Subprocessors
Last updated: 31 July 2026 · Factual corrections: 1 August 2026
We engage the following subprocessors to deliver the Alethe AI agent platform. The list is updated whenever a subprocessor is added, removed, or changes country of processing.
Our standard, and where we stand against it. We require a Data Processing Agreement meeting Art. 28(3) GDPR to be in place with a subprocessor before it receives personal data from the platform. Data processing agreements are in place with subprocessors across this list, and we are working through the remainder. The status is published per subprocessor rather than as a single blanket claim: where a row is marked ⚠ DPA gap, no Art. 28 agreement is in place yet and that subprocessor is fenced to non-personal-data use until one is executed; where a row is marked ⚠ verify, we are confirming the position and apply the same fence in the meantime. This page reflects the position on the date shown above and is updated as each agreement is executed.
This list is referenced from our Privacy Policy and from our Data Processing Agreements (provided at onboarding; request at info@alethe.eu).
Core infrastructure (always engaged)
| Subprocessor | Service | Country of processing | Transfer safeguard | Link |
|---|---|---|---|---|
| Hostinger International Ltd. | VPS hosting (production app, database, Redis, Qdrant) | Germany — Frankfurt (EEA); provider-held whole-disk images additionally stored in Lithuania — Vilnius (EEA) | None needed (both EEA) | DPA |
| Stripe Payments Europe Ltd | Payment processing (subscriptions, credits, invoices) | Ireland (EEA) | None needed (EEA) | DPA |
| Stripe Inc. | Card-network routing + tax + fraud (downstream of Stripe Europe) | United States | 2021 SCCs as parallel fallback. (The DPF-certified Stripe entity on the US register is Stripe, LLC; we are reconciling which entity contracts with us before naming DPF here) | DPA |
AI model providers (engaged when AI features are used — i.e. effectively always)
| Subprocessor | Service | Country of processing | Transfer safeguard | Link |
|---|---|---|---|---|
| OpenRouter Inc. | LLM routing across multiple model providers; primary LLM gateway. A routing layer — it dispatches each request to an underlying model provider | United States | 2021 Standard Contractual Clauses (Module 2) + transfer impact assessment | DPA |
| OpenAI, L.L.C. | LLM inference (GPT family, embeddings) via direct API or OpenRouter | United States | 2021 Standard Contractual Clauses + transfer impact assessment; API-tier training opt-out applied | DPA |
| Anthropic, PBC | LLM inference (Claude family) | United States | 2021 Standard Contractual Clauses + transfer impact assessment | DPA |
| Google LLC | LLM inference (Gemini family) + OAuth identity (when end-user signs in with Google) | United States + EU regions | DPF + 2021 SCCs | DPA |
| Groq, Inc. | LLM inference (fast-tier, primarily open-weight models) + audio transcription (Whisper) — audio may carry personal data (voices, names) | United States | 2021 SCCs — ⚠ verify the transcription egress is DPA-covered | Privacy policy |
| fal.ai (Features and Labels, Inc.) | AI image and video generation (platform key, all tiers) — media prompts are an unmasked egress path | United States | 2021 SCCs — ⚠ DPA gap: fal's DPA incorporates the 2021 SCCs but engages only under a fal enterprise contract, which we do not hold. On self-serve terms fal acts as an independent controller, not our Art. 28 sub-processor. | Privacy policy |
| Google LLC — media endpoints (Imagen) | AI image generation, direct API (separate route from the Gemini LLM row above) | United States | DPF + 2021 SCCs — ⚠ scope of the Google Cloud DPA over these media endpoints to be confirmed | DPA |
| OpenAI, L.L.C. — image endpoints | AI image generation, direct API (gpt-image-1, dall-e-3) | United States | 2021 Standard Contractual Clauses + transfer impact assessment — covered by the same OpenAI API DPA as the row above | DPA |
