Suunta.ai
Terms Privacy DPA Subprocessors

Authorized Subprocessors

Last Updated: 18 August 2026
GDPR ZDR

This list names every subprocessor that may process Customer Data in the Suunta.ai service. The Customer grants general authorization to these subprocessors under section 6.1 of our Data Processing Agreement. We notify Customers at least 30 days before a new subprocessor is taken into use, and Customers may object on reasonable data protection grounds (DPA section 6.3 and 6.4).

Infrastructure and Hosting

SubprocessorPurposeLocationData Processed
Amazon Web Services (AWS)Application hosting, PostgreSQL database including the vector index, S3 object storage, KMS key management, backups, operational logsEU (Stockholm, eu-north-1)All Customer Data

AI Processing

SubprocessorPurposeLocationData ProcessedRetention
AnthropicAI analysis (Claude). Default provider.USAPrompt, selected context, user first and last nameNo training on API data per provider terms
OpenAIAI analysis (GPT) and text embeddings for document searchUSAPrompt, selected context, document text passages to be embeddedZero Data Retention agreement in place*
GoogleAI analysis (Gemini)USA by default**Prompt, selected contextPer provider terms
Mistral AIAI analysisEU (France)Prompt, selected contextPer provider terms
Voyage AIReranking of document search results. Optional component; active only when configured.USASearch query and candidate document passagesPer provider terms

*Suunta.ai has a separately agreed Zero Data Retention arrangement with OpenAI, under which API inputs and outputs are not retained by the provider. In addition, store=False is set in application code on every OpenAI API call, and model improvement is disabled at the organization account level.

**Google AI calls are routed to the Gemini Developer API (USA) in the default configuration. The service also supports Vertex AI in the EU region (europe-north1); that routing is not enabled by default. We state the configuration in effect rather than the option that is available.

We do not use Customer Data to train, fine-tune or improve AI models, and we do not permit subprocessors to do so (DPA section 5.2). Prompts and responses are not written to our own logs; only usage metadata such as model name, token counts, latency and cost is recorded.

Product Analytics

SubprocessorPurposeLocationData Processed
PostHogProduct usage analyticsEU (PostHog EU Cloud)Pseudonymous user and organization identifiers, product usage events, organization-level metadata such as plan, seat count, country and language. No organization names, no strategy, chat or document content, no message bodies.

Integration Infrastructure

SubprocessorPurposeLocationData Processed
NangoOAuth handling and token storage for long-tail (Tier 2) connectors. Core connectors run on our own EU infrastructure and do not use Nango.USA (AWS us-west-2). Transfers rely on the EU-US Data Privacy Framework and on Standard Contractual Clauses under Nango's DPA.OAuth tokens for connected third-party accounts, and, where a sync connector is used, a temporary cache of records retrieved from that third-party system.

Payments and Billing

SubprocessorPurposeLocationData Processed
StripePayment processingUSA/EUEmail, name, billing metadata

Communications

SubprocessorPurposeLocationData Processed
ResendTransactional emailEUEmail address, message content

Customer-Initiated Integrations

The following are enabled only when the Customer explicitly connects them:

SubprocessorPurposeLocationData Processed
SlackWorkspace integrationUSAMessages, user IDs (as configured)
Microsoft TeamsWorkspace integrationUSA/EU (per the Customer's Microsoft 365 tenant)Messages, user IDs (as configured)
Google WorkspaceCalendar, Sheets syncUSA/EUCalendar events, sheet data (as configured)
ZapierAutomation webhooksUSAWebhook payloads (as configured)
Third-party connectorsAny additional system the Customer connects (for example HubSpot, Notion, GitHub, Salesforce)Per the provider of that systemOnly the data covered by the access scopes the Customer grants

Conditional Services

The following are listed in advance under DPA section 6.3. They are not enabled in the service today, and we will notify Customers before activating them.

SubprocessorPurposeLocationData Processed
Cloudflare (Turnstile) or Google (reCAPTCHA)Bot and abuse protection on sign-up formsUSA/EUIP address and browser signals of the person completing the challenge
Salesforce (Suunta.ai's own CRM)Account and license administration on our side. This is separate from a Salesforce connector that a Customer may connect themselves.Per the region of our Salesforce instanceOrganization-level account metadata and the name and email address of the Customer's business contacts

Contact

For subprocessor inquiries: privacy@suunta.ai

Document Version: 1.1 | Y4 Works Oy (Suunta.ai)

Contents