Subprocessors

Last updated: 31 July 2026 · Factual corrections: 1 August 2026

We engage the following subprocessors to deliver the Alethe AI agent platform. The list is updated whenever a subprocessor is added, removed, or changes country of processing.

Our standard, and where we stand against it. We require a Data Processing Agreement meeting Art. 28(3) GDPR to be in place with a subprocessor before it receives personal data from the platform. Data processing agreements are in place with subprocessors across this list, and we are working through the remainder. The status is published per subprocessor rather than as a single blanket claim: where a row is marked ⚠ DPA gap, no Art. 28 agreement is in place yet and that subprocessor is fenced to non-personal-data use until one is executed; where a row is marked ⚠ verify, we are confirming the position and apply the same fence in the meantime. This page reflects the position on the date shown above and is updated as each agreement is executed.

This list is referenced from our Privacy Policy and from our Data Processing Agreements (provided at onboarding; request at info@alethe.eu).

Core infrastructure (always engaged)

SubprocessorServiceCountry of processingTransfer safeguardLink
Hostinger International Ltd.VPS hosting (production app, database, Redis, Qdrant)Germany — Frankfurt (EEA); provider-held whole-disk images additionally stored in Lithuania — Vilnius (EEA)None needed (both EEA)DPA
Stripe Payments Europe LtdPayment processing (subscriptions, credits, invoices)Ireland (EEA)None needed (EEA)DPA
Stripe Inc.Card-network routing + tax + fraud (downstream of Stripe Europe)United States2021 SCCs as parallel fallback. (The DPF-certified Stripe entity on the US register is Stripe, LLC; we are reconciling which entity contracts with us before naming DPF here)DPA

AI model providers (engaged when AI features are used — i.e. effectively always)

SubprocessorServiceCountry of processingTransfer safeguardLink
OpenRouter Inc.LLM routing across multiple model providers; primary LLM gateway. A routing layer — it dispatches each request to an underlying model providerUnited States2021 Standard Contractual Clauses (Module 2) + transfer impact assessmentDPA
OpenAI, L.L.C.LLM inference (GPT family, embeddings) via direct API or OpenRouterUnited States2021 Standard Contractual Clauses + transfer impact assessment; API-tier training opt-out appliedDPA
Anthropic, PBCLLM inference (Claude family)United States2021 Standard Contractual Clauses + transfer impact assessmentDPA
Google LLCLLM inference (Gemini family) + OAuth identity (when end-user signs in with Google)United States + EU regionsDPF + 2021 SCCsDPA
Groq, Inc.LLM inference (fast-tier, primarily open-weight models) + audio transcription (Whisper) — audio may carry personal data (voices, names)United States2021 SCCs — ⚠ verify the transcription egress is DPA-coveredPrivacy policy
fal.ai (Features and Labels, Inc.)AI image and video generation (platform key, all tiers) — media prompts are an unmasked egress pathUnited States2021 SCCs — ⚠ DPA gap: fal's DPA incorporates the 2021 SCCs but engages only under a fal enterprise contract, which we do not hold. On self-serve terms fal acts as an independent controller, not our Art. 28 sub-processor.Privacy policy
Google LLCmedia endpoints (Imagen)AI image generation, direct API (separate route from the Gemini LLM row above)United StatesDPF + 2021 SCCs — ⚠ scope of the Google Cloud DPA over these media endpoints to be confirmedDPA
OpenAI, L.L.C.image endpointsAI image generation, direct API (gpt-image-1, dall-e-3)United States2021 Standard Contractual Clauses + transfer impact assessment — covered by the same OpenAI API DPA as the row aboveDPA
Black Forest Labs (FLUX)AI image generation, direct API (api.bfl.ml)Unverified — operating entity and country not confirmedDPA gap — no Art. 28 DPA identified. No client personal data is to be routed here until entity, country and DPA are resolved.⚠ verify
IdeogramAI image generation, direct API (api.ideogram.ai)Unverified — operating entity and country not confirmedDPA gap — same fence as Black Forest Labs⚠ verify
Third-party-hosted media models routed through fal (fal's "Partner API") — model families wired: ByteDance (Seedance / Seedream / OmniHuman), Kuaishou (Kling), MiniMax (Hailuo), Alibaba (Wan / Qwen-Image)AI image and video generation where fal forwards the request to a third party that runs the modelUnverified — operator not disclosed by the supplier. The developers named are China-based; that is not a statement that processing occurs in China, which is precisely what we cannot yet evidence.Not cleared — a transfer whose importer is unidentified cannot be assessed. Open question with the supplier.⚠ verify

Search and research tools (engaged when customer agents invoke them)

SubprocessorServiceCountry of processingTransfer safeguardLink
Brave Search API (Brave Software, Inc.)Web search resultsUnited States2021 SCCsPrivacy policy
Serper.devGoogle shopping-search API (not a Brave fallback — Brave is the web-search primary)United States (entity undisclosed)2021 SCCs — ⚠ DPA gap: no Art. 28 DPA, no subprocessor list, no DPF. Slated for replacement.Privacy policy
Apify Technologies s.r.o.Web-scraping actors for research + Instagram / X / web lookups (LinkedIn scraper disabled 19 June 2026)Czech Republic (EEA)None needed (EEA)DPA
Jina AI (Reader API)Web-scrape / page-read — primary scrape path; receives target URLs and scraped page content, which may include personal data⚠ verify entity + countryDPA gap — Art. 28 DPA and transfer safeguard to be verified before client PIIjina.ai
ZyteWeb-scrape (JS-render escalation) — receives target URLs and scraped page content⚠ verify (believed Ireland / EEA)⚠ verify DPA executedzyte.com
LinkupWeb-search (fallback path)⚠ verify entity + countryDPA gap — Art. 28 DPA and safeguard to be verified⚠ verify
Perplexity AI, Inc. (Sonar API)AI web-search / deep research (direct platform key and via OpenRouter)United States2021 SCCs — Sonar API is zero-retention and no-train, DPA auto-incorporated in the API terms; ⚠ EU residency / DPF unconfirmedDPA
YouTube (Google LLC, via yt-dlp)Public video metadata and transcript fetch (channel monitoring / transcription) — public data, low PIIUnited StatesDPF + 2021 SCCsDPA

