Preferium AI Edge — Sub-processor list
Last updated: 2026-05-21 (R174).
Notification cadence: Material changes (additions, transfer-mechanism changes, primary-region changes) are emailed to every Customer admin/owner ≥ 30 days before the change takes effect, per DPA.md §5. Customers may object within 14 days; we work in good faith to reach a substitute solution or accept the objection.
This list catalogues every third party that processes personal data of Customer’s website visitors, Customer’s tenant users, or Customer-published content (which may contain personal data the Customer chose to publish). Required by GDPR Article 28(3) + SOC 2 CC9.2 + ISO 27001 A.15.
If you are a customer reviewing this for procurement, the canonical version is at https://trust.preferium.com/sub-processors post-R174 deploy. Until then, this file in the public repo is canonical.
A. Primary infrastructure
| Vendor | Service | Personal data processed | Primary region | Transfer mechanism | DPA link |
|---|
| Cloudflare, Inc. | Workers compute, KV cache, R2 object storage, DNS, AI Gateway, CDN | Visitor IP (truncated to /24), User-Agent, request path, optimized HTML payload, edge logs | US/EU (Workers run in 300+ datacenters) | EU SCCs (Module 2) + UK IDTA + EU-US Data Privacy Framework where US | cloudflare.com/cloudflare-customer-dpa |
| Supabase, Inc. | Managed Postgres + Auth + Storage. Project preferium-edge-prod (eu-west-1) | All Customer tenant data: users, domains, pages, optimizations, audit_logs, billing references | EU (Frankfurt, eu-west-1) | No third-country transfer — EU intra-region. Sub-processor: AWS (also EU intra-region) | supabase.com/legal/dpa |
| Cloudflare AI Gateway | LLM request proxying with cost-tracking + rate-limit | Routes through Cloudflare; original prompts (Customer-published HTML) + AI responses cached + logged for cost analytics | US/EU | EU SCCs (inherited from Cloudflare DPA) | cloudflare.com/cloudflare-customer-dpa |
B. LLM providers (for AI generation + citation tracking)
| Vendor | Service | Personal data processed | Primary region | Transfer mechanism | DPA link |
|---|
| Anthropic PBC | Claude Sonnet 4.6 (default generative model) | Customer-published HTML excerpt + AI-generated optimization | US | EU SCCs (via Cloudflare AI Gateway DPA) | anthropic.com/legal/dpa |
| OpenAI, LLC | ChatGPT API for LLM citation tracking (Phase 13) | Tracked queries (e.g., “best vet clinic in Oslo”) — no Customer-identifying metadata | US | EU SCCs (direct DPA) | openai.com/policies/dpa |
| Perplexity AI, Inc. | sonar-pro API for LLM citation tracking | Same as OpenAI row | US | EU SCCs | perplexity.ai/dpa (Enterprise tier) |
| Google LLC (Gemini) | Gemini API for LLM citation tracking | Same as OpenAI row | US | EU-US Data Privacy Framework + EU SCCs | cloud.google.com/terms/data-processing-addendum |
C. Google APIs (for SEO data integration)
| Vendor | Service | Personal data processed | Primary region | Transfer mechanism | DPA link |
|---|
| Google LLC (OAuth + APIs) | OAuth flow, Search Console, Analytics, PageSpeed Insights, Knowledge Graph | Tenant user email, OAuth tokens (encrypted at rest), GSC + GA4 metrics on Customer’s site | US | EU-US Data Privacy Framework + EU SCCs | cloud.google.com/terms/data-processing-addendum |
D. Billing + email
| Vendor | Service | Personal data processed | Primary region | Transfer mechanism | DPA link |
|---|
| Stripe Payments Europe Ltd. | Subscription billing, customer portal, Checkout, webhooks | Email, name, Stripe customer ID, plan tier, payment method (held by Stripe — we never see card data) | EU (Dublin) | No third-country transfer | stripe.com/legal/dpa |
| Resend, Inc. | Transactional email (invitations, notifications, password resets) | Email, name, message content | US (with EU pop) | EU SCCs | resend.com/legal/dpa |
E. SEO data
| Vendor | Service | Personal data processed | Primary region | Transfer mechanism | DPA link |
|---|
| DataForSEO LLC | Keywords, SERP, Backlinks v3, Competitor data | Query terms (e.g., “best vet clinic in Oslo”) — no Customer identifying data, no end-user data | EU (Vilnius) | No third-country transfer | dataforseo.com/dpa |
F. Observability + status
| Vendor | Service | Personal data processed | Primary region | Transfer mechanism | DPA link |
|---|
| Sentry, Inc. | Application error monitoring (api + edge + dashboard) | Stack traces. PII scrubbing enabled on transport (no request bodies stored, IPs masked). | US/EU | EU SCCs (EU pop enabled per Sentry DPA) | sentry.io/legal/dpa |
| Better Stack Inc. | Uptime monitoring + hosted status page (status.preferium.com) | Status-page subscriber email (opt-in) | US (with EU pop) | EU SCCs | betterstack.com/legal/dpa |
G. Support + analytics (minimal-PII)
| Vendor | Service | Personal data processed | Primary region | Transfer mechanism | DPA link |
|---|
| Cloudflare Web Analytics | Page-view + bounce rate on app.preferium.com dashboard | None — cookieless, no IPs stored | Inherited from Cloudflare | Inherited | cloudflare.com/cloudflare-customer-dpa |
Customer-support correspondence inbox (post@preferium.com) is hosted on Robert’s personal email infrastructure pending Q3 2026 migration to a managed B2B mailbox (likely Microsoft 365 or Resend Inbox). Not technically a sub-processor; documented here for transparency.
H. Pending evaluations / candidate vendors
These services are mentioned in docs/MASTERPLAN.md or enterprise-readiness.md as planned integrations but are NOT yet active sub-processors. They will be added to the active list with proper 30-day Customer notice when they go live.
| Vendor | Planned service | Round when activated | Status |
|---|
| Anthropic PBC | Direct DPA without AI Gateway (today routed via CF) | Not planned | Routing via AI Gateway acceptable for v1 |
| Resend, Inc. (Inbox) | Replace post@preferium.com Robert-hosted mailbox | Q3 2026 | Pending procurement |
| Vanta or Drata | SOC 2 evidence collection (R170+) | R170-R200 | Not yet contracted |
| External pen-test firm | First annual pen-test (~$8-15k) | R174 | Vendor selection 2026-06 |
I. Change-notification process
Per DPA.md §5:
- Detect change — adding/removing a sub-processor, changing region, or changing transfer mechanism.
- Update this file + bump the “Last updated” header. Commit as
docs(sub-processors): <vendor>: <change>.
- Notify Customers via email to every tenant owner/admin AND post to
trust.preferium.com/sub-processors-changelog. Notification ≥ 30 days before effective date.
- Receive objections during the 14-day window (Customer emails
dpo@preferium.com).
- Resolution path — if objection cannot be resolved (e.g., we cannot deliver Service without the new sub-processor), Customer can terminate Service per DPA.md §11 with pro-rated refund.
J. Change log
| Date | Round | Change |
|---|
| 2026-05-21 | R174 | Initial publication. Catalogued 11 active sub-processors. 4 pending. Aligned with DPA.md §5 + gdpr-article-30-records.md §C. |