GDPR Article 28 · updated June 2026
Sub-processor list
Every third party that processes tenant data on behalf of SLAtech is listed below with purpose, data category, region and legal basis. Changes to this list trigger a 14-day advance notification to every active tenant.
| Vendor | Purpose | Data category | Region | SCC basis |
|---|---|---|---|---|
| Microsoft Azure | Compute, storage, networking — primary cloud | All tenant data (DB, blob, vectors) | Enterprise-configurable | Covered by DPA |
| Language-model provider | LLM inference | Visitor questions + redacted context | US | SCC 2021/914 + DPA |
| Re-ranking provider | Embedding generation + re-ranking | Document chunks (text only) | EU + US | SCC 2021/914 + DPA |
| Vector-search provider | Semantic vector hosting (embeddings + payload) | Chunk embeddings + source URLs | Enterprise-configurable | Covered by DPA |
| SendGrid | Transactional email (notifications, DSR) | Email addresses + content | EU + US | SCC 2021/914 + DPA |
| Sentry | Error tracking and performance monitoring | Stack traces + scrubbed context | Global | Covered by DPA |
| Cloudflare | CDN, WAF, DDoS mitigation | HTTP request metadata | Global edge | SCC 2021/914 + DPA |
| Microsoft Entra | Optional SAML SSO integration | User identity + group membership | Tenant-chosen | Inherited from tenant |
| GitHub | Source code, CI/CD, deploy pipeline | No tenant data (source code only) | US | SCC 2021/914 |
| Language-model provider (vertical-routing) | LLM inference (vertical-routing experiments) | Visitor questions + redacted context | US | SCC 2021/914 + DPA |
FAQ
Transparency questions answered
How do you notify customers of sub-processor changes?
Updates to this page trigger a notification to the contact on file for every active tenant 14 days before the change goes live. Tenants can object in writing within that window; SLAtech offers either a technical workaround (e.g. excluding the new sub-processor from the tenant's pipeline) or an exit clause if no workaround is possible.
Do all tenants use all sub-processors?
No. The default profile uses Microsoft Azure (compute), a language-model provider (LLM), a vector-search provider (vectors), Cloudflare (edge), SendGrid (email), Sentry (errors). A re-ranking provider, an alternate language-model provider and Microsoft Entra are opt-in per tenant. Enterprise tier customers can request a scoped sub-processor list if certain vendors are off-limits.
Are any sub-processors located outside the EU?
Our language-model providers and SendGrid have US-based infrastructure. All transfers are governed by SCC 2021/914 + each vendor's individual DPA. For opt-in document uploads and visitor chat messages, detected structured identifiers (email, phone, payment card, Israeli national-ID, medical-record number) are tokenised or redacted before egress to these vendors; free-text names are not auto-detected and public website-crawled content is sent as-is.
Where can I get the DPA?
A Data Processing Agreement is generated on request via the admin platform or by emailing info@slatech.ai. The DPA references this sub-processor list by URL and commits SLAtech to the notification process described above.
Need a DPA?
Generated on request via the admin platform or by email.
Buyer evaluation tools
Four self-serve tools for evaluating SLAtech (or any AI chatbot vendor) without a sales call: