Subprocessors and Service Providers
Effective date: August 24, 2026
This page explains which third parties PacketSafari uses, what they do, and whether they are part of the managed SaaS data path, a website or business operation, or a customer-controlled deployment.
PacketSafari is operated by Ripka Technologies S.L.
- Address: Calle Peris Brell 7 Trip Bajo, 46022 Valencia, Spain
- Email: contact@packetsafari.com
1. How to Read This List
A subprocessor processes personal data on our behalf while we provide a service to a customer. Other providers may instead have a direct or separate relationship with the individual, for example as a payment provider or a user-selected identity provider. We list both categories for transparency, but their legal roles are not necessarily the same.
The vendors used by managed SaaS are different from those used only for our public website, sales, or internal business operations. Customer-managed and on-premises deployments can use a different, usually smaller, vendor set.
2. Managed SaaS Subprocessors
These providers may process personal data to operate PacketSafari's shared or managed SaaS services.
| Provider | Purpose and data involved | When it applies |
|---|---|---|
| Amazon Web Services (AWS) | Managed-SaaS compute, storage, deployment artifacts, service logs, backups, application delivery through Amazon S3 and CloudFront, and outbound transactional email through AWS SES. Depending on the feature, this can include account data, uploaded captures, derived analysis data, request metadata, and email delivery data. | Managed SaaS |
| OpenAI | PacketSafari's primary hosted AI provider for Copilot, Agent, reports, visual AI, and other core AI features. Requests contain prompts and the selected packet evidence or analysis context needed for the requested feature, rather than an automatic transfer of every capture. | Default managed-SaaS AI route and OpenAI-specific features; only when hosted cloud AI is enabled |
| OpenRouter and the selected model provider | Gateway for qualified third-party hosted models. OpenRouter receives the prompts, selected packet evidence or analysis context, and generated outputs needed for the requested AI feature and routes them to the selected underlying model provider. Both OpenRouter and that provider may process the request under the applicable route's data policy. | Only when an administrator or customer selects an approved OpenRouter-backed model route |
| PostHog | Product analytics, evaluation and conversion measurement, and error diagnostics. Events can include account or contact details, feature and page usage, device or request metadata, and evaluation-upload metadata such as filename, description, type, and size. Packet-capture contents are not part of the normal analytics event path. | Shared SaaS; browser analytics are consent-gated, while limited service events may be sent to our EU PostHog project to operate and measure requested SaaS flows |
| Google Analytics | Product usage analytics for app.packetsafari.com. With analytics consent, Google Analytics can receive application routes, interaction events, browser and device data, IP-derived network or location data, and related usage metadata. Packet-capture contents are not intentionally included in analytics events. | Managed-SaaS frontend; enabled only after analytics consent |
| Slack | Internal service operations, customer communications, and support collaboration. Slack may contain contact or account details, support messages, and operational diagnostics deliberately shared with the PacketSafari team. It is not used to host or analyze packet captures as part of the core application data path. | Managed SaaS support and operations |
3. Website, Communications, and Commercial Services
These providers support the public website, communications, or commercial relationship. They do not host or analyze packet captures as part of the core PacketSafari SaaS data path.
| Provider | Purpose and data involved | Relationship |
|---|---|---|
| Cloudflare | Static hosting, content delivery, TLS termination, availability, and security for www.packetsafari.com. Cloudflare can process visitor IP addresses, request URLs and headers, browser or device metadata, and delivery or security logs. It is not part of the managed-SaaS capture-processing path. | Public-website infrastructure processor |
| hosting.de | Mailbox infrastructure for the packetsafari.com domain, including messages and attachments sent to PacketSafari email addresses. | Communications service provider |
| Paddle | Checkout, payment processing, subscriptions, tax, fraud prevention, and billing-related account activation. Paddle acts as merchant of record for purchases and also processes data needed to provide its services. | Payment and billing provider with its own buyer terms and privacy notice |
| Google Analytics | Public-website traffic and interaction analytics for www.packetsafari.com. With analytics consent, Google Analytics can receive page routes, interaction events, browser and device data, IP-derived network or location data, and related usage metadata. | Public-website analytics processor; enabled only after analytics consent |
| PostHog | Public-website analytics and conversion measurement, including page, device, and interaction data. | Processor; browser tracking is enabled only after analytics consent |
| lemlist | Consent-gated website visitor tracking and sales outreach, including visitor, contact, company, and campaign-interaction data where available. | Sales and marketing processor; website tracking is enabled only after analytics consent |
4. Optional or Customer-Controlled Providers
These services are used only when a feature or deployment is configured to use them.
| Provider | Purpose and data involved | Control |
|---|---|---|
| Customer-configured OpenAI-compatible provider | AI inference at an endpoint selected by the customer or on-premises operator. The selected endpoint receives the prompts and bounded packet evidence or analysis context required for the requested AI feature. | Customer-controlled |
| Customer-configured SAML or OIDC identity provider | Enterprise authentication using identifiers and identity claims supplied by the customer's configured provider. | Customer-controlled |
| Customer-configured SMTP provider | Outbound email instead of PacketSafari's managed AWS SES path, including recipient, message, and delivery metadata. | Customer-controlled |
| Google Certificate Transparency services | Downloads signed public CT catalogs and, when certificate proof verification is requested, queries supported Google CT logs using a certificate leaf hash derived from the analyzed TLS certificate. PacketSafari does not send the capture file. | Feature-optional public certificate verification |
5. Public Data Sources That Do Not Receive Customer Content
PacketSafari can download public security rules and intelligence catalogs from the Open Information Security Foundation, abuse.ch SSLBL and URLhaus, Emerging Threats Open, Spamhaus DROP, and Stamus Networks. These sources receive normal download request metadata from PacketSafari infrastructure, but not customer captures, extracted indicators, account data, or analysis results, so they are not listed as subprocessors.
6. Deployment Boundaries
- Shared and managed SaaS use PacketSafari-selected infrastructure and operational providers.
- A dedicated SaaS agreement may narrow or further specify the approved provider, region, AI route, retention, and support boundary.
- In a customer-managed or on-premises deployment, the customer controls its infrastructure, identity, mail, and configured AI providers. Those customer-selected services are not PacketSafari-selected subprocessors merely because PacketSafari can connect to them.
- A provider can have more than one role. For example, PostHog supports both the public website and the shared SaaS product, while Slack supports SaaS operations without being part of the capture-processing path.
We update this page when our active vendor set or a material processing purpose changes. Contract-specific notice and approval terms, if any, are governed by the applicable customer agreement or data processing addendum.
For broader information about personal data, legal bases, transfers, and individual rights, see our Privacy Policy.
