Legal

Sub-processors.

The third-party services Elennai (operated by ElennAI ApS, VAT: DK46697146) uses to deliver the platform. Our Data Processing Agreement references this list. Pro and Scale customers get 30 days notice by email before a new sub-processor is added.

Active sub-processors

ProviderPurposeLocationData accessedTransfer mechanism
RailwayApplication + database hosting, first-party error tracking, and product-analytics event storage (Postgres). Object-storage migration target.europe-west4 (Eemshaven, NL)All operational data, first-party product-analytics + error eventsEU/EEA - none required
Cloudflare R2Object storage for uploaded documents + file metadata (migration to Railway Buckets in progress)EU jurisdictionUploaded documents + file metadataCloudflare DPA (EU jurisdiction)
Google Cloud (Vertex AI)Google, a US-headquartered group; contracting entity to be confirmedProcessor acting on our instructions: generates the assistant's answers, and turns the content you give it into the searchable form the assistant reads fromeurope-west4 (Eemshaven, NL)The visitor's message and the passages of your own content selected to answer it. The text of the content you upload or connect. No visitor message and no account identity.Processed in the EU under Google's data processing terms. No transfer out of the EEA for this processing.
StripeStripe, a US-headquartered group; contracting entity to be confirmedBilling (payments, invoices, webhooks)US (with EU operations)Customer email, plan code, payment-method metadataStripe's data processing agreement and the EU Standard Contractual Clauses
ResendTransactional email (welcome, password reset, newsletter)EU (eu-west-1)Recipient email, message bodyEU/EEA - none required
Managed RedisoptionalCache + cross-replica rate-limit state (when enabled)EU regionCache keys + counters (no document content)EU/EEA - none required

Where these companies sit

Your workspace, your documents and your conversations are processed in the EU. Two of the companies involved belong to groups headquartered in the United States: Google, which runs the models, and Stripe, which handles payments. Every one of them is bound by a data processing agreement with us. Railway, Cloudflare R2, Google Cloud (Vertex AI), Resend and Managed Redis process inside the EEA, so no transfer out of it happens for that work. Stripe does involve a transfer out of the EEA, and that rests on the EU Standard Contractual Clauses. Where each one processes is in the Location column above.

Here is the part a list like this usually leaves out. A company in a US-headquartered group can be ordered by a US authority to hand over data it holds, wherever in the world it holds it. That is US law, it reaches every such provider in this industry, and no contract we sign makes it go away. We have not received such an order. If we ever do, we will challenge it where we can and tell you unless the order forbids it.

What we can control, we do. When it generates the assistant's answers, it is sent the visitor's message and the passages of your own content selected to answer it. When it turns the content you give it into the searchable form the assistant reads from, it is sent the text of the content you upload or connect. No visitor message and no account identity. It is never sent your customer records, and neither is anyone else. Google's terms for this service govern what it may do with what it receives, and we will publish the applicable clause here. Stripe is sent an email address and a plan, never a conversation. If you want none of this at all, the honest answer is that we cannot offer an EU-owned model provider today, and you should weigh that before you sign.

What stays in-house

  • Postgres + pgvector runs on Railway in the same EU region as the application - not a separate sub-processor.
  • Preparing your content for search is done by Google, listed above, and not by a separate vendor. It moved into the same EU region as the answers on 4 September 2026. One thing we will not overstate: material prepared before that date was handled by a Google service outside the EU region. It has always been stored in the EU, it is still correct, and we did not redo it, because redoing it would have produced the same result.
  • Product analytics, when enabled, is a first-party address on our own API that writes into the same Railway EU Postgres as the rest of the application. No third-party analytics vendor is engaged and no separate analytics infrastructure exists - it is an expanded purpose of existing infrastructure, not a new sub-processor.
  • Visitor country and organisation are derived on our own servers: the country from an offline database that ships with the application, and the organisation from the public registry that publishes which organisation a network range is registered to. The registry is asked about a network block (a /24 or /48), never about a visitor's address, never about who they are, and never about which site they were on - and the answer is the registration record that registry publishes to anyone who asks. Querying a public register is not a sub-processing relationship: nobody processes personal data on our instructions, and no visitor data is disclosed to anyone. We deliberately do not use a commercial IP-to-company service, which is what would put a new row in the table above.
  • Slack channel traffic flows through the customer's own Slack workspace, where the customer is the data controller; Slack is not Elennai's sub-processor for that.

Changes and the DPA

When a sub-processor is added, Pro and Scale customers receive 30 days notice by email and can object before the new processor goes live. Free, Starter, and Growth customers see the change reflected on this page.

Today all data is hosted in the EU region. As additional data regions launch, this page will show the sub-processor list for each region. To request the Data Processing Agreement, write to support@elenn.ai.