We are live · Workspace and Law pricing available
Optimaite
Trust Center
Annex to DPA

Subprocessors

Complete list of all subprocessors pursuant to Art. 28(2) GDPR that process personal data within the Optimaite platform.

As of: March 5, 2026 · Changes are communicated in advance pursuant to § 7 DPA.

H

Hetzner Cloud

Hetzner Online GmbH

Purpose

Cloud infrastructure, Kubernetes cluster, S3-compatible object storage, self-hosted PostgreSQL database (CloudNativePG)

Processed Data

All application data (documents, user data, metadata)

Falkenstein / Nürnberg, Germany
Website

Guarantees

DPAISO 27001GDPR-compliant
Z

Zilliz Cloud

Zilliz Inc.

Purpose

Vector database (embeddings for document search)

Processed Data

Vector embeddings of document content (no plaintext documents)

EU (Frankfurt, AWS eu-central-1)
Website

Guarantees

DPAEU Standard Contractual ClausesEU data region
A

Azure AI Foundry

Microsoft Ireland Operations Limited

Purpose

AI model API for text processing, document analysis, and generation

Processed Data

Document contents and user queries (processing only, no storage)

EU (Germany West)
Website

Guarantees

DPAISO 27001Zero-RetentionEU data residency
A

AWS Bedrock

Amazon Web Services EMEA SARL

Purpose

AI model API (Claude) for text processing and reasoning

Processed Data

Document contents and user queries (processing only, no storage)

EU (Frankfurt)
Website

Guarantees

DPAISO 27001Zero-RetentionEU data residency
G

Google Cloud (Vertex AI & Speech-to-Text)

Google Ireland Limited

Purpose

AI inference (Vertex AI / Gemini) and speech recognition (Speech-to-Text)

Processed Data

Document content and speech/text requests (processing only, no storage)

EU (europe-west, EU endpoint)
Website

Guarantees

DPAISO 27001SOC 2EU data region
V

Vercel

Vercel Inc.

Purpose

Website hosting, Edge Functions, CDN

Processed Data

Website requests, IP addresses, performance metrics

EU regions (Frankfurt)
Website

Guarantees

DPASOC 2 Type IIEU data region
S

Stripe

Stripe Payments Europe Ltd.

Purpose

Payment processing and invoicing

Processed Data

Invoice data, payment information, email addresses

Ireland, EU
Website

Guarantees

DPAPCI DSS Level 1SOC 2 Type II
M

Mailgun

Mailgun Technologies Inc.

Purpose

Transactional email delivery (notifications, invitations)

Processed Data

Email addresses, message contents, delivery logs

EU (data region)
Website

Guarantees

DPASOC 2 Type IIEU data residency
S

Sentry

Functional Software Inc.

Purpose

Error monitoring, performance monitoring, crash reporting

Processed Data

Error logs, stack traces, device information (pseudonymized)

EU (data region)
Website

Guarantees

DPASOC 2 Type IIEU data residency
L

LangSmith

LangChain Inc.

Purpose

AI observability, tracing, and quality assurance of LLM calls

Processed Data

AI requests and responses (pseudonymized), latency and error data

EU (eu.smith.langchain.com)
Website

Guarantees

DPASOC 2 Type IIEU SCCs

Notes on Data Processing by AI Providers

The AI services (Microsoft Azure AI Foundry, AWS Bedrock, Google Vertex AI) process document content within EU data centres to answer API requests. Contractual zero-retention agreements are in place: input data is discarded immediately after processing and is neither stored nor used to train models.

AI processing takes place in EU data centres (Azure Germany West, AWS Frankfurt, Google Vertex AI EU). Where a participating provider has a third-country connection, the processing is safeguarded by an adequacy decision or appropriate safeguards under Art. 46 GDPR, in particular EU Standard Contractual Clauses.

Customers have the option to use their own API keys and thus control the processing chain themselves.