Skip to main content
Legal Document

Subprocessors

Last updated: June 8, 2026

This page lists the third-party subprocessors that AIOX Suite engages to deliver the Services. It is referenced from our Terms of Service and our Privacy Policy, and is provided to help customers meet their own subprocessor-disclosure obligations under the GDPR, the UK GDPR, the CCPA / CPRA, and similar laws.

1. Current subprocessors

1.1 Infrastructure and hosting

Subprocessor Purpose Location of processing Transfer mechanism (if outside EEA / UK)
Amazon Web Services, Inc. Application hosting, server infrastructure, database storage, encrypted backups Atlanta, Georgia, USA (US-East region) EU–US Data Privacy Framework + Standard Contractual Clauses + AWS Data Processing Addendum
Cloudflare, Inc. Content delivery network, DDoS mitigation, DNS resolution, edge caching Global edge network with US primary EU–US Data Privacy Framework + Standard Contractual Clauses + Cloudflare DPA

1.2 Payment processing

Subprocessor Purpose Location of processing Transfer mechanism (if outside EEA / UK)
Stripe, Inc. Payment processing, billing, subscription management, fraud detection, Customer Portal United States; Ireland (for EU customers) EU–US Data Privacy Framework + Standard Contractual Clauses + Stripe Data Processing Agreement + UK International Data Transfer Addendum

1.3 Advertising analytics and attribution

Subprocessor Purpose Location of processing Transfer mechanism (if outside EEA / UK)
Meta Platforms, Inc. Server-side conversion attribution via the Meta Conversions API (hashed email + name, IP, UA, _fbp, _fbc) United States EU–US Data Privacy Framework + Standard Contractual Clauses
Google LLC (Analytics 4 + Measurement Protocol) Server-side conversion attribution and aggregate analytics (anonymous client_id, transaction value) United States; EU regions where elected EU–US Data Privacy Framework + Google Cloud DPA + Standard Contractual Clauses

1.4 Third-party AI providers

AI providers are engaged when you invoke an app or feature that calls them. They receive only the prompt and contextual data necessary to fulfil the specific request; they do not receive your dashboard activity, visitor IPs from your connected sites, or billing data.

Subprocessor Purpose Location of processing Transfer mechanism (if outside EEA / UK)
Google LLC (Gemini API) Default AI provider for content optimisation, Capsule generation, Help Concierge, Sentinel rule proposals, AI Visibility Score, AI Forensics United States; EU regions where elected EU–US Data Privacy Framework + Standard Contractual Clauses + Google Cloud Data Processing Addendum
OpenAI, L.L.C. Optional / alternate AI provider for content processing and Forensics probes United States EU–US Data Privacy Framework + Standard Contractual Clauses + OpenAI Data Processing Addendum
Anthropic, PBC Optional / alternate AI provider for content processing and Forensics probes United States EU–US Data Privacy Framework + Standard Contractual Clauses + Anthropic Data Processing Addendum
Perplexity AI, Inc. Optional / alternate AI provider for Forensics probes United States Standard Contractual Clauses + Perplexity Data Processing Addendum

1.5 Operational tooling

Subprocessor Purpose Location of processing Transfer mechanism (if outside EEA / UK)
Amazon Web Services, Inc. (Amazon SES) Delivery of account, billing, security, support, dunning, and marketing emails United States EU–US Data Privacy Framework + Standard Contractual Clauses + AWS DPA
Sentry, Inc. Application monitoring, error reporting, performance telemetry United States; EU regions where elected EU–US Data Privacy Framework + Standard Contractual Clauses + Sentry DPA
CookieYes (Sahaj Software Solutions Limited) Cookie-consent banner, consent log management, automatic cookie scanning India + EU regions Standard Contractual Clauses + CookieYes DPA

2. Scope of processing per subprocessor

  • Amazon Web Services (hosting) processes all categories of personal data because it hosts the systems on which the Services run. Data is encrypted at rest with AES-256 and in transit with TLS 1.3.
  • Cloudflare processes only the metadata required to deliver edge caching and DDoS mitigation: IP addresses, request paths, HTTP headers, TLS fingerprints. Cloudflare does not see request bodies for HTTPS-terminated origin traffic.
  • Stripe processes only the personal data necessary for payment: account identifiers, payment-method tokens, billing addresses, invoice records, and fraud-detection signals. Stripe does not receive content data, AI prompts, or visitor telemetry from connected websites.
  • Meta and Google (advertising attribution) receive only the conversion-event payloads described in the Privacy Policy §9. They do not receive your dashboard activity, visitor data, or content.
  • AI providers receive only the specific prompt and contextual data necessary to fulfil the request that invoked them. They do not receive your dashboard activity, visitor IPs from your connected sites, billing data, or other operational data.
  • Amazon SES processes recipient email addresses, message subjects, and message bodies for delivery. Bounce and complaint feedback is retained for 90 days.
  • Sentry processes error stack traces and operational telemetry. Personal data is filtered out at source where possible; the Sentry instance is configured with PII scrubbing.
  • CookieYes processes consent choices, IP address, and timestamp for legal-evidence purposes.

3. Subprocessor selection and review

Before engaging a new subprocessor, we:

  • Review the subprocessor's security posture, certifications (SOC 2, ISO 27001, etc.), and incident-response practices;
  • Bind the subprocessor by written agreement to data-protection obligations no less protective than those in our Privacy Policy and Terms of Service;
  • Where personal data is transferred outside the EEA, UK, or Switzerland, ensure that an appropriate transfer mechanism is in place;
  • Maintain documentation of the basis on which we conduct the transfer impact assessment required under European law.

4. Notification of changes

We will update this page when we add, remove, or replace a subprocessor.

For customers who have entered a Data Processing Addendum with us that requires advance notification of subprocessor changes:

  • We will provide at least thirty (30) days' notice before a new subprocessor begins processing personal data on our behalf, via email to the contact address on file and via a notice on this page;
  • If you object to a new subprocessor on reasonable data-protection grounds, you may notify us within the notice window at support@aioxsuite.com; we will work in good faith to address your concerns.

5. Data Processing Addendum

A Data Processing Addendum incorporating the Standard Contractual Clauses and the UK International Data Transfer Addendum is available on request to support@aioxsuite.com.

6. Questions

For questions about this Subprocessor List, contact:

AIOX Suite
All inquiries: support@aioxsuite.com