Subprocessors

Data processors (Art. 28 GDPR)

Last reviewed: 17 July 2026Version: 1.2

This English translation is provided for convenience only. The Spanish version is the legally binding text.

Read the Spanish version (legally binding)

This document is for information purposes only. It does not constitute legal advice. For its interpretation as applied to your specific situation, consult a professional.

Sub-processors

Alethexis relies on the following sub-processors to provide the service. All of them process data on behalf of the customer (the controller) under a data processing agreement (Art. 28 GDPR).

ProviderPurposeData processedLocationSafeguard mechanism
SupabaseDatabase, storage, authentication and functionsAll product dataEU — Frankfurt (eu-central-1)Supabase DPA + SCCs (US entity)
VercelApplication hosting and Edge networkHTTP logs, request metadataUnited States (primary processing) + global edgeEU-US DPF + SCCs
CloudflareDNS proxy, CDN, WAF and Turnstile (captcha)Visitor IP addresses and browser signalsUnited States (proxy over all traffic)EU-US DPF + SCCs
Stripe Payments EuropePayment processingPayment dataUnited States (+ India)SCCs + EU-US DPF
ResendTransactional email deliveryRecipient email address and message contentUnited States (delivery via SES eu-west-1)SCCs + EU-US DPF
Google WorkspaceInbound email and customer communicationEmail content and sender dataUnited States / EU (Google Ireland)SCCs + EU-US DPF
HoldedStatutory invoicingCustomer tax data (tax ID, company name, amounts)Spain (entity); US sub-processors (GCP, MongoDB Atlas, Salesforce)Holded DPA + SCCs (sub-processors)
SentryError monitoringError traces (with PII scrubbing), metadataEU — FrankfurtSentry DPA (EU configuration)

Internal providers (no access to customer data)

The following providers form part of our development and internal operations environment. They do not process customer production data. They are listed for transparency.

ProviderPurposeData processedLocation
GitHubSource code repositorySource code. No customer dataUnited States (standard contractual clauses)
AnthropicClaude models used in developmentDevelopment prompts and code only. No customer production dataUnited States / EU depending on endpoint

International transfers

Product data is hosted in the European Union (Frankfurt). Some processors supporting the service process personal data outside the EEA (United States), covered by transfer safeguards in accordance with Chapter V of the GDPR: standard contractual clauses (Art. 46(2)) and, where applicable, the EU-US Data Privacy Framework. The location and mechanism of each processor are detailed in the table above.

Notification of changes. Any addition of a new sub-processor is notified to customers 30 days in advance by email and by notice in the product. Customers may object in accordance with the data processing agreement.