Harmonia Repo Ready
Terms Privacy Cookies Security
Legal

Subprocessors

Providers, including AI model providers, that may process data for Harmonia Repo Ready.

← Back to site Company Details Terms and Conditions Privacy Policy Cookie Policy Acceptable Use Policy AI & Data Processing Notice Security Policy Refunds and Cancellation Subprocessors Disclaimer
Questions about this document? Contact support@multivohub.com.

Controller: MultivoHub Limited (company no. 17236540), 340 Poplars Avenue
Warrington
WA2 9UF
United Kingdom.

Contact: support@multivohub.com.

Last updated: 26 June 2026.

This page lists third-party service providers, processors and subprocessors that may process personal data or customer-related data in connection with Harmonia Repo Ready.

The providers that actually receive Customer Content depend on the product mode, customer configuration, active licence, enabled integrations and active API keys. Local CLI mode is designed to run offline and does not intentionally send source code to MultivoHub Limited or AI providers.

1. Core infrastructure and platform providers

ProviderPurposeData categoriesStatusNotes
HostingerVPS hosting, server infrastructure, website/API hosting, server logs, email/SMTP where enabledAccount data, technical logs, IP addresses, API metadata, service data, email metadataConfirmedExact Hostinger contracting entity, data-centre region, backup settings and DPA to be confirmed from the Hostinger account/invoice.
GitHub, Inc.Repository hosting integration, public GitHub API, GitHub Action workflows, PR comments, job summaries, status checks, optional SARIF/code scanningRepository URL, public repository metadata, workflow metadata, reports, PR comments, SARIF findings where enabledConfirmedCustomer-selected integration. The GitHub Action runs in the customer's runner environment.
StripeCard payments, checkout, subscriptions, invoices, credits, one-off audit paymentsCustomer contact details, billing details, payment metadata, subscription status, invoice recordsConfirmed (payment flow)Exact Stripe contracting entity to confirm in the Stripe dashboard.
PayPalAlternative payment methodCustomer contact details, PayPal payment metadata, transaction recordsConfirmed (payment flow)PayPal may act as an independent controller for some payment processing.
RevolutAlternative payment / business payment processingCustomer contact details, payment metadata, transaction recordsConfirmed (payment flow)Exact Revolut contracting entity to confirm.
OpenRouter, Inc.AI routing / OpenAI-compatible model gateway where enabledPrompts, README excerpts, audit facts, findings, AI outputs, request metadataSupported — active only if configuredMay route data to downstream model providers. Downstream providers must be pinned or disclosed.
OpenAI, L.L.C.AI semantic analysis / repair suggestions where enabledPrompts, README excerpts, audit facts, findings, AI outputs, request metadataSupported — active only if configuredConfirm training/data-use settings before production use.
Anthropic, PBCAI semantic analysis / repair suggestions where enabledPrompts, README excerpts, audit facts, findings, AI outputs, request metadataSupported — active only if configuredConfirm DPA and retention settings.
Google LLC (Gemini)AI semantic analysis / repair suggestions where enabledPrompts, README excerpts, audit facts, findings, AI outputs, request metadataSupported — active only if configuredConfirm Google contracting entity and data-use terms (paid tier / Vertex AI).
Groq, Inc.AI inference where enabledPrompts, README excerpts, audit facts, findings, AI outputs, request metadataSupported — active only if configuredConfirm DPA, region and retention.
xAI Corp.AI inference where enabledPrompts, README excerpts, audit facts, findings, AI outputs, request metadataSupported — active only if configuredConfirm DPA, region and retention before production use.
Mistral AI SASAI inference where enabledPrompts, README excerpts, audit facts, findings, AI outputs, request metadataSupported — active only if configuredEU provider, but contract/DPA still required.
Cohere Inc.AI inference where enabledPrompts, README excerpts, audit facts, findings, AI outputs, request metadataSupported — active only if configuredConfirm DPA, region and retention.
Perplexity AI, Inc.AI / search-style analysis where enabledPrompts, README excerpts, audit facts, findings, AI outputs, request metadataSupported — active only if configuredDo not send private code or secrets unless separately approved.
DeepSeekAI inference where enabledPrompts, README excerpts, audit facts, findings, AI outputs, request metadataSupported — high-risk transferDo not enable for UK/EU Customer Content until a transfer-risk assessment, DPA and safeguards are approved.

Llama-family models are a model family, not a separate subprocessor. They may be accessed through an OpenAI-compatible host such as OpenRouter or another configured model host. In that case the configured host — not Meta — is the data recipient.

2. Internal / self-hosted components

ComponentPurposeSubprocessor statusNotes
PostgreSQLProduction database where self-hosted on MultivoHub infrastructureNot an external subprocessor if self-hostedStill covered by security, backup and retention controls.
SQLiteLocal / dev / demo databaseNot an external subprocessorNot for production Customer Content unless intentionally configured.
HashiCorp VaultSecret storage where self-hostedNot an external subprocessor if self-hostedIf using HashiCorp Cloud instead, add HashiCorp as a provider.
Harmonia API / MultivoHub infrastructureLayer 2 semantic QC, licence checks, verified-repair workflowInternal processing unless hosted by a third partyThe hosting provider must be disclosed separately.

3. Local tools not treated as subprocessors

ToolPurposeWhy not listed as a subprocessor
GitleaksOptional local deep secret scanningRuns locally if the customer installs/uses it; data is not sent to MultivoHub merely by using the CLI.
TruffleHogOptional local deep secret scanningRuns locally if the customer installs/uses it; data is not sent to MultivoHub merely by using the CLI.
pipx / setuptools / Python packaging toolsInstallation / build toolingNot service providers processing customer repository content for MultivoHub.
actions/setup-pythonGitHub Action dependencyPart of the GitHub Action runner workflow; disclosed under GitHub / GitHub Actions rather than as a separate customer-data subprocessor.

4. Providers not currently used

The following categories are not currently confirmed as external subprocessors:

  • third-party analytics provider;
  • cookie-consent management provider;
  • support / ticketing provider;
  • external log-monitoring provider;
  • managed backup / storage provider.

If any of these are added, this page will be updated before, or when, they begin processing personal data.

5. Contractual basis

Where a processor uses a subprocessor, an Article 28 UK GDPR contract imposing equivalent data-protection obligations is required. This page alone is not sufficient — an executed DPA, contract or accepted data-processing terms is required with each active provider before it processes personal data in production.

© MultivoHub Limited
Terms Privacy Cookies Acceptable Use