| Black Forest Labs (FLUX) | AI image generation, direct API (api.bfl.ml) | ⚠ Unverified — operating entity and country not confirmed | ⚠ DPA gap — no Art. 28 DPA identified. No client personal data is to be routed here until entity, country and DPA are resolved. | ⚠ verify |
| Ideogram | AI image generation, direct API (api.ideogram.ai) | ⚠ Unverified — operating entity and country not confirmed | ⚠ DPA gap — same fence as Black Forest Labs | ⚠ verify |
| Third-party-hosted media models routed through fal (fal's "Partner API") — model families wired: ByteDance (Seedance / Seedream / OmniHuman), Kuaishou (Kling), MiniMax (Hailuo), Alibaba (Wan / Qwen-Image) | AI image and video generation where fal forwards the request to a third party that runs the model | ⚠ Unverified — operator not disclosed by the supplier. The developers named are China-based; that is not a statement that processing occurs in China, which is precisely what we cannot yet evidence. | ⚠ Not cleared — a transfer whose importer is unidentified cannot be assessed. Open question with the supplier. | ⚠ verify |
Search and research tools (engaged when customer agents invoke them)
| Subprocessor | Service | Country of processing | Transfer safeguard | Link |
|---|---|---|---|---|
| Brave Search API (Brave Software, Inc.) | Web search results | United States | 2021 SCCs | Privacy policy |
| Serper.dev | Google shopping-search API (not a Brave fallback — Brave is the web-search primary) | United States (entity undisclosed) | 2021 SCCs — ⚠ DPA gap: no Art. 28 DPA, no subprocessor list, no DPF. Slated for replacement. | Privacy policy |
| Apify Technologies s.r.o. | Web-scraping actors for research + Instagram / X / web lookups (LinkedIn scraper disabled 19 June 2026) | Czech Republic (EEA) | None needed (EEA) | DPA |
| Jina AI (Reader API) | Web-scrape / page-read — primary scrape path; receives target URLs and scraped page content, which may include personal data | ⚠ verify entity + country | ⚠ DPA gap — Art. 28 DPA and transfer safeguard to be verified before client PII | jina.ai |
| Zyte | Web-scrape (JS-render escalation) — receives target URLs and scraped page content | ⚠ verify (believed Ireland / EEA) | ⚠ verify DPA executed | zyte.com |
| Linkup | Web-search (fallback path) | ⚠ verify entity + country | ⚠ DPA gap — Art. 28 DPA and safeguard to be verified | ⚠ verify |
| Perplexity AI, Inc. (Sonar API) | AI web-search / deep research (direct platform key and via OpenRouter) | United States | 2021 SCCs — Sonar API is zero-retention and no-train, DPA auto-incorporated in the API terms; ⚠ EU residency / DPF unconfirmed | DPA |
| YouTube (Google LLC, via yt-dlp) | Public video metadata and transcript fetch (channel monitoring / transcription) — public data, low PII | United States | DPF + 2021 SCCs | DPA |
Code execution (engaged only when an agent runs code)
| Subprocessor | Service | Country of processing | Transfer safeguard | Link |
|---|---|---|---|---|
| E2B | Sandboxed Python / code execution — data passed into the executed code may include personal data | United States (⚠ verify entity) | ⚠ DPA gap — Art. 28 DPA + 2021 SCCs to be verified before any client PII | e2b.dev |
Contact-data providers (engaged only when contact lookup is invoked)
| Subprocessor | Service | Country of processing | Transfer safeguard | Link |
|---|---|---|---|---|
| Apollo.io | B2B contact database | United States | DPF + 2021 SCCs | DPA |
| Hunter.io (Hunter Web Services, Inc.) | Business email lookup | United States (servers in Belgium) | 2021 SCCs | DPA |
Integration providers (engaged only when the customer enables the integration)
These process Customer Content only on the customer's explicit configuration (e.g. enabling a Meta Ads campaign module). Listed for transparency.
