Sub-processors
| Field | Value |
|---|---|
| Version | 1.0 |
| Effective date | 1 October 2026 |
| Last revised | 31 August 2026 |
| Approved by | Subgen AI Spain, S.L. |
| Supersedes | Not applicable (first published version) |
The full version history is available in the Legal document changelog.
This page is the up-to-date list of Sub-processors referred to in clause 6 of the Data Processing Agreement and in section 6 of the Privacy Policy. Section 1 below lists the Platform Sub-processors engaged under clause 6.2. Section 2 lists the Customer-Elected Providers engaged under clause 6.4. Section 3 explains why Customer-Configured Destinations, addressed in clause 6.5, cannot be listed here.
A Sub-processor is a third party engaged by Subgen AI Spain, S.L. to Process Personal Data on behalf of a Customer. Capitalised terms have the meaning given to them in the Data Processing Agreement.
1. Platform Sub-processors
These Sub-processors support the delivery of the Serenity* Star platform for every Customer, irrespective of any choice the Customer makes. They are engaged under clause 6.2 of the Data Processing Agreement.
| Sub-processor | Service provided | Categories of Personal Data | Region of Processing | Storage location | Basis for international transfer |
|---|---|---|---|---|---|
| Microsoft Azure | Cloud infrastructure and hosting | Account and contact data, Inputs, Outputs, technical and security logs | European Union | European Union | Not applicable (EEA) |
| Google Cloud Platform | Cloud infrastructure and hosting | Account and contact data, Inputs, Outputs, technical and security logs | Ireland | Ireland | Not applicable (EEA) |
| Google Cloud Platform | Cloud infrastructure for the US version of the APIs | Account and contact data, Inputs, Outputs, technical and security logs | United States | United States | EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) |
| Twilio SendGrid | Transactional and notification email | Identity and contact data | United States | United States | EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) |
| Google LLC (Google Analytics) | Website and product analytics | IP address, device and browser data, pages viewed, and a client-identifier cookie | United States | United States | EU-US Data Privacy Framework |
| Google LLC (Web Risk) | Evaluation of submitted URLs against Google's threat database | The URLs submitted by a Customer or produced by an agent, including any query string | United States | United States | EU-US Data Privacy Framework |
| Userflow, Inc. | In-product onboarding and guidance | Account identifier and in-product usage events | United States | United States | EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) |
| Meta Platforms Ireland Limited | Sign-in, where a User chooses to authenticate with Facebook | Authentication identifiers and the profile data the User authorises | Ireland | Ireland | Not applicable (EEA) |
| Google Ireland Limited | Sign-in, where a User chooses to authenticate with Google | Authentication identifiers and the profile data the User authorises | Ireland | Ireland | Not applicable (EEA) |
| Microsoft Ireland Operations Limited | Sign-in, where a User chooses to authenticate with a Microsoft account | Authentication identifiers and the profile data the User authorises | Ireland | Ireland | Not applicable (EEA) |
| GitHub, Inc. | Sign-in, where a User chooses to authenticate with GitHub | Authentication identifiers and the profile data the User authorises | United States | United States | EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) |
| X (formerly Twitter) | Sign-in, where a User chooses to authenticate with X | Authentication identifiers and the profile data the User authorises | United States | United States | EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) |
| Cloudflare, Inc. | Reverse proxy, content delivery and protection against network attacks | IP address and request metadata for every request reaching the platform | Global anycast edge network | Global | EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) |
| Microsoft Azure Application Insights | Application monitoring and diagnostics | Request metadata, IP address, error traces, and any Personal Data incidentally present in them | European Union | European Union | Not applicable (EEA) |
| Google LLC (reCAPTCHA) | Protection of sign-up and sign-in against automated abuse | IP address, browser and device signals, and interaction data | United States | United States | EU-US Data Privacy Framework |
| Stripe | Payment and subscription management | Identity, contact, payment and billing data | United States | United States | EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) |
| OpenAI | Automatic moderation of Inputs, on the Free Services only | The content of the conversation submitted to the agent | United States | United States | EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) |
Where a User signs in with an external identity provider, that provider acts as an independent controller for the authentication itself. Subgen AI receives only the identifiers and profile data the User authorises.
Subgen AI's file manager, dataset service and chart renderer are internal subsystems running on Microsoft Azure within Subgen AI's own tenant. They are not separate Sub-processors; the underlying infrastructure is covered by the Microsoft Azure entry above.
The moderation of Inputs described above applies only to the Free Services. It is applied automatically, is not selected by the Customer, and runs irrespective of which Model the Customer has enabled. It does not apply to the Paid Services.
