Sub-processor list · 2026-06-03
Where the data actually goes.
Every third party that touches Customer personal data, the service it provides, the region it processes in, and the legal mechanism for any transfer outside the EU. Storage and compute are EU-resident; only the model inference and embedding hop reaches the US, under SCCs with Zero Data Retention.
01—Core sub-processors
Engaged for every deployment.
These sub-processors are engaged whenever a brokerage uses AI Broker. Customer personal data is stored in the EU and all application, API, and workflow compute runs in an EU region (Vercel dub1, Dublin).
The only personal data that leaves the EU is the prompt and embedding payload sent to the AI providers at inference time. The Vercel AI Gateway operates Zero Data Retention — that payload is deleted after the request completes and is never used to train a model.
| Provider | Service | Region | Transfer mechanism |
|---|---|---|---|
| Supabase | Postgres database, authentication, object storage | EU (Ireland, eu-west-1) | EU only · DPA |
| Vercel | Application + API + workflow hosting, AI Gateway, Blob storage | EU compute (dub1, Dublin) · Vercel Inc. US-established | DPA + EU SCCs (Module 3) · AI Gateway Zero Data Retention |
| Anthropic | Claude inference (Sonnet 4.6, Haiku 4.5) via the Vercel AI Gateway | USA | EU SCCs + EU-US DPF · Zero Data Retention · no training on inputs |
| OpenAI | text-embedding-3-small embeddings via the Vercel AI Gateway | USA | EU SCCs (not DPF-listed) · Zero Data Retention · no training on inputs |
| Resend | Transactional email delivery | EU | Resend DPA · EU region |
02—Conditional sub-processors
Only when you connect them.
These sub-processors are engaged only if a brokerage chooses to connect the corresponding channel or integration. If you never connect WhatsApp, Gmail, or Microsoft 365, no data flows to that provider.
Axiom receives application and database logs where log analytics is enabled for the account.
| Provider | Service | Region | Transfer mechanism |
|---|---|---|---|
| Meta Platforms Ireland | WhatsApp Business Cloud API | EU + USA | Meta DPA + EU SCCs |
| Gmail API + Calendar | EU + USA | Google Workspace DPA + EU SCCs | |
| Microsoft | Microsoft Graph (Microsoft 365 / Outlook) | EU + USA | Microsoft DPA + EU SCCs |
| Axiom | Application + database log analytics | USA | Axiom DPA + EU SCCs · SOC 2 Type II |
03—Transfers and notice
SCCs on every EU exit.
Every transfer of personal data outside the European Economic Area runs under the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with the provider’s executed Data Processing Agreement, and, where the recipient is certified, the EU-US Data Privacy Framework.
AI Broker gives subscribers at least 30 days’ written notice before engaging a new sub-processor or replacing an existing one. Customers may object on reasonable data-protection grounds, as set out in the Data Processing Agreement.
This list is authoritative. Material changes are dated against the “Last updated” marker below. Last updated: 2026-06-03.
Contact
Questions about a sub-processor?
Email support@aibroker.ie to request a sub-processor’s DPA, ask about a transfer mechanism, or subscribe to change notifications.