Sub-Processor List
AICA uses the following sub-processors to provide its services. This list is maintained pursuant to GDPR Article 28(2) and our Data Processing Agreement with customers.
Customers are notified at least 30 days in advance of any new sub-processor being added, and may object in accordance with the DPA.
Audio Processing (ASR)
| # | Provider | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|---|
| 1 | Deepgram | Speech-to-text transcription | Audio recordings (voice data) | US | SCCs |
| 2 | ElevenLabs | Speech-to-text transcription (Scribe v1) | Audio recordings (voice data) | US | EU-US DPF + SCCs fallback |
Data sensitivity: HIGH — Audio recordings contain voice data (potential biometric data). Each tenant is configured to use one ASR provider only.
AI Analysis (LLM)
| # | Provider | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|---|
| 3 | OpenRouter | LLM routing gateway | Transcripts (with PII redaction) | US | SCCs |
Downstream models via OpenRouter: OpenAI (GPT-4), Anthropic (Claude). PII redaction is applied before transmission.
Authentication
| # | Provider | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|---|
| 4 | Clerk | User authentication and session management | User accounts (name, email), sessions, login events | US | EU-US DPF + SCCs fallback |
Data sensitivity: MEDIUM — No call content or transcripts. Only user account data.
Data Storage
| # | Provider | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|---|
| 5 | Neon | Primary database (PostgreSQL) | Transcripts, AI analyses, metadata, user data | US (configurable) | EU-US DPF + SCCs fallback |
| 6 | Cloudflare | Infrastructure: R2 (audio storage), D1 (edge metadata), Workers (compute) | Audio files (R2), metadata (D1), all data in transit | Global (edge) | Cloudflare DPA + SCCs |
Communications
| # | Provider | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|---|
| 7 | Resend | Email delivery (notifications, alerts) | Email addresses, delivery metadata. No call content. | US | EU-US DPF + SCCs fallback |
Data sensitivity: LOW — Only delivery metadata.
Observability
| # | Provider | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|---|
| 8 | Langfuse | LLM observability (traces, cost tracking) | LLM traces, token counts, latency. No raw transcripts. | EU (Germany) | Not required (EU→EU) |
Data sensitivity: LOW — Operational traces only. No PII, no call content.
Summary
| # | Provider | Data Risk | Location |
|---|---|---|---|
| 1 | Deepgram | HIGH (audio) | US |
| 2 | ElevenLabs | HIGH (audio) | US |
| 3 | OpenRouter | HIGH (transcripts) | US |
| 4 | Clerk | MEDIUM (accounts) | US |
| 5 | Neon | HIGH (all data) | US |
| 6 | Cloudflare | HIGH (audio + metadata) | Global |
| 7 | Resend | LOW (metadata) | US |
| 8 | Langfuse | LOW (traces) | EU |
Not Sub-Processors
| Integration | Why Not a Sub-Processor |
|---|---|
| Bitrix24 | Customer's own CRM. AICA sends data to Customer-configured webhook URL on Customer's instruction. Bitrix24 is the Customer's processor, not AICA's sub-processor. |
| n8n | Self-hosted by tenant. AICA sends webhook to tenant-provided URL. n8n processes data under tenant's control. |
Change Notification Policy
- New sub-processor: Customers notified via email at least 30 days before processing begins
- Objection right: Customers may object within the 30-day notice period
- Removal: If objection cannot be resolved, customer may terminate the affected service
- Updates: Published at this URL and in the AICA documentation
Contact
For questions about sub-processors or data processing:
Auspex Streamline S.L.
C.I.F.: B56341829
Calle Velarde 13, 4B
35010 Las Palmas de Gran Canaria
Canarias, Spain
Email: privacy@auspex.company
Document ID: SPL-AICA-2026-001 · Version: 1.1