قائمة المعالجين الفرعيين
Last updated: 30 July 2026
Next review: 30 October 2026
Operator: DataDiwan, Y-tunnus 3641767-6, Pakkamestarinkatu 1 F 94, 00520 Helsinki, Finland
Contact: info@datadiwan.com · support@datadiwan.com
1. Introduction
This Subprocessor List identifies the third-party service providers ("Subprocessors") that DataDiwan engages to process personal data on behalf of our customers in connection with the DataDiwan OS platform (the "Service").
This list is maintained in accordance with GDPR Article 28(2) and (4) and the Finnish Data Protection Act (Tietosuojalaki 1050/2018). We notify customers of any changes to this list at least 30 days before a new Subprocessor is engaged, unless the change is required for security or legal compliance.
2. Current Subprocessors
2.1 Infrastructure & Hosting
| Subprocessor | Purpose | Location | Data Processed | Safeguards |
|---|---|---|---|---|
| Fly.io, Inc. | Application hosting (API + Agent Worker) | EU (Amsterdam) | All application data, runtime data, environment variables | GDPR Art. 28 DPA, EU Standard Contractual Clauses (SCCs) |
| Vercel, Inc. | Web application hosting (Next.js Dashboard) | EU (Frankfurt) | Static assets, edge-rendered pages, IP addresses, access logs | GDPR Art. 28 DPA, EU Standard Contractual Clauses (SCCs) |
| Supabase, Inc. | PostgreSQL database, authentication (Auth), row-level security | EU (Frankfurt) | All customer data, user accounts, Company Memory, lead data, session tokens | GDPR Art. 28 DPA, EU Standard Contractual Clauses (SCCs) |
| Upstash, Inc. | Redis cache, message queue (Event Bus), rate limiting | EU (Frankfurt) | Session data, job queues, event streams, temporary cache | GDPR Art. 28 DPA, data minimization, EU region |
2.2 Artificial Intelligence & Machine Learning
| Subprocessor | Purpose | Location | Data Processed | Safeguards |
|---|---|---|---|---|
| Google Cloud / Vertex AI | LLM inference for AI agent outputs (production environment) | EU (Frankfurt) + USA | Anonymized prompts, business context, Company Memory excerpts for AI generation | Google Cloud Data Processing Addendum (GDPR Art. 28), EU Standard Contractual Clauses (SCCs), data minimization |
| Anthropic PBC | LLM inference (local development environment only) | USA | Synthetic/test data only; no production personal data | EU Standard Contractual Clauses (SCCs), development isolation |
Note on AI data flows: We minimize data sent to LLM APIs. Where possible, business context is pseudonymized or stripped of direct identifiers before transmission. Personal data of your leads or clients is only transmitted when explicitly required for the AI function you request (e.g., drafting a personalized email to a specific lead).
2.3 Payment Processing
| Subprocessor | Purpose | Location | Data Processed | Safeguards |
|---|---|---|---|---|
| Stripe, Inc. | Payment processing, subscription management, metered billing, invoicing, fraud prevention | USA | Payment card tokens, billing addresses, transaction history, VAT IDs | Stripe Services Agreement (DPA incorporated), EU Standard Contractual Clauses (SCCs), PCI-DSS Level 1 |
2.4 Communication & Authentication
| Subprocessor | Purpose | Location | Data Processed | Safeguards |
|---|---|---|---|---|
| Google LLC | User authentication (Google Sign-In / OAuth 2.0) | USA | Authentication tokens, email addresses, profile names | Google API Services User Data Policy, Google Cloud Data Processing Addendum, EU Standard Contractual Clauses (SCCs) |
| Meta Platforms, Inc. | WhatsApp Cloud API — inbound/outbound business messaging | USA | Phone numbers, message content (when user enables integration), contact metadata | Meta Business Tools Terms, Meta Data Processing Terms, EU Standard Contractual Clauses (SCCs), HMAC webhook verification |
2.5 Observability & Monitoring
| Subprocessor | Purpose | Location | Data Processed | Safeguards |
|---|---|---|---|---|
| Langfuse GmbH | LLM tracing, observability, performance monitoring | Germany (EU) | Anonymized LLM request/response traces, latency metrics, token counts | GDPR Art. 28 DPA, EU-based, data minimization |
2.6 User-Connected Integrations (Not Subprocessors)
The following services are connected directly by the user to their own accounts. DataDiwan does not act as a processor for data stored in these services; we merely provide an integration layer:
| Integration | Purpose | Controller |
|---|---|---|
| Gmail (Google LLC) | Email draft creation, send/receive metadata | The user |
| QuickBooks (Intuit Inc.) | Invoice sync, payment tracking | The user |
| Slack (Slack Technologies, LLC) | Notifications, alerts | The user |
| Google Calendar (Google LLC) | Event scheduling, availability | The user |
For these integrations, the user retains full control and acts as the data controller. DataDiwan's access is limited to the scope authorized by the user through OAuth consent screens.
3. Subprocessor Notification Process
3.1 Notification
If we intend to add a new Subprocessor or replace an existing one, we will:
- Update this Subprocessor List at least 30 days before the change takes effect
- Notify affected customers by email at least 30 days in advance
- Provide information about the new Subprocessor's role, location, and safeguards
3.2 Right to Object
Customers have the right to object to a new Subprocessor on reasonable grounds within 14 days of receiving notification. If you object:
- We will work with you to find an acceptable alternative solution
- If no alternative is feasible, you may terminate the affected portion of the Service without penalty
3.3 Emergency Changes
In exceptional circumstances (security threat, legal requirement, or service continuity), we may engage a Subprocessor with less than 30 days' notice. In such cases, we will notify customers as soon as possible and provide the rationale.
4. Data Transfers Outside the EEA
Some Subprocessors are headquartered outside the European Economic Area (EEA) but process data in EU regions where indicated. For any processing outside the EEA, we ensure:
- EU Commission Standard Contractual Clauses (SCCs) are in place with the Subprocessor
- Additional technical and organizational measures are implemented (encryption, access controls, data minimization)
- Transfers are limited to what is strictly necessary for the service function
- Regular reviews of Subprocessor compliance and data residency settings
5. Changes to This List
We review and update this Subprocessor List quarterly. The "Last updated" date at the top indicates the current version. Material changes are notified to customers as described in Section 3.
6. Contact
For questions about this Subprocessor List, contact:
Email: info@datadiwan.com · support@datadiwan.com
Postal: DataDiwan, Pakkamestarinkatu 1 F 94, 00520 Helsinki, Finland