Legal
Sub-processors
The third-party service providers that help us run Open Lab, and where your data is processed. Last updated June 2026.
For help, visit Support or check the documentation.
A sub-processor is a third party we engage to carry out specific processing on our behalf. With respect to the study data researchers collect through the platform, Open Lab acts as the researcher's processor, and these vendors act as our sub-processors — each handling only the data needed for its part, under a contract with data-protection obligations (Art. 28 GDPR).
This list is incorporated by reference into our Data Processing Agreement and constitutes the controller's general written authorisation of sub-processors under Art. 28(2) and (4) GDPR. We publish it for transparency.
Notice of changes. Before we add or replace a sub-processor that processes researcher or participant personal data, we will give advance notice by updating this page and emailing account owners, with a 30-day window during which a researcher (controller) may reasonably object. If an objection cannot be resolved, the researcher may stop using the affected service as their remedy.
This list is incorporated by reference into our Data Processing Agreement and constitutes the controller's general written authorisation of sub-processors under Art. 28(2) and (4) GDPR. We publish it for transparency.
Notice of changes. Before we add or replace a sub-processor that processes researcher or participant personal data, we will give advance notice by updating this page and emailing account owners, with a 30-day window during which a researcher (controller) may reasonably object. If an objection cannot be resolved, the researcher may stop using the affected service as their remedy.
Our compute, the PostgreSQL database, and Spaces object storage are all hosted by DigitalOcean in Frankfurt (fra1), Germany. The bulk of personal data — including study datasets and uploaded files — therefore stays in the EU. Our analytics provider, PostHog, is also served from an EU-hosted instance.
Where a researcher enables end-to-end encryption for a study (the researcher holds the key), providers that merely store that study's data — including DigitalOcean — cannot read its contents. Other study data is protected by the hosting provider's encryption at rest and by access controls.
Where a researcher enables end-to-end encryption for a study (the researcher holds the key), providers that merely store that study's data — including DigitalOcean — cannot read its contents. Other study data is protected by the hosting provider's encryption at rest and by access controls.
| Sub-processor | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| DigitalOcean | Cloud hosting — compute, PostgreSQL database, and Spaces object storage | All platform data, including encrypted study datasets and uploaded files, and account records | Frankfurt (fra1), Germany — EU | Data hosted in the EU. US-parent company; covered by the vendor's DPA and Standard Contractual Clauses as a backstop |
| Stripe | Researcher subscription billing and payment processing | Researcher name, email, billing details (card data handled directly by Stripe), customer & subscription IDs | US / global | EU–US Data Privacy Framework and/or Standard Contractual Clauses |
| Postmark | Transactional and marketing email delivery | Recipient email and name, email content | US | EU–US Data Privacy Framework and/or Standard Contractual Clauses |
| Tremendous | Participant payout fulfilment (bank, PayPal, or gift card via a hosted redemption page) | Participant name, email, payout amount and currency | US | EU–US Data Privacy Framework and/or Standard Contractual Clauses |
| Researcher sign-in (only if a researcher chooses Google sign-in) | Researcher email, name, basic profile | US / EU | EU–US Data Privacy Framework and/or Standard Contractual Clauses | |
| ORCID | Researcher sign-in (only if a researcher chooses ORCID sign-in) | Researcher ORCID iD, email | US / global | Standard Contractual Clauses |
| PostHog | Product / usage analytics — loads only if you accept analytics cookies | Pseudonymous usage events; for a consented, signed-in user, identified events including email/name | EU-hosted instance (eu.i.posthog.com) — data stays in the EU | Data hosted in the EU. US-parent company; covered by the vendor's DPA |
Core hosting and storage are in the EU (Frankfurt), and our analytics stay in the EU. Transfers outside the EEA arise only via the US-based vendors above, and only for the specific purposes shown (billing, email, participant payouts, and optional sign-in). For those transfers we rely on the EU–US Data Privacy Framework where the recipient is certified, and on the European Commission's Standard Contractual Clauses as a safeguard or fallback. Study data for which a researcher has enabled encryption remains unreadable by storage providers.
Study definitions posted from builder.open-lab.online to open-lab.online stay within Open Lab Online UG's own systems and are not a sub-processor transfer.
Last updated: June 2026.
Last updated: June 2026.
Questions about a sub-processor?
If you need this list for your institution's records or a data-processing assessment, contact us at info@open-lab.online.