This list names every subprocessor that may process Customer Data in the
Suunta.ai service. The Customer grants general authorization to these
subprocessors under section 6.1 of our
Data Processing Agreement. We notify Customers at
least 30 days before a new subprocessor is taken into use, and Customers may
object on reasonable data protection grounds (DPA section 6.3 and 6.4).
Infrastructure and Hosting
| Subprocessor | Purpose | Location | Data Processed |
| Amazon Web Services (AWS) | Application hosting, PostgreSQL database including the vector index, S3 object storage, KMS key management, backups, operational logs | EU (Stockholm, eu-north-1) | All Customer Data |
AI Processing
| Subprocessor | Purpose | Location | Data Processed | Retention |
| Anthropic | AI analysis (Claude). Default provider. | USA | Prompt, selected context, user first and last name | No training on API data per provider terms |
| OpenAI | AI analysis (GPT) and text embeddings for document search | USA | Prompt, selected context, document text passages to be embedded | Zero Data Retention agreement in place* |
| Google | AI analysis (Gemini) | USA by default** | Prompt, selected context | Per provider terms |
| Mistral AI | AI analysis | EU (France) | Prompt, selected context | Per provider terms |
| Voyage AI | Reranking of document search results. Optional component; active only when configured. | USA | Search query and candidate document passages | Per provider terms |
*Suunta.ai has a separately agreed Zero Data Retention arrangement with OpenAI,
under which API inputs and outputs are not retained by the provider. In addition,
store=False is set in application code on every OpenAI API call, and
model improvement is disabled at the organization account level.
**Google AI calls are routed to the Gemini Developer API (USA) in the default
configuration. The service also supports Vertex AI in the EU region
(europe-north1); that routing is not enabled by default. We state the
configuration in effect rather than the option that is available.
We do not use Customer Data to train, fine-tune or improve AI models, and we do not
permit subprocessors to do so (DPA section 5.2). Prompts and responses are not
written to our own logs; only usage metadata such as model name, token counts,
latency and cost is recorded.
Product Analytics
| Subprocessor | Purpose | Location | Data Processed |
| PostHog | Product usage analytics | EU (PostHog EU Cloud) | Pseudonymous user and organization identifiers, product usage events, organization-level metadata such as plan, seat count, country and language. No organization names, no strategy, chat or document content, no message bodies. |
Integration Infrastructure
| Subprocessor | Purpose | Location | Data Processed |
| Nango | OAuth handling and token storage for long-tail (Tier 2) connectors. Core connectors run on our own EU infrastructure and do not use Nango. | USA (AWS us-west-2). Transfers rely on the EU-US Data Privacy Framework and on Standard Contractual Clauses under Nango's DPA. | OAuth tokens for connected third-party accounts, and, where a sync connector is used, a temporary cache of records retrieved from that third-party system. |
Payments and Billing
| Subprocessor | Purpose | Location | Data Processed |
| Stripe | Payment processing | USA/EU | Email, name, billing metadata |
Communications
| Subprocessor | Purpose | Location | Data Processed |
| Resend | Transactional email | EU | Email address, message content |
Customer-Initiated Integrations
The following are enabled only when the Customer explicitly connects them:
| Subprocessor | Purpose | Location | Data Processed |
| Slack | Workspace integration | USA | Messages, user IDs (as configured) |
| Microsoft Teams | Workspace integration | USA/EU (per the Customer's Microsoft 365 tenant) | Messages, user IDs (as configured) |
| Google Workspace | Calendar, Sheets sync | USA/EU | Calendar events, sheet data (as configured) |
| Zapier | Automation webhooks | USA | Webhook payloads (as configured) |
| Third-party connectors | Any additional system the Customer connects (for example HubSpot, Notion, GitHub, Salesforce) | Per the provider of that system | Only the data covered by the access scopes the Customer grants |
Conditional Services
The following are listed in advance under DPA section 6.3. They are not enabled in
the service today, and we will notify Customers before activating them.
| Subprocessor | Purpose | Location | Data Processed |
| Cloudflare (Turnstile) or Google (reCAPTCHA) | Bot and abuse protection on sign-up forms | USA/EU | IP address and browser signals of the person completing the challenge |
| Salesforce (Suunta.ai's own CRM) | Account and license administration on our side. This is separate from a Salesforce connector that a Customer may connect themselves. | Per the region of our Salesforce instance | Organization-level account metadata and the name and email address of the Customer's business contacts |
Contact
For subprocessor inquiries: privacy@suunta.ai
Document Version: 1.1 | Y4 Works Oy (Suunta.ai)