2. Customer-Elected Providers
These providers are engaged under clause 6.4 of the Data Processing Agreement. A provider Processes Personal Data only where the Customer has enabled a Model, Skill or other optional feature that relies on it. A Customer that enables nothing from a provider sends that provider no data.
2.1. Model providers
These providers serve the Models available for chat, embeddings, vision, image generation and speech generation. Every Model in the catalogue names the provider that serves it, in brackets after the Model name, so a Customer can identify the recipient before enabling it. The catalogue is at Available AI Models and is the authoritative record of which Models each provider currently serves.
| Model provider | Models it serves |
|---|---|
| OpenRouter | Aggregated access to Models from a range of research labs |
| OpenAI | OpenAI Models |
| Azure OpenAI | OpenAI Models hosted on Microsoft Azure |
| Azure AI Foundry | Models hosted on Microsoft Azure AI Foundry |
| Anthropic | Claude Models |
| Google Vertex AI | Google Models |
| Mistral AI | Mistral Models |
| xAI | Grok Models |
| Alibaba Cloud | Qwen Models, and speech transcription and synthesis |
| DeepSeek | DeepSeek Models |
| Moonshot AI | Kimi Models |
| Together AI | Open-weight Models |
| Amazon Bedrock | Models hosted on Amazon Bedrock |
| Replicate | Image generation Models |
| ElevenLabs | Speech synthesis and transcription Models |
| Serenity Cloud | Subgen AI's own Models |
The Models served under the provider name Serenity Cloud run on infrastructure operated by Subgen AI Spain, S.L. They are not served by a third party.
OpenRouter is an aggregator: it does not run Models itself, but forwards each request to a further upstream provider. Where a Customer enables a Model served through OpenRouter, the Processing may be carried out by an upstream provider of OpenRouter's choosing.
2.2. Services behind Skills and other optional features
These providers support specific Skills and other optional features. A provider receives data only where the Customer has enabled the corresponding Skill or feature for an agent.
| Provider | Feature it supports | Data transmitted to it |
|---|---|---|
| ScrapingBee | Retrieval of websites that Subgen AI's own crawler cannot reach | The URLs submitted for retrieval |
| Alinia | A guardrail provider for Metacontrol, where the Customer enables it for an agent | The content of the messages analysed |
| Microsoft Azure AI Content Safety | A guardrail provider for Metacontrol, where the Customer enables it for an agent | The content of the messages analysed |
| OpenAI | A guardrail provider for Metacontrol, where the Customer enables it for an agent | The content of the messages analysed |
| Replicate | Image Generator Skill | The prompt submitted for image generation |
| ElevenLabs | Speech Generation Skill | The text submitted for speech synthesis |
| Anthropic | Code Execution Skill | The code and data submitted for execution |
Replicate, ElevenLabs and Anthropic also appear in section 2.1, since they serve Models in the catalogue as well.
Ingestion of a website into Knowledge is carried out by a scraping service operated by Subgen AI Spain, S.L. ScrapingBee is used only where that service cannot reach the site.
Personal data detection, anonymisation and language detection run on Subgen AI's own infrastructure and are not carried out by a third party.
The Web Search Skill does not use a separate search provider. The search is performed by the server-side tool of whichever model provider the Customer has already enabled for the agent.
3. Customer-Configured Destinations
Some features let the Customer specify the destination to which data is sent. The Remote MCP Connector connects to a Model Context Protocol server at an address the Customer supplies. The HTTP Request Skill calls an endpoint the Customer defines. An external account connected to a Workspace is chosen by the Customer.
In each case the Customer determines the recipient. Subgen AI transmits the data as instructed and does not select, evaluate or contract with that recipient, so these destinations are not Sub-processors engaged by Subgen AI and cannot be enumerated on this page. Clause 6.5 of the Data Processing Agreement sets out how they are treated.
4. Changes to this list
In accordance with clause 6.6 of the Data Processing Agreement, for the Platform Sub-processors in section 1:
- Notice period. Subgen AI gives at least 30 days of notice before a new Sub-processor starts Processing Personal Data on behalf of a Customer.
- Channel. Changes are notified by email to the administrative contact associated with the Customer's Account, and published on this page.
- Objection. Customers may object to a new Sub-processor within 30 days of notification. If no resolution is reached, the Customer may terminate the affected Services.
- Subscription. To be notified of changes to this list, write to [email protected].
5. Contact
Questions about this list, about a specific Sub-processor, or about the safeguards applied to an international transfer can be sent to [email protected], or by post to Subgen AI Spain, S.L., Attn: Privacy Team, Calle Colón 8, Puerta 2, 46004 Valencia, Spain.