Skip to content

Subprocessor Register & DPAs

UK GDPR Art 28. Controls GOV-02. Status: designed — register maintained and reconciled per-PR; every DPA remains OPEN (none signed; counsel C20). Last reconciled 2026-07-04 (dataroom PR-12, with Ada's data-governance inputs).

Policy: policies/vendor-and-subprocessor-policy.md.

For each vendor: purpose, data categories shared, location/region, DPA/ safeguard status, and a pointer to the signed DPA (Tier 2 / restricted — not stored here). Vendor account IDs and contract terms are Tier 2. Production hosting is Google Cloud (europe-west2); there is still no real user data — pre-launch seed data is fictional/mock and must be purged before GA.

Processors and subprocessors (personal data in scope now or when users launch)

Subprocessor Purpose Data categories Region DPA / safeguard status Evidence
Google Cloud Production hosting, database, cache, jobs, secrets, logs, Artifact Registry, remote state All persisted production data once real users launch; pre-launch mock seed data only today europe-west2 OPEN — DPA/data-processing terms not yet executed (C20) partile-ops: infra/envs/prod-gcp/; technical/infrastructure-and-deployment.md
LinkedIn (OIDC) Identity provider OIDC sub, email, name, picture OPEN — DPA not started (C20) partile-prod-linkedin-* secret labels; SEC-10
Cloudflare Production API edge, data-room Access/Pages Network metadata; no persisted application database data global edge OPEN — DPA not started; API-token rotation action open (ACT-001) cloudflare-api-token secret label; technical/architecture-overview.md
Anthropic (Claude API, key-gated) AI match rationale and optional profile interview Minimized only: display name/headline/intent tags (rationale); bounded role/content turns (interview). No email, raw identifiers, raw boarding-pass data, secrets, or broker enrichment TBD OPEN — integrated in infra PR-27/PR-28; not live until ANTHROPIC_API_KEY is set; DPA not started (C20, C27) partile-prod-anthropic-api-key label; GOV-06
Apple (Developer Program / App Store Connect) iOS signing, TestFlight/App Store distribution (native app; Expo/EAS retired 2026-06-28) App metadata; no end-user PII in scope today US OPEN — DPA not started asc-*, ios-dist-cert-* secret labels; IOS-NATIVE-NOTES.md
Sentry Error/crash monitoring; sanitized scanner-failure telemetry PII-free by construction: closed-enum failure class/stage/reason codes, rounded image dimensions, attempt counts. Structurally cannot carry raw pass payload, names, PNR, file paths, or image content; fires only when a DSN is configured US OPEN — DPA not reviewed (Sentry publishes a standard DPA at sentry.io/legal/dpa/); dSYM upload currently disabled (wrong slug) sentry-dsn, sentry-*-token labels; technical/data-architecture.md (scanner telemetry boundary); telemetry sanitization unit tests

Data providers (inbound flight data — no user identity sent)

Requests carry flight number + date only, server-side, with no user identifier attached; responses are public flight-schedule/status data. Whether these vendors are Art 28 processors at all is OPEN — counsel (the query pattern could itself be considered personal data in context); recorded here conservatively pending that call.

Vendor Purpose Data categories Region Status Evidence
AirLabs (airlabs.co) PRIMARY live flight status/times since 2026-06-28 Flight number + date out; public schedule/status data in global OPEN — free tier, no DPA; ToS review pending infra PR-38 (AirLabsProvider); airlabs-api-key label; deployed api-00010-gxg; FLIGHT_DATA_PROVIDER=airlabs
AeroDataBox (via api.market) Flight status fallback only Same as AirLabs when active; subscription currently lapsed (no processing) global OPEN — dormant; re-confirm terms before any re-enable aerodatabox-api-key label; DIGEST 2026-06-27/28 lapse record
FlightAware AeroAPI Flight-data trial pending (provider bake-off, data PR-1) Same query pattern; airport-board queries during the bake-off US OPEN — trial approved 2026-07-04, signup not complete; no data flows yet vendor-spend register; key will vault as aeroapi-key

Tooling vendors (no end-user personal data)

These process company/engineering material, not user personal data (there are no real users; the repo is Tier-1 no-PII by rule). Recorded for completeness and because posture changes must come back through this register.

Vendor Purpose Data categories Region Status / safeguards Evidence
Z.ai (GLM Coding Plan) AI executor vendor (glm executor: gpu-lab, data/Ada tracks) Source code, specs, and prompts from executor runs; no user personal data permitted in executor context PRC-based vendor — cross-border flag: before any personal data could ever enter executor context, Art 44–49 / UK IDTA analysis is REQUIRED (OPEN — counsel, C20) ACTIVE; OPEN — ToS/DPA review not done glm-api-key label; DIGEST 2026-07-01 (vendor wiring); atelier [executors.glm] config
RunPod GPU rental (gpu-lab experiments; candidate for Phase-2 self-host inference) Experiment code/models; synthetic/public data only; no production or user data US ACTIVE (prepaid). Vendor attests SOC 2 Type II (2025-10) and GDPR/HIPAA (2026-02) — attestation pointers to be filed Tier-2 (OPEN); company policy: SECURE cloud tier only runpod-api-key, runpod-password labels; DIGEST 2026-07-03/04 (onboarding); vendor-spend register

Planned / future

Vendor Purpose Data categories Region Status
PDL (enrichment, deferred) Future profile enrichment for internal matching signals only Professional enrichment attributes; not displayed or redistributed; no data processed today TBD planned; not contracted (C26)
ZoomInfo (enrichment, deferred) Future profile enrichment for internal matching signals only Same as PDL; no data processed today TBD planned; not contracted (C26)
Push provider (future) Notifications Device token (future) TBD not started
Analytics/BI (future) Product analytics Tiered events TBD not started

[counsel required] for DPA terms and transfer mechanisms — C20 covers the full vendor set above, including the Z.ai PRC cross-border question. Ties to PRIV-11 (international transfers) and counsel-queue.md C20/C26/C27. New vendor onboarding follows policies/vendor-and-subprocessor-policy.md; the CFO's vendor-spend.md and renewal-calendar.md track the commercial side of the same vendor set.