Introduction

List of Subprocessors

List of personal data subprocessors used by Duale AI.

Introduction

List of subprocessors with access to personal data. All bound by a Data Processing Agreement (DPA).

Changes

New subprocessor = email notification.

  • 30 days prior notice for EU-based subprocessors
  • 90 days prior notice for non-EU subprocessors

Right to object → contact+legal@mail.duale.ai

International Transfers

Transfers to the USA rely on SCCs and the DPF (Data Privacy Framework).

If the DPF is invalidated by the CJEU, transfers will continue via SCCs with supplementary measures (EDPB Recommendations 01/2020). Transfer Impact Assessments (TIAs) are documented for each US subprocessor.

Infrastructure and Hosting

SubprocessorFunctionData ProcessedLocationTransfer Safeguards
Hetzner Online GmbHInfrastructure hostingAll platform dataGermanyN/A (EU)
GitHub, Inc.Website hostingAccess logs (IP, UA)USASCCs + DPF
Cloudflare, Inc.CDN, DDoS protectionNavigation data, IPUSA / EUSCCs + DPF

Authentication and Security

SubprocessorFunctionData ProcessedLocationTransfer Safeguards
Auth0 (Okta)Authentication, SSOEmail, name, credentialsUSASCCs + DPF
Cloudflare, Inc.WAF, attack protectionConnection logs, IPUSA / EUSCCs + DPF

AI Services

BYOK (Bring Your Own Key) Architecture: Customer connects their own API keys to AI model providers of their choice (OpenAI, Anthropic, Mistral, etc.).

SubprocessorFunctionData ProcessedLocationTransfer Safeguards
Duale AIRouting, contextual memoryPrompts, results, metadataEUN/A (EU)
VariableLLM inferencePrompts, resultsVariablePer chosen provider

Duale AI’s Role:

  • Technical routing: Duale AI acts as subprocessor for API request routing
  • Contextual memory: Prompts and results are stored for service-associated memory (continuous experience improvement)
  • Strict isolation: Data never reused outside Customer context, not for training, not for statistics
  • Location: Hetzner infrastructure, multiple EU datacenters (redundancy)

AI Provider Responsibility: Customer contracts directly with their AI provider for inference and must verify GDPR compliance of the model used (EDPB Opinion 28/2024 on processing of personal data in the context of AI models).

Payment and Billing

SubprocessorFunctionData ProcessedLocationTransfer Safeguards
Stripe Payments Europe, Ltd.Payment processingBanking data, emailIreland / USASCCs + DPF

Note: Duale AI does not store credit card numbers. These are processed exclusively by Stripe, PCI-DSS Level 1 certified.

Communication and Support

SubprocessorFunctionData ProcessedLocationTransfer Safeguards
Crisp IM SASCustomer support, chatEmail, name, ticket contentEU (Netherlands / Germany)N/A (EU)

Analytics and Monitoring

Duale AI does not use third-party analytics or monitoring services that collect personal data. Statistics and logs are generated internally on Hetzner infrastructure, on anonymized data.

EU AI Act Compliance

Duale AI qualifies as a deployer under the AI Regulation (EU) 2024/1689.

Obligation applicable since February 2, 2025:

  • Staff training on AI literacy (Article 4)

Customer remains responsible for classifying their use cases (minimal, limited, high risk) and associated obligations.

Glossary

AcronymMeaning
BYOKBring Your Own Key (API key provided by Customer)
CJEUCourt of Justice of the European Union
DPAData Processing Agreement
DPFData Privacy Framework (EU-USA, adequacy decision 2023)
EDPBEuropean Data Protection Board
GDPRGeneral Data Protection Regulation
SCCsStandard Contractual Clauses (transfers outside EU)
TIATransfer Impact Assessment
N/A (EU)No transfer outside EU

Contact