Sub-processors.
The full live list of third parties that touch any layer of the CloakAPI service. Customers can subscribe at trust@cloakapi.io for 30-day advance notice of any change. The objection window per Art. 28(2) GDPR is 30 days from publication.
AI providers (when routed to)
Activated only when the customer routes a call to one of these providers. The receipt chain records exactly which provider was hit per request. Each receives only tokenised text — never your raw prompt or response, never the re-identification map that would recover the redacted values, and (for healthcare customers) never plaintext PHI. Tokenisation happens on your device before egress; these providers see surrogates, not personal data.
Providers you connect with your own key (BYOK) — e.g. OpenRouter, Perplexity, Mistral — are engaged under your own contract with them, not ours, so they are not CloakAPI sub-processors and are not listed here.
| Sub-processor | Purpose | Region | Category | DPA / SCC |
|---|---|---|---|---|
| Anthropic, PBC | Claude family completions | US | AI provider | SCC Mod-2 + UK Add. |
| OpenAI Ireland Ltd. | GPT family completions, embeddings | EU/US | AI provider | SCC Mod-2 |
| xAI Corp. | Grok family completions | US | AI provider | SCC Mod-2 |
| Google LLC (Gemini API) | Gemini completions via the Gemini API (generativelanguage.googleapis.com) | US/global | AI provider | EU DPA |
| DeepSeek (Hangzhou DeepSeek AI Co., Ltd.) | DeepSeek family completions | CN | AI provider | SCC Mod-2 |
Infrastructure & operations
| Sub-processor | Purpose | Region | Category | DPA / SCC |
|---|---|---|---|---|
| Hetzner Online GmbH | Gateway + portal hosting, storage, DDoS protection (the single EU data plane) | DE (Nuremberg) | Hosting | EU DPA |
| Cloudflare, Inc. | Authoritative DNS only (grey-cloud) — no proxy, CDN, WAF or TLS termination; traffic connects direct to the EU origin | Anycast DNS | DNS | SCC Mod-2 + DPA |
| Amazon Web Services (SES) | Transactional & inbound email only — SES, an inbound-mail S3 bucket and mail-forwarder Lambdas. No AWS compute or hosting; never prompt/response payloads | eu-north-1 (Stockholm) | EU DPA | |
| Tailscale Inc. | Internal-network access (operator side only; not in any customer request path) | CA | Networking | SCC Mod-2 + adequacy |
Billing & finance
| Sub-processor | Purpose | Region | Category | DPA / SCC |
|---|---|---|---|---|
| Stripe Payments Europe Ltd. | Card processing (PCI DSS) | IE | Payments | EU DPA |
| Sparebank 1 SR-Bank | Banking, SEPA / SWIFT | NO | Banking | NO bank secrecy |
| Fiken AS | Bookkeeping, VAT submission | NO | Accounting | NO bookkeeping law |
Observability & security
| Sub-processor | Purpose | Region | Category | DPA / SCC |
|---|---|---|---|---|
| GlitchTip (self-hosted) | Error reporting (self-hosted on the Hetzner box, operator-side, payload-stripped) | DE | Observability | Internal |
Legal
| Sub-processor | Purpose | Region | Category | DPA / SCC |
|---|---|---|---|---|
| Onsagers AS | Trademark / IP counsel | NO | Legal | NO confidentiality |
Usage-metadata attribution
Where a customer builds on CloakAPI and enables it, CloakAPI processes content-free usage metadata — plus an opaque pseudonym the builder supplies for its own end users (the optional X-Cloak-App-Id and X-Cloak-End-User headers) — as that builder's sub-processor, so the builder can attribute usage to its app and, pseudonymously, to its end users. This carries no request or response content and no end-customer PII: the pseudonym must be an opaque token, we hold no map from it to a real identity, and a value that resembles PII (email, name, phone, national id, card or bank identifier) is dropped rather than stored. This capability is off by default and records nothing until enabled. See the DPA (§2, §4) and the builder documentation at docs.cloakapi.io/platform/attribution.
Subscribe to changes
To receive 30-day advance notice of any addition or removal, email trust@cloakapi.io from the email associated with your CloakAPI account. Confirmations are sent within one business day. To object to a new sub-processor under Art. 28(2) GDPR, reply to the notification within 30 days.