| Subprocessor | Service | Country of processing | Transfer safeguard | Link |
|---|---|---|---|---|
| Meta Platforms, Inc. | Facebook / Instagram / Threads — ads + social publishing APIs | United States + Ireland (Meta Platforms Ireland Ltd.) | DPF (EU–US and Swiss only — Meta holds no UK Extension) + 2021 SCCs | DPA |
| Shopify Inc. | E-commerce platform — products, orders, customers (when customer connects their Shopify store) | Canada (adequacy) | None needed (adequacy decision) | DPA |
| Slack Technologies, LLC (Salesforce, Inc.) | Workspace messaging / bots | United States | DPF (covered under Salesforce, Inc.'s certification, not its own) + 2021 SCCs | DPA |
| Google Workspace (Google LLC) | Docs / Sheets / Drive / Gmail integrations | United States + EU regions | DPF + 2021 SCCs | DPA |
| AliExpress (Alibaba group) | Dropship product-catalog lookups (Shopify tools) — product data, generally no personal data | Singapore / China (⚠ verify entity) | ⚠ verify — confirm no personal-data egress and the transfer safeguard | ⚠ verify |
Observability and analytics
| Subprocessor | Service | Country of processing | Transfer safeguard | Link |
|---|---|---|---|---|
| Self-hosted, Sentry-protocol-compatible endpoint (running on our Hostinger VPS) | Error and crash reporting | Germany — Frankfurt (EEA, same VPS as production) | None needed (same controller infrastructure — not a third-party subprocessor) | N/A |
| Sentry SDK (client library only — no data sent to Sentry SaaS) | Error capture library configured to point at our own self-hosted endpoint | N/A | N/A | N/A |
| Telegram (Telegram FZ-LLC) | Internal ops-alert delivery — a superadmin-configured bot posts error / regression notifications to Alethe's own ops chat. Not used to process Customer Content in the ordinary course; error text is masked and truncated before egress but may incidentally carry fragments of personal data present in diagnostics. Engaged only when a superadmin enables it. | United Arab Emirates (Dubai) / distributed | 2021 SCCs — ⚠ DPA gap: no Art. 28 DPA in place; the masking guardrail and no-PII fence stand until one is obtained. | Privacy policy |
| Google LLC (Google Analytics 4 — marketing site alethe.eu only, consent-gated) | Marketing-site usage analytics (IP anonymisation on; loaded only after Analytics consent) | United States | DPF + 2021 SCCs | Processor terms |
| Meta Platforms Ireland Ltd. (Meta Pixel — marketing site only, consent-gated; joint controller for pixel collection per CJEU C-40/17 Fashion ID, not a processor — listed for transparency) | Advertising measurement / audiences via Meta Pixel (loaded only after Marketing consent) | Ireland / US | DPF (EU–US and Swiss only — Meta holds no UK Extension) + SCCs | DPA |
Email (transactional and marketing)
Transactional and marketing email providers will be added to this list before first use, with 30 days' notice to customers.
Notification of changes
Material changes (new subprocessor added; existing subprocessor changes country of processing; sub-processor decommissioned) are notified at least 30 days before taking effect, via:
- Update to this published list
- Email to active business customers' designated data-protection contact
In-product notification to organisation administrators is intended but not yet built; we do not list it as an operating channel until it is.
B2B customers have the right to object on reasonable data-protection grounds — the objection mechanism is set out in the DPA (provided at onboarding; request at info@alethe.eu).
Sub-subprocessors
Each subprocessor above may engage its own sub-processors (chip vendors, hosting providers, content-delivery networks). We require all subprocessors to disclose theirs in their respective DPAs and to flow the same Art. 28(3) protections to their sub-processors.
One place where that requirement is visibly unsatisfied. Our media supplier publishes a sub-processor list of 14 companies, none of which is an AI model provider, while publicly attributing model families to ByteDance, Kuaishou and others. Both cannot be complete. Either the supplier serves those weights on infrastructure it controls, or a separate company operates them and must be named. We have asked and do not yet have the answer, and we will not guess at it here.
Audit and TOM evidence
For customers under the inbound DPA, evidence of subprocessor security posture (SOC 2 reports, ISO 27001 certificates, recent pen-test summaries) is available on request to info@alethe.eu, subject to NDA where the subprocessor requires it.