# Subprocessors

Version: 2026-08-24

This page identifies third parties that may process Customer Personal Data on behalf of d5s when providing the Service. Capitalised terms have the meaning given in the Business SaaS Terms and the Data Processing Addendum. The services actually used depend on Customer's plan, deployment, model selection, enabled features, and instructions.

The entries below distinguish d5s-selected subprocessors from independent controllers and customer-directed recipients.

## 1. Core service subprocessors

### Amazon Web Services EMEA SARL and relevant affiliates

- Purpose: cloud infrastructure, compute, networking, managed database, object storage, backup, logging, and key-management infrastructure.
- Primary service region: eu-central-1 (Frankfurt, Germany); us-east-1 is used only for a separately selected US service where offered.
- Data: Customer Content, account/service metadata, logs, backups, and encrypted secrets as required by the Service.
- Retention: active data follows the Service and deletion instructions; automated database backups and non-current object versions expire after seven days.
- Transfer safeguard: the AWS GDPR DPA forms part of the AWS Service Terms and incorporates the European Commission Standard Contractual Clauses for restricted transfers. AWS states that customer data remains in the selected region except as needed to provide or maintain the selected service or comply with law.

### Vercel Inc. and relevant affiliates

- Purpose: hosting and delivery of public websites and web application surfaces, aggregated Web Analytics for the public marketing site, and AI Gateway routing for model requests.
- Processing location: Vercel's primary processing facilities are in the United States, with global infrastructure and subprocessors depending on the service; AI Gateway traffic is routed to the provider that serves the selected model.
- Data: web request/device data, application assets and metadata, aggregated page-view and custom-event data, and model inputs/outputs routed through AI Gateway as instructed. Marketing-site analytics does not include contact-form contents or custom event properties.
- Retention: website deployment and service-generated data follow the Vercel account configuration. Web Analytics uses a daily visitor hash that is discarded after 24 hours, while aggregate reports remain available for the account's reporting window. AI Gateway and upstream-provider retention depend on the effective routing controls described below.
- Transfer safeguard: Vercel's DPA applies to eligible Pro and Enterprise processing, incorporates the European Commission Standard Contractual Clauses and UK transfer addendum, and describes its onward subprocessors.

### WorkOS, Inc.

- Purpose: authentication, identity management, and enterprise identity features when enabled.
- Processing location: United States and other locations used by WorkOS and its subprocessors.
- Data: user identity, business contact, authentication, organisation, directory, and security metadata.
- Retention: authentication and directory data is retained for the service term and deleted under the configured account lifecycle and WorkOS backup schedule.
- Transfer safeguard: the WorkOS DPA incorporates the European Commission Standard Contractual Clauses for applicable transfers.

### Plus Five Five, Inc., trading as Resend

- Purpose: transactional and service email, including account, waitlist, notification, and support-related messages.
- Processing location: United States for account data, email metadata, logs, and API records; delivery infrastructure may process data in the configured sending region.
- Data: recipient identity/contact details, message content and metadata, delivery events, and related logs.
- Retention: Resend's published default is 30 days for email data, subject to the contracted service configuration and legally required records.
- Transfer safeguard: the Resend DPA incorporates SCC Modules One, Two, and Three as applicable and the UK transfer addendum.

### Google Workspace and the Google contracting entity identified in the applicable agreement

- Purpose: operate d5s contact, privacy, legal, security, and service mailboxes and related internal collaboration.
- Processing location: European and global Google infrastructure under the Workspace account configuration and Google subprocessor list.
- Data: sender and recipient identity/contact details, message content and attachments, routing information, and security/delivery metadata.
- Retention: messages follow d5s mailbox and legal-retention rules; Google deletes Customer Data under the Workspace Cloud Data Processing Addendum after d5s deletes it or the service ends, subject to the provider's deletion process.
- Transfer safeguard: the Google Workspace Cloud Data Processing Addendum forms part of or may be accepted under the Workspace agreement and incorporates the applicable European Commission Standard Contractual Clauses.

### Functional Software, Inc. (Sentry)

- Purpose: error monitoring, diagnostics, and limited performance/security troubleshooting.
- Processing location: Germany for projects configured for Sentry's European data region, with United States and global support/subprocessor access as described in the Sentry DPA.
- Data: scrubbed error events, request metadata, identifiers, stack traces, device/browser data, and diagnostic context. Request bodies and cookies are removed before an event is sent.
- Retention: event retention follows the Sentry subscription and project configuration.
- Browser status: browser error reporting is integrated and sends events only when a reporting endpoint is configured in the build; session replay and performance tracing are disabled.
- Transfer safeguard: the Sentry DPA provides European transfer safeguards, including the Standard Contractual Clauses and other mechanisms described in its transfer documentation.

