Legal · Sub-processors

Sub-processors.

The full live list of third parties that touch any layer of the CloakAPI service. Customers can subscribe at trust@cloakapi.io for 30-day advance notice of any change. The objection window per Art. 28(2) GDPR is 30 days from publication.

List version 4.5 · Effective 2026-07-10 · 14 entries

AI providers (when routed to)

Activated only when the customer routes a call to one of these providers. The receipt chain records exactly which provider was hit per request. Each receives only tokenised text — never your raw prompt or response, never the re-identification map that would recover the redacted values, and (for healthcare customers) never plaintext PHI. Tokenisation happens on your device before egress; these providers see surrogates, not personal data.

Providers you connect with your own key (BYOK) — e.g. OpenRouter, Perplexity, Mistral — are engaged under your own contract with them, not ours, so they are not CloakAPI sub-processors and are not listed here.

Sub-processorPurposeRegionCategoryDPA / SCC
Anthropic, PBCClaude family completionsUSAI providerSCC Mod-2 + UK Add.
OpenAI Ireland Ltd.GPT family completions, embeddingsEU/USAI providerSCC Mod-2
xAI Corp.Grok family completionsUSAI providerSCC Mod-2
Google LLC (Gemini API)Gemini completions via the Gemini API (generativelanguage.googleapis.com)US/globalAI providerEU DPA
DeepSeek (Hangzhou DeepSeek AI Co., Ltd.)DeepSeek family completionsCNAI providerSCC Mod-2

Infrastructure & operations

Sub-processorPurposeRegionCategoryDPA / SCC
Hetzner Online GmbHGateway + portal hosting, storage, DDoS protection (the single EU data plane)DE (Nuremberg)HostingEU DPA
Cloudflare, Inc.Authoritative DNS only (grey-cloud) — no proxy, CDN, WAF or TLS termination; traffic connects direct to the EU originAnycast DNSDNSSCC Mod-2 + DPA
Amazon Web Services (SES)Transactional & inbound email only — SES, an inbound-mail S3 bucket and mail-forwarder Lambdas. No AWS compute or hosting; never prompt/response payloadseu-north-1 (Stockholm)EmailEU DPA
Tailscale Inc.Internal-network access (operator side only; not in any customer request path)CANetworkingSCC Mod-2 + adequacy

Billing & finance

Sub-processorPurposeRegionCategoryDPA / SCC
Stripe Payments Europe Ltd.Card processing (PCI DSS)IEPaymentsEU DPA
Sparebank 1 SR-BankBanking, SEPA / SWIFTNOBankingNO bank secrecy
Fiken ASBookkeeping, VAT submissionNOAccountingNO bookkeeping law

Observability & security

Sub-processorPurposeRegionCategoryDPA / SCC
GlitchTip (self-hosted)Error reporting (self-hosted on the Hetzner box, operator-side, payload-stripped)DEObservabilityInternal

Legal

Sub-processorPurposeRegionCategoryDPA / SCC
Onsagers ASTrademark / IP counselNOLegalNO confidentiality

Usage-metadata attribution

Where a customer builds on CloakAPI and enables it, CloakAPI processes content-free usage metadata — plus an opaque pseudonym the builder supplies for its own end users (the optional X-Cloak-App-Id and X-Cloak-End-User headers) — as that builder's sub-processor, so the builder can attribute usage to its app and, pseudonymously, to its end users. This carries no request or response content and no end-customer PII: the pseudonym must be an opaque token, we hold no map from it to a real identity, and a value that resembles PII (email, name, phone, national id, card or bank identifier) is dropped rather than stored. This capability is off by default and records nothing until enabled. See the DPA (§2, §4) and the builder documentation at docs.cloakapi.io/platform/attribution.

Subscribe to changes

To receive 30-day advance notice of any addition or removal, email trust@cloakapi.io from the email associated with your CloakAPI account. Confirmations are sent within one business day. To object to a new sub-processor under Art. 28(2) GDPR, reply to the notification within 30 days.

Related documents