Sub-processors

We use trusted third-party subprocessors for hosting, payments, analytics, and customer support. Each provider meets high security and compliance standards.

Last updated: 02/17/2025 

Name: Google Cloud Platform
Address: The physical location for processing used is within the EU.
Contact person’s name, position and contact details: Google’s Cloud Data Protection Team can be contacted at https://support.google.com/cloud/contact/dpo 

Description of the processing (including a clear delimitation of responsibilities in case several sub-processors are authorised): Cloud service provider providing PaaS-services and technically providing the web interface for the service.

Personal data
- User full name, email address and potentially phone number is stored at rest when authenticating with the application
- Client database credentials including name are stored at rest with Google Secrets Manager. The contents and nature of data within the database varies between clients.

Name: Microsoft Azure
Address: The physical location for processing used is within the EU.
Contact person’s name, position and contact details: Microsofts Data Protection Team can be contacted  at https://aka.ms/privacyresponse

Description of the processing (including a clear delimitation of responsibilities in case several sub-processors are authorised): Microsoft Azure is hosting the Large Language Model that is used by the processor to convert end user questions and metadata into SQL-queries.

Personal data
- Questions made in the application are sent to large language models (LLMs) and can contain references to personal data that are logged by Microsoft Azure for tracing purposes.

Name: AWS (Amazon Web Services)
Address: The physical location for processing used is within the EU.
Contact person’s name, position and contact details: AWS Data Protection Team can be contacted  at https://docs.aws.amazon.com/whitepapers/latest/navigating-gdpr-compliance/aws-data-processing-addendum-dpa.html

Description of the processing (including a clear delimitation of responsibilities in case several sub-processors are authorised): AWS is hosting the backend API and background worker components of the application. LLMs produced by Anthropic and hosted via AWS may also be used to improve the answers provided by the application.

Personal data
- User full name, email address and potentially phone number is stored at rest when authenticating with the application.
- Client database credentials including name are stored at rest with AWS Secrets Manager. The contents and nature of data within the database varies between clients.

Name: Datadog
Address: The physical location for processing used is within the EU.
Contact person’s name, position and contact details: Datadog’s Data Protection Team can be contacted at https://www.datadoghq.com/legal/data-processing-addendum/#modifications

Description of the processing (including a clear delimitation of responsibilities in case several sub-processors are authorised): A monitoring and observability tool to ensure the application is in good working order.

Personal data
- Data flowing from the application to Datadog can inadvertently contain personal data such as that included in HTTP requests. Use of Datadog’s Log Obfuscation shall be employed to minimize the likelihood of this.

Name: Sentry
Address: The physical location for processing used is within the EU.
Contact person’s name, position and contact details: Sentry’s Data Protection Team can be contacted at https://sentry.io/legal/dpa/

Description of the processing (including a clear delimitation of responsibilities in case several sub-processors are authorised): A monitoring and observability tool to ensure the application is in good working order.

Personal data
- Data flowing from the application to Sentry can inadvertently contain personal data such as that included in HTTP requests. Server-side Scrubbing of Data shall be employed in order to minimize this.

(In addition to these services, the processor also relies on sub-processors GitLab and Google Workspaces. However, these services are not used as a part of provisioning this service)