### Slack Technologies, LLC and relevant Salesforce affiliates

- Purpose: private operational login/security notifications, service alerts, and customer-facing Slack functionality where d5s selects Slack to perform part of the Service.
- Processing location: United States by default, or another location enabled by the applicable Slack data-residency configuration; certain profile, membership, analytics, and service metadata may remain global.
- Data: business email, organisation label, authentication method, first-login status, alert metadata, and messages or files intentionally sent to Slack.
- Retention: d5s-controlled messages and files follow the configured Slack workspace retention; customer-directed Slack destinations follow the customer's Slack settings.
- Transfer safeguard: Slack provides a DPA with European transfer safeguards. Customer-directed Slack workspaces are governed by the customer's own Slack agreement.

### Cloudflare, Inc.

- Purpose: Turnstile bot detection on the public request-access form, when enabled for the deployment.
- Processing location: Cloudflare's global network, including the United States.
- Data: browser, device, network, interaction, and verification metadata needed to decide whether a submission is automated. No form content is sent to Cloudflare.
- Retention: verification data is retained under Cloudflare's Turnstile service terms; d5s stores only the short-lived verification token needed to accept a submission.
- Transfer safeguard: Cloudflare's DPA incorporates the European Commission Standard Contractual Clauses and Cloudflare's Data Privacy Framework commitments for applicable transfers.

## 2. Model and AI-routing providers

d5s may send Customer-selected prompts, relevant Customer Content, instructions, tool context, and generated responses to Vercel AI Gateway and the model provider needed to perform the request.

The current model catalog routes through Vercel AI Gateway. The provider that serves a request may differ from the model publisher and can change through routing or failover. d5s records the effective provider route for audit and support purposes.

This processing covers both user-selected model calls and auxiliary calls made to operate the Service, including web search, deep research, subagents, context compaction, summarisation, and other fixed-model features. Perplexity Sonar is used for web search through Vercel AI Gateway.

Provider and model-publisher categories include:

- Anthropic entities — language-model inference;
- OpenAI entities — language-model and related inference;
- Google entities — Gemini/model inference;
- Mistral AI entities — language-model inference;
- Amazon, xAI, Meta, Alibaba, DeepSeek, Cohere, NVIDIA, and other providers expressly shown in the model selector, Order, route evidence, or deployment configuration.

An authenticated user may enable no-training routing. When enabled, d5s instructs AI Gateway to use only eligible routes that are not permitted to use prompts or outputs for model training, and unknown routes fail closed. If it is not enabled, training and retention depend on the selected provider's terms. Zero Data Retention applies only where expressly identified for the request, provider, feature, or Order.

Vercel's DPA and transfer terms govern AI Gateway processing. Vercel's agreements with the selected upstream host govern onward processing. Customers may restrict or select available models and, where supported by their plan or Order, approved providers.

## 3. Conditional subprocessors

None at present. Providers that d5s enables only on a Customer's instruction are described in section 5.

## 4. Payment provider and independent-controller processing

### Stripe Payments Europe, Limited and relevant Stripe affiliates

- Purpose: checkout, payment processing, recurring billing, invoicing, fraud prevention, and payment compliance.
- Data: customer/business contact, billing address, tax/VAT information, payment method, transaction, invoice, and fraud/device data.
- Role: Stripe may act as d5s's processor for some services and as an independent controller for regulated payment, fraud, compliance, and legal purposes. Its own privacy terms apply to independent processing.
- Processing/transfer information: for an account outside the Americas, Stripe's DPA identifies Stripe Payments Europe, Limited in Ireland. The DPA forms part of the Stripe Services Agreement; its Data Transfers Addendum uses the EU-US Data Privacy Framework where available and the European Commission Standard Contractual Clauses as a fallback.

### Google Fonts

- Purpose: deliver web-font resources where d5s pages load fonts directly from Google rather than self-hosting them.
- Data: IP address, user agent, request time, referrer where sent, and requested font resources; no Customer Content is intentionally submitted.
- Role: direct website recipient and independent controller, rather than a Customer Content subprocessor.
- Processing/transfer information: the requests are governed by the Google Fonts API Terms and Google privacy terms. d5s may remove this direct recipient by self-hosting the font files.

## 5. Customer-directed integrations

When an authorised user enables a connector, MCP server, model endpoint, communication destination, or other third-party integration, d5s sends data to that third party on Customer's instructions. The third party is not a d5s subprocessor merely because d5s provides a connection mechanism.

Customer is responsible for:

- authorising the integration and its recipients;
- reviewing the third party's terms, privacy, security, retention, and transfer arrangements;
- configuring scopes and credentials;
- ensuring the instruction and disclosure are lawful; and
- disabling the integration when no longer required.

If d5s selects a third party to perform part of the Service on d5s's behalf rather than at Customer's independent direction, d5s will classify and list it as a subprocessor.

## 6. Changes and objections

d5s will give the notice stated in the applicable DPA before a new subprocessor begins processing Customer Personal Data, except where urgent replacement is reasonably necessary for security, continuity, or law.

Customers may subscribe to notices by writing to privacy@d5s.tech. A Customer may object on reasonable data-protection grounds by writing to the same address within the 30-day DPA notice period.

## 7. Contact

Questions about this list or transfer safeguards: privacy@d5s.tech.
