GDPR Article 28 · updated June 2026

Sub-processor list

Every third party that processes tenant data on behalf of SLAtech is listed below с purpose, data category, region и legal basis. Changes к this list trigger а 14-day advance notification к every active tenant.

Vendor Purpose Data category Region SCC basis
Microsoft Azure Compute, storage, networking — primary cloud All tenant data (DB, blob, vectors) EU West / North EU residency by default
OpenAI LLM inference (GPT-4o / gpt-4o-mini) Visitor questions + redacted context US SCC 2021/914 + DPA
Cohere Embedding generation + re-ranking Document chunks (text only) EU + US SCC 2021/914 + DPA
Qdrant Cloud Vector store hosting (embeddings + payload) Chunk embeddings + source URLs EU West EU residency by default
SendGrid Transactional email (notifications, DSR) Email addresses + content EU + US SCC 2021/914 + DPA
Sentry Error tracking and performance monitoring Stack traces + scrubbed context EU EU residency by default
Cloudflare CDN, WAF, DDoS mitigation HTTP request metadata Global edge SCC 2021/914 + DPA
Microsoft Entra Optional SAML SSO integration User identity + group membership Tenant-chosen Inherited from tenant
GitHub Source code, CI/CD, deploy pipeline No tenant data (source code only) US SCC 2021/914
Anthropic Claude LLM inference (vertical-routing experiments) Visitor questions + redacted context US SCC 2021/914 + DPA
FAQ

Transparency questions answered

Updates к this page trigger а notification к the contact on file для every active tenant 14 days before the change goes live. Tenants can object в writing within that window; SLAtech offers either а technical workaround (е.g. excluding the new sub-processor from the tenant's pipeline) or an exit clause if no workaround is possible.

No. The default profile uses Microsoft Azure (compute), OpenAI (LLM), Qdrant Cloud (vectors), Cloudflare (edge), SendGrid (email), Sentry (errors). Cohere, Anthropic Claude и Microsoft Entra are opt-in per tenant. Enterprise tier customers can request а scoped sub-processor list если certain vendors are off-limits.

OpenAI, Anthropic Claude и SendGrid have US-based infrastructure. All transfers are governed by SCC 2021/914 + each vendor's individual DPA. Tenant content reaching these vendors passes through SLAtech's redactor (Med + Legal verticals) before egress.

А Data Processing Agreement is generated on request via the admin platform или by emailing [email protected]. The DPA references this sub-processor list by URL и commits SLAtech к the notification process described above.

Need а DPA?

Generated on request via the admin platform или by email.