Controller: MultivoHub Limited (company no. 17236540), 340 Poplars Avenue
Warrington
WA2 9UF
United Kingdom.
Contact: support@multivohub.com.
Last updated: 26 June 2026.
This page lists third-party service providers, processors and subprocessors that may process personal data or customer-related data in connection with Harmonia Repo Ready.
The providers that actually receive Customer Content depend on the product mode, customer configuration, active licence, enabled integrations and active API keys. Local CLI mode is designed to run offline and does not intentionally send source code to MultivoHub Limited or AI providers.
1. Core infrastructure and platform providers
| Provider | Purpose | Data categories | Status | Notes |
|---|---|---|---|---|
| Hostinger | VPS hosting, server infrastructure, website/API hosting, server logs, email/SMTP where enabled | Account data, technical logs, IP addresses, API metadata, service data, email metadata | Confirmed | Exact Hostinger contracting entity, data-centre region, backup settings and DPA to be confirmed from the Hostinger account/invoice. |
| GitHub, Inc. | Repository hosting integration, public GitHub API, GitHub Action workflows, PR comments, job summaries, status checks, optional SARIF/code scanning | Repository URL, public repository metadata, workflow metadata, reports, PR comments, SARIF findings where enabled | Confirmed | Customer-selected integration. The GitHub Action runs in the customer's runner environment. |
| Stripe | Card payments, checkout, subscriptions, invoices, credits, one-off audit payments | Customer contact details, billing details, payment metadata, subscription status, invoice records | Confirmed (payment flow) | Exact Stripe contracting entity to confirm in the Stripe dashboard. |
| PayPal | Alternative payment method | Customer contact details, PayPal payment metadata, transaction records | Confirmed (payment flow) | PayPal may act as an independent controller for some payment processing. |
| Revolut | Alternative payment / business payment processing | Customer contact details, payment metadata, transaction records | Confirmed (payment flow) | Exact Revolut contracting entity to confirm. |
| OpenRouter, Inc. | AI routing / OpenAI-compatible model gateway where enabled | Prompts, README excerpts, audit facts, findings, AI outputs, request metadata | Supported — active only if configured | May route data to downstream model providers. Downstream providers must be pinned or disclosed. |
| OpenAI, L.L.C. | AI semantic analysis / repair suggestions where enabled | Prompts, README excerpts, audit facts, findings, AI outputs, request metadata | Supported — active only if configured | Confirm training/data-use settings before production use. |
| Anthropic, PBC | AI semantic analysis / repair suggestions where enabled | Prompts, README excerpts, audit facts, findings, AI outputs, request metadata | Supported — active only if configured | Confirm DPA and retention settings. |
| Google LLC (Gemini) | AI semantic analysis / repair suggestions where enabled | Prompts, README excerpts, audit facts, findings, AI outputs, request metadata | Supported — active only if configured | Confirm Google contracting entity and data-use terms (paid tier / Vertex AI). |
| Groq, Inc. | AI inference where enabled | Prompts, README excerpts, audit facts, findings, AI outputs, request metadata | Supported — active only if configured | Confirm DPA, region and retention. |
| xAI Corp. | AI inference where enabled | Prompts, README excerpts, audit facts, findings, AI outputs, request metadata | Supported — active only if configured | Confirm DPA, region and retention before production use. |
| Mistral AI SAS | AI inference where enabled | Prompts, README excerpts, audit facts, findings, AI outputs, request metadata | Supported — active only if configured | EU provider, but contract/DPA still required. |
| Cohere Inc. | AI inference where enabled | Prompts, README excerpts, audit facts, findings, AI outputs, request metadata | Supported — active only if configured | Confirm DPA, region and retention. |
| Perplexity AI, Inc. | AI / search-style analysis where enabled | Prompts, README excerpts, audit facts, findings, AI outputs, request metadata | Supported — active only if configured | Do not send private code or secrets unless separately approved. |
| DeepSeek | AI inference where enabled | Prompts, README excerpts, audit facts, findings, AI outputs, request metadata | Supported — high-risk transfer | Do not enable for UK/EU Customer Content until a transfer-risk assessment, DPA and safeguards are approved. |
Llama-family models are a model family, not a separate subprocessor. They may be accessed through an OpenAI-compatible host such as OpenRouter or another configured model host. In that case the configured host — not Meta — is the data recipient.
2. Internal / self-hosted components
| Component | Purpose | Subprocessor status | Notes |
|---|---|---|---|
| PostgreSQL | Production database where self-hosted on MultivoHub infrastructure | Not an external subprocessor if self-hosted | Still covered by security, backup and retention controls. |
| SQLite | Local / dev / demo database | Not an external subprocessor | Not for production Customer Content unless intentionally configured. |
| HashiCorp Vault | Secret storage where self-hosted | Not an external subprocessor if self-hosted | If using HashiCorp Cloud instead, add HashiCorp as a provider. |
| Harmonia API / MultivoHub infrastructure | Layer 2 semantic QC, licence checks, verified-repair workflow | Internal processing unless hosted by a third party | The hosting provider must be disclosed separately. |
3. Local tools not treated as subprocessors
| Tool | Purpose | Why not listed as a subprocessor |
|---|---|---|
| Gitleaks | Optional local deep secret scanning | Runs locally if the customer installs/uses it; data is not sent to MultivoHub merely by using the CLI. |
| TruffleHog | Optional local deep secret scanning | Runs locally if the customer installs/uses it; data is not sent to MultivoHub merely by using the CLI. |
| pipx / setuptools / Python packaging tools | Installation / build tooling | Not service providers processing customer repository content for MultivoHub. |
| actions/setup-python | GitHub Action dependency | Part of the GitHub Action runner workflow; disclosed under GitHub / GitHub Actions rather than as a separate customer-data subprocessor. |
4. Providers not currently used
The following categories are not currently confirmed as external subprocessors:
- third-party analytics provider;
- cookie-consent management provider;
- support / ticketing provider;
- external log-monitoring provider;
- managed backup / storage provider.
If any of these are added, this page will be updated before, or when, they begin processing personal data.
5. Contractual basis
Where a processor uses a subprocessor, an Article 28 UK GDPR contract imposing equivalent data-protection obligations is required. This page alone is not sufficient — an executed DPA, contract or accepted data-processing terms is required with each active provider before it processes personal data in production.