Subprocessors
Last updated: June 8, 2026
This page lists the third-party subprocessors that AIOX Suite engages to deliver the Services. It is referenced from our Terms of Service and our Privacy Policy, and is provided to help customers meet their own subprocessor-disclosure obligations under the GDPR, the UK GDPR, the CCPA / CPRA, and similar laws.
1. Current subprocessors
1.1 Infrastructure and hosting
| Subprocessor | Purpose | Location of processing | Transfer mechanism (if outside EEA / UK) |
|---|---|---|---|
| Amazon Web Services, Inc. | Application hosting, server infrastructure, database storage, encrypted backups | Atlanta, Georgia, USA (US-East region) | EU–US Data Privacy Framework + Standard Contractual Clauses + AWS Data Processing Addendum |
| Cloudflare, Inc. | Content delivery network, DDoS mitigation, DNS resolution, edge caching | Global edge network with US primary | EU–US Data Privacy Framework + Standard Contractual Clauses + Cloudflare DPA |
1.2 Payment processing
| Subprocessor | Purpose | Location of processing | Transfer mechanism (if outside EEA / UK) |
|---|---|---|---|
| Stripe, Inc. | Payment processing, billing, subscription management, fraud detection, Customer Portal | United States; Ireland (for EU customers) | EU–US Data Privacy Framework + Standard Contractual Clauses + Stripe Data Processing Agreement + UK International Data Transfer Addendum |
1.3 Advertising analytics and attribution
| Subprocessor | Purpose | Location of processing | Transfer mechanism (if outside EEA / UK) |
|---|---|---|---|
| Meta Platforms, Inc. | Server-side conversion attribution via the Meta Conversions API (hashed email + name, IP, UA, _fbp, _fbc) |
United States | EU–US Data Privacy Framework + Standard Contractual Clauses |
| Google LLC (Analytics 4 + Measurement Protocol) | Server-side conversion attribution and aggregate analytics (anonymous client_id, transaction value) |
United States; EU regions where elected | EU–US Data Privacy Framework + Google Cloud DPA + Standard Contractual Clauses |
1.4 Third-party AI providers
AI providers are engaged when you invoke an app or feature that calls them. They receive only the prompt and contextual data necessary to fulfil the specific request; they do not receive your dashboard activity, visitor IPs from your connected sites, or billing data.
| Subprocessor | Purpose | Location of processing | Transfer mechanism (if outside EEA / UK) |
|---|---|---|---|
| Google LLC (Gemini API) | Default AI provider for content optimisation, Capsule generation, Help Concierge, Sentinel rule proposals, AI Visibility Score, AI Forensics | United States; EU regions where elected | EU–US Data Privacy Framework + Standard Contractual Clauses + Google Cloud Data Processing Addendum |
| OpenAI, L.L.C. | Optional / alternate AI provider for content processing and Forensics probes | United States | EU–US Data Privacy Framework + Standard Contractual Clauses + OpenAI Data Processing Addendum |
| Anthropic, PBC | Optional / alternate AI provider for content processing and Forensics probes | United States | EU–US Data Privacy Framework + Standard Contractual Clauses + Anthropic Data Processing Addendum |
| Perplexity AI, Inc. | Optional / alternate AI provider for Forensics probes | United States | Standard Contractual Clauses + Perplexity Data Processing Addendum |
1.5 Operational tooling
| Subprocessor | Purpose | Location of processing | Transfer mechanism (if outside EEA / UK) |
|---|---|---|---|
| Amazon Web Services, Inc. (Amazon SES) | Delivery of account, billing, security, support, dunning, and marketing emails | United States | EU–US Data Privacy Framework + Standard Contractual Clauses + AWS DPA |
| Sentry, Inc. | Application monitoring, error reporting, performance telemetry | United States; EU regions where elected | EU–US Data Privacy Framework + Standard Contractual Clauses + Sentry DPA |
| CookieYes (Sahaj Software Solutions Limited) | Cookie-consent banner, consent log management, automatic cookie scanning | India + EU regions | Standard Contractual Clauses + CookieYes DPA |
2. Scope of processing per subprocessor
- Amazon Web Services (hosting) processes all categories of personal data because it hosts the systems on which the Services run. Data is encrypted at rest with AES-256 and in transit with TLS 1.3.
- Cloudflare processes only the metadata required to deliver edge caching and DDoS mitigation: IP addresses, request paths, HTTP headers, TLS fingerprints. Cloudflare does not see request bodies for HTTPS-terminated origin traffic.
- Stripe processes only the personal data necessary for payment: account identifiers, payment-method tokens, billing addresses, invoice records, and fraud-detection signals. Stripe does not receive content data, AI prompts, or visitor telemetry from connected websites.
- Meta and Google (advertising attribution) receive only the conversion-event payloads described in the Privacy Policy §9. They do not receive your dashboard activity, visitor data, or content.
- AI providers receive only the specific prompt and contextual data necessary to fulfil the request that invoked them. They do not receive your dashboard activity, visitor IPs from your connected sites, billing data, or other operational data.
- Amazon SES processes recipient email addresses, message subjects, and message bodies for delivery. Bounce and complaint feedback is retained for 90 days.
- Sentry processes error stack traces and operational telemetry. Personal data is filtered out at source where possible; the Sentry instance is configured with PII scrubbing.
- CookieYes processes consent choices, IP address, and timestamp for legal-evidence purposes.
3. Subprocessor selection and review
Before engaging a new subprocessor, we:
- Review the subprocessor's security posture, certifications (SOC 2, ISO 27001, etc.), and incident-response practices;
- Bind the subprocessor by written agreement to data-protection obligations no less protective than those in our Privacy Policy and Terms of Service;
- Where personal data is transferred outside the EEA, UK, or Switzerland, ensure that an appropriate transfer mechanism is in place;
- Maintain documentation of the basis on which we conduct the transfer impact assessment required under European law.
4. Notification of changes
We will update this page when we add, remove, or replace a subprocessor.
For customers who have entered a Data Processing Addendum with us that requires advance notification of subprocessor changes:
- We will provide at least thirty (30) days' notice before a new subprocessor begins processing personal data on our behalf, via email to the contact address on file and via a notice on this page;
- If you object to a new subprocessor on reasonable data-protection grounds, you may notify us within the notice window at support@aioxsuite.com; we will work in good faith to address your concerns.
5. Data Processing Addendum
A Data Processing Addendum incorporating the Standard Contractual Clauses and the UK International Data Transfer Addendum is available on request to support@aioxsuite.com.
6. Questions
For questions about this Subprocessor List, contact:
AIOX Suite
All inquiries: support@aioxsuite.com