Code execution (engaged only when an agent runs code)

SubprocessorServiceCountry of processingTransfer safeguardLink
E2BSandboxed Python / code execution — data passed into the executed code may include personal dataUnited States (⚠ verify entity)DPA gap — Art. 28 DPA + 2021 SCCs to be verified before any client PIIe2b.dev

Contact-data providers (engaged only when contact lookup is invoked)

SubprocessorServiceCountry of processingTransfer safeguardLink
Apollo.ioB2B contact databaseUnited StatesDPF + 2021 SCCsDPA
Hunter.io (Hunter Web Services, Inc.)Business email lookupUnited States (servers in Belgium)2021 SCCsDPA

Integration providers (engaged only when the customer enables the integration)

These process Customer Content only on the customer's explicit configuration (e.g. enabling a Meta Ads campaign module). Listed for transparency.

SubprocessorServiceCountry of processingTransfer safeguardLink
Meta Platforms, Inc.Facebook / Instagram / Threads — ads + social publishing APIsUnited States + Ireland (Meta Platforms Ireland Ltd.)DPF (EU–US and Swiss only — Meta holds no UK Extension) + 2021 SCCsDPA
Shopify Inc.E-commerce platform — products, orders, customers (when customer connects their Shopify store)Canada (adequacy)None needed (adequacy decision)DPA
Slack Technologies, LLC (Salesforce, Inc.)Workspace messaging / botsUnited StatesDPF (covered under Salesforce, Inc.'s certification, not its own) + 2021 SCCsDPA
Google Workspace (Google LLC)Docs / Sheets / Drive / Gmail integrationsUnited States + EU regionsDPF + 2021 SCCsDPA
AliExpress (Alibaba group)Dropship product-catalog lookups (Shopify tools) — product data, generally no personal dataSingapore / China (⚠ verify entity)⚠ verify — confirm no personal-data egress and the transfer safeguard⚠ verify

Observability and analytics

SubprocessorServiceCountry of processingTransfer safeguardLink
Self-hosted, Sentry-protocol-compatible endpoint (running on our Hostinger VPS)Error and crash reportingGermany — Frankfurt (EEA, same VPS as production)None needed (same controller infrastructure — not a third-party subprocessor)N/A
Sentry SDK (client library only — no data sent to Sentry SaaS)Error capture library configured to point at our own self-hosted endpointN/AN/AN/A
Telegram (Telegram FZ-LLC)Internal ops-alert delivery — a superadmin-configured bot posts error / regression notifications to Alethe's own ops chat. Not used to process Customer Content in the ordinary course; error text is masked and truncated before egress but may incidentally carry fragments of personal data present in diagnostics. Engaged only when a superadmin enables it.United Arab Emirates (Dubai) / distributed2021 SCCs — ⚠ DPA gap: no Art. 28 DPA in place; the masking guardrail and no-PII fence stand until one is obtained.Privacy policy
Google LLC (Google Analytics 4 — marketing site alethe.eu only, consent-gated)Marketing-site usage analytics (IP anonymisation on; loaded only after Analytics consent)United StatesDPF + 2021 SCCsProcessor terms
Meta Platforms Ireland Ltd. (Meta Pixel — marketing site only, consent-gated; joint controller for pixel collection per CJEU C-40/17 Fashion ID, not a processor — listed for transparency)Advertising measurement / audiences via Meta Pixel (loaded only after Marketing consent)Ireland / USDPF (EU–US and Swiss only — Meta holds no UK Extension) + SCCsDPA

Email (transactional and marketing)

Transactional and marketing email providers will be added to this list before first use, with 30 days' notice to customers.

Notification of changes

Material changes (new subprocessor added; existing subprocessor changes country of processing; sub-processor decommissioned) are notified at least 30 days before taking effect, via:

  • Update to this published list
  • Email to active business customers' designated data-protection contact

In-product notification to organisation administrators is intended but not yet built; we do not list it as an operating channel until it is.

B2B customers have the right to object on reasonable data-protection grounds — the objection mechanism is set out in the DPA (provided at onboarding; request at info@alethe.eu).

Sub-subprocessors

Each subprocessor above may engage its own sub-processors (chip vendors, hosting providers, content-delivery networks). We require all subprocessors to disclose theirs in their respective DPAs and to flow the same Art. 28(3) protections to their sub-processors.

One place where that requirement is visibly unsatisfied. Our media supplier publishes a sub-processor list of 14 companies, none of which is an AI model provider, while publicly attributing model families to ByteDance, Kuaishou and others. Both cannot be complete. Either the supplier serves those weights on infrastructure it controls, or a separate company operates them and must be named. We have asked and do not yet have the answer, and we will not guess at it here.

Audit and TOM evidence

For customers under the inbound DPA, evidence of subprocessor security posture (SOC 2 reports, ISO 27001 certificates, recent pen-test summaries) is available on request to info@alethe.eu, subject to NDA where the subprocessor requires it.