureFrance (EEA)Sender + recipient email addresses, message content, open/click event timestamps and metadataIntra-EEA (Art 44 GDPR not applicable)Live
Anthropic, PBCPremium-tier AI model (Claude Sonnet) for Cast content generationUSAInput prompts containing AI-generation context (which may include Prospect names / business email / brief context), Hookd Group-side audit hashesSCCs Module 3 + DPFLive
Anthropic, PBCMid-tier AI model (Claude Haiku) for AI openers, deep enrichment, classificationUSAAs above for the same providerSCCs Module 3 + DPFLive
PostHog Inc.Product analytics, usage instrumentation, dashboards (per Phase 7 instrumentation spec)USAUser identifiers (pseudonymised), event metadata (clicks, views, feature usage), session timestampsSCCs Module 2 + DPFLive
HetznerApplication hosting, web server, database, file storageFrankfurt, GermanyAll Client Content at rest; encryptedSCCs Module 3 + DPFLive

2. Notes on Specific Subprocessors

2.1 Polar Software, Inc. — Merchant of Record

Polar operates as the Merchant of Record for all Hookd Group transactions, meaning Polar (not Hookd Group) is the entity that contracts directly with the Client for the payment transaction and handles tax, refunds, and chargeback flows. Card data is tokenised by Polar and not stored by Hookd Group.

2.2 AI Provider Stack — Tier-Based Routing

Per the internal AI Model Routing Specification, Hookd Group uses a least-cost-with-quality-floor routing logic across multiple AI providers. The current stack comprises:

  • Premium tier — Anthropic Claude Sonnet (used for voice-critical content generation)
  • Mid tier — Anthropic Claude Haiku (used for openers, classification, deep enrichment)
  • Budget tier — DeepSeek V3 (used for basic enrichment and structured extraction)

Provider rotation and tier transitions are governed by the routing logic and are not Controller-controlled. Where the Controller has a documented data-protection objection to a specific provider, Hookd Group will accommodate within reasonable engineering constraints.

2.3 DeepSeek — Elevated-Review Subprocessor

DeepSeek is located in Hong Kong SAR / People's Republic of China, which does not benefit from a European Commission adequacy decision. Hookd Group maintains DeepSeek under elevated review pending completion of a Schrems II-style Transfer Impact Assessment ("TIA"):

  • Data minimisation: only the minimum personal data required for the enrichment or extraction task is transmitted
  • No special-category data is ever routed via DeepSeek
  • Outputs are processed with attention to potential downstream re-identification risks

A formal TIA will be completed before public launch; if the assessment is not favourable, DeepSeek will be replaced with an alternative budget-tier provider.

2.4 Hosting and Backup — Pre-Launch TBD

As of the version date of this List, the hosting and backup providers are: Hetzner (Frankfurt, Germany) for application hosting, web server, database and file storage (see table). The provider-selection preferences applied were:

  • EU-region (Germany, France, or Ireland) for primary storage of Client Content — minimises cross-border transfer issues
  • Provider with ISO 27001 or equivalent certification
  • Provider offering encryption at rest with key-management controls
  • Backup provider with cross-region replication and air-gapped option for incident-recovery scenarios

3. Subscription-Activated Subprocessors

Some subprocessors are engaged only when the Controller activates specific features:

  • Brevo SAS — engaged only when the Controller activates outbound email features
  • AI provider stack (Anthropic, DeepSeek) — engaged for any AI-generation, enrichment, or scoring action; deactivation is not feasible without disabling the corresponding feature

Controllers who do not activate the email feature are not subject to data transfer to Brevo.

4. Subprocessors Removed or Replaced

None as of the version date of this List. Removed or replaced subprocessors will be listed here with the effective date of removal and the reason.

5. Updates to This List

Hookd Group may update this Subprocessor List from time to time. Material changes (additions, replacements, removals) will be communicated to Controllers at least 14 days before they take effect, per DPA Section 8.4.

— End of Subprocessor List —