Draft — not legal advice, and not in force
This document has not been reviewed by counsel and has no effective date. It is published here for internal review only and is excluded from search indexing.
Sub-processors
Diaphora engages a small number of third parties to help run the hosted platform. This page lists them, what each one does, and where it processes data. It is referenced by the Data Processing Addendum and forms Annex III of the Standard Contractual Clauses.
Draft — not yet in force. This document has not been reviewed by counsel and carries no effective date. The vendors below are correct, but the contracting entities, regions and remaining rows still need confirmation before publication.
Current sub-processors
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Google LLC — Google Cloud Platform | Platform hosting, compute, storage and networking | All Customer Content | [NEEDS INPUT: GCP region(s), e.g. us-central1] |
| Google LLC — managed PostgreSQL on GCP | Primary database — plans, results history, workspace and account records | Customer Content, account data | Same region as above |
| Stripe, Inc. | Subscription billing, payment processing, invoicing and overage charges | Billing contact, payment method token, invoice records — no full card numbers reach Diaphora | United States |
| Intuit Inc. — Mailchimp | Transactional email: account, security, billing and overage notifications | Name, email address, message contents | United States |
| [NEEDS INPUT: error monitoring, if any] | Crash and error reporting | Diagnostic data, which may incidentally include Customer Content in stack traces | [region] |
| [NEEDS INPUT: support tooling, if any] | Support ticketing and correspondence | Name, email, ticket contents | [region] |
| [NEEDS INPUT: analytics, if any] | Product and marketing analytics | Usage events, IP address | [region] |
Three things on this table need resolving before it is published:
The Google contracting entity depends on your customers. Google Cloud is contracted through Google LLC (US) by default, but customers with EEA or UK data-protection requirements are usually served by Google Cloud EMEA Limited (Ireland). Which entity appears here determines how the transfer analysis in the DPA reads. Confirm which one you contract with, and name the region.
Stripe and Mailchimp are both US-based, so both involve a transfer out of the EEA and UK for European customers. Both publish their own DPAs and SCCs; those need to be executed and on file, since section 6 of our DPA commits us to imposing obligations no less protective than our own.
Confirm which Mailchimp product this is. Mailchimp Transactional (formerly Mandrill) is the correct product for account, security and billing email. Standard Mailchimp is a marketing platform, and sending transactional mail through a marketing tool mixes two consent regimes — marketing consent is withdrawable, whereas security and billing notices are contractually necessary and must still be delivered to someone who has unsubscribed. If transactional and marketing mail share one Mailchimp audience, that needs separating regardless of what this page says.
Error monitoring is the row most likely to be wrong in practice. Stack traces and crash payloads routinely capture fragments of whatever was being processed at the moment of failure. If you run any error monitor and it is not configured to scrub Customer Content and Vault material, it is processing more than this table admits. If you run none, delete the row.
Why LLM providers are not on this list
Anthropic, OpenAI, Google and any other model provider your plans call are not Diaphora sub-processors, and this is a deliberate consequence of the bring-your-own-keys design.
You supply your own API keys. Your plans call those providers under your account, on your contract, at your cost — Diaphora takes no markup on tokens and has no commercial relationship with the provider on your behalf. We are not engaging them to process your data; you are.
What follows from that:
- Their terms, privacy policy and data-retention and training settings apply to your prompts and completions — not ours.
- Whether your data can be used to train their models is a setting in your account with them. We cannot change it for you and cannot see what you have chosen.
- If you need a DPA covering prompts sent to a model provider, you need it from that provider, not from us.
- Adding or switching model providers is your decision and does not require notice from us.
Prompts and completions do pass through the Diaphora platform in transit and are stored in your results history for the retention period your plan provides. That processing is covered by our DPA and the sub-processors listed above.
Google appears here in two unrelated roles — don't conflate them
This trips up almost everyone reviewing the page, so it is worth stating directly.
Google as our hosting provider is a sub-processor. We run the platform on Google Cloud Platform and store Customer Content in managed PostgreSQL there. That is our commercial relationship, our contract, and our responsibility — which is why Google appears in the table above.
Google as a model provider is not. If you configure a Gemini API key in your Vault, your plans call Google's model APIs under your Google account on your contract. We are not engaging Google for that processing and take no markup on it. It is governed by your agreement with Google, not ours.
The same company, two entirely separate relationships, with different contracting entities and different terms. A prompt your plan sends to Gemini is covered by your Google agreement; the database row storing that prompt in your results history is covered by ours.
Systems your plans connect to
The same reasoning applies to everything else your automations touch — MCP servers, databases, file servers and APIs. You choose them, you hold the credentials, and you control what your plans send. They are not our sub-processors.
Changes
We give at least 30 days' notice before adding or replacing a sub-processor. Notice goes to the workspace billing contact by email, and this page is updated at the same time.
Customers with a DPA in place may object on reasonable data-protection grounds during the notice period, under section 6 of the DPA.
[NEEDS INPUT: consider offering a subscribe-to-changes mechanism. Enterprise buyers frequently require notification by a means other than "check the page periodically", and some DPAs make it a condition.]
Contact
Questions about this list: hello@diaphora.ai
The third parties that process customer content on Diaphora's behalf, why each one is engaged, and why the LLM providers your plans call are deliberately not on this list.