Introduction
List of subprocessors with access to personal data. All bound by a Data Processing Agreement (DPA).
Changes
New subprocessor = email notification.
- 30 days prior notice for EU-based subprocessors
- 90 days prior notice for non-EU subprocessors
Right to object → contact+legal@mail.duale.ai
International Transfers
Transfers to the USA rely on SCCs and the DPF (Data Privacy Framework).
If the DPF is invalidated by the CJEU, transfers will continue via SCCs with supplementary measures (EDPB Recommendations 01/2020). Transfer Impact Assessments (TIAs) are documented for each US subprocessor.
Infrastructure and Hosting
Authentication and Security
AI Services
BYOK (Bring Your Own Key) Architecture: Customer connects their own API keys to AI model providers of their choice (OpenAI, Anthropic, Mistral, etc.).
Duale AI’s Role:
- Technical routing: Duale AI acts as subprocessor for API request routing
- Contextual memory: Prompts and results are stored for service-associated memory (continuous experience improvement)
- Strict isolation: Data never reused outside Customer context, not for training, not for statistics
- Location: Hetzner infrastructure, multiple EU datacenters (redundancy)
AI Provider Responsibility: Customer contracts directly with their AI provider for inference and must verify GDPR compliance of the model used (EDPB Opinion 28/2024 on processing of personal data in the context of AI models).
Payment and Billing
Note: Duale AI does not store credit card numbers. These are processed exclusively by Stripe, PCI-DSS Level 1 certified.
Communication and Support
Analytics and Monitoring
Duale AI does not use third-party analytics or monitoring services that collect personal data. Statistics and logs are generated internally on Hetzner infrastructure, on anonymized data.
EU AI Act Compliance
Duale AI qualifies as a deployer under the AI Regulation (EU) 2024/1689.
Obligation applicable since February 2, 2025:
- Staff training on AI literacy (Article 4)
Customer remains responsible for classifying their use cases (minimal, limited, high risk) and associated obligations.
Glossary
Contact
- Questions: contact+privacy@mail.duale.ai
- DPA request: contact+dpa@mail.duale.ai