GROUPSPACE
Legal · subprocessors

Subprocessors

The service providers GROUPSPACE relies on to run the product, what each category handles, and how changes to the list are announced.

Last updated 10 August 2026

Draft. This document is a working draft prepared for GROUPSPACE and has not been reviewed by a lawyer. Do not publish it as binding policy until counsel has read it — particularly the sections covering children’s data, and the Roblox and Discord platform terms it depends on.

What a subprocessor is

GROUPSPACE processes personal data on a customer’s behalf. To do that we use other companies — a host, a database, a payment processor. Those companies are subprocessors, and the DPA requires us to tell you who they are.

Each one is bound by written terms with data protection obligations no less protective than ours, may only act on our instructions, and we stay fully liable to you for what they do.

Two categories are not settled yet. Hosting, the database and payment processing are decided and named below. Transactional email and error tracking are not chosen yet, so this page says [provider] rather than naming a company we have not contracted with. We would rather publish an honest blank than a plausible name. Neither category is live today: no service email is being sent and no error data is leaving GROUPSPACE.

Current subprocessors

CategoryProviderPurposeProcessing location
Application hostingRailway Corp.Runs the GROUPSPACE web application, API and background jobs.United States — US East
Database and storageRailway Corp.The primary Postgres database, file storage, and encrypted backups. Chat history is held here, encrypted at rest and separate from the main tables.United States — US East
Payment processingStripe, Inc.Subscriptions, checkout, invoicing and the billing portal. Card details go to Stripe and never reach GROUPSPACE systems.United States
Transactional email[provider]Sign-in, notification and service emails. No marketing sends.[processing region]
Error tracking and monitoring[provider]Captures exceptions and performance data so faults can be diagnosed. May incidentally include a user or workspace id where an error was specific to one.[processing region]

That is the whole list. If a provider is not in this table, it does not receive personal data from GROUPSPACE.

What each one sees

Access is scoped to what the job needs. None of these providers gets a general copy of the product database.

CategoryPersonal data reaching it
Application hostingAll data in transit through the application, and data held in memory while a request is served.
Database and storageAll stored workspace and account data, including chat history where a workspace has enabled it.
Payment processingBilling contact details and the workspace identifier. No workspace content, no records, no chat, no game data.
Transactional emailRecipient email address, name, and the contents of the message being sent.
Error tracking and monitoringTechnical diagnostics: stack traces, request metadata, IP address, and identifiers attached to the failing request. Not chat, and not bulk record content.

Platforms are not subprocessors

Roblox, Discord and the other platforms GROUPSPACE connects to are not subprocessors. They are independent controllers of their own users’ data, and their own terms and privacy notices apply to what they do. GROUPSPACE exchanges data with them to make features work, on the instruction of the customer who set the connection up.

Who does not get data

  • No advertising or analytics networks. There is no ad system, no advertising pixel and no third-party analytics tag on the product. The cookie policy is short for this reason.
  • No data brokers. Data obtained through a platform API is not sold, licensed, traded or published as a dataset. This is a platform prohibition, not just our preference.
  • No AI or model training providers. Personal data flowing through GROUPSPACE is not sent to a model provider for training, and is not used to train a model of our own.
  • No enrichment or identity-resolution services. We do not join platform identities to outside datasets. Doing so would be cross-experience tracking.
  • No offshore support contractors with production access at present. If that changes, this page changes first.

Notice of changes

We give at least 30 days’ notice before adding or replacing a subprocessor that handles customer personal data.

  • Notice goes by email to workspace owners subscribed to the change list, and this page is updated with the new entry and the date it takes effect.
  • Where a change is urgent — a provider fails, or there is a security reason to move — we may act first and notify immediately. The objection right still runs from the notice.
  • Removing a subprocessor, or narrowing what one receives, does not need advance notice. The page is updated when it happens.
  • Filling in a [provider] placeholder with the name of a provider already in that role is a disclosure, not a change, and does not restart the notice period.

Objecting to a change

If you have a signed DPA you can object to a new subprocessor on reasonable data protection grounds within the notice period. Write to legal@groupspace.xyz and say what the concern is.

We will try to resolve it — a different provider, a different region, or a change to what that provider receives. If we cannot, you may terminate the affected part of the service and we will refund the unused portion of any prepaid fees.

Staying informed

Email legal@groupspace.xyz to be added to the subprocessor change list. Workspace owners on a paid plan are added by default; anyone else can ask.


Railway and Stripe are named and in use. Transactional email and error tracking are still open. Before this page is published as fact, each remaining category needs a named vendor, a signed data processing agreement with that vendor, and a confirmed processing region — and the Railway and Stripe DPAs need to be executed and filed.
2 of 5 vendors open Updated 10 August 2026

All legal documentsData processing addendumPrivacy policy