Optimaite Logo
Trust Center
Annex to DPA

Subprocessors

Complete list of all subprocessors pursuant to Art. 28(2) GDPR that process personal data within the Optimaite platform.

As of: March 5, 2026 · Changes are communicated in advance pursuant to § 7 DPA.

H

Hetzner Cloud

Hetzner Online GmbH

Purpose

Cloud infrastructure, Kubernetes cluster, S3-compatible object storage

Processed Data

All application data (documents, user data, metadata)

Falkenstein / Frankfurt, Germany
Website

Guarantees

DPAISO 27001GDPR-compliant
N

Neon

Neon Inc.

Purpose

Serverless PostgreSQL database (primary application database)

Processed Data

Structured application data (user accounts, document metadata, configurations)

Frankfurt, EU
Website

Guarantees

DPASOC 2 Type IIEU data region
A

Azure AI Foundry

Microsoft Ireland Operations Limited

Purpose

AI model API for text processing, document analysis, and generation

Processed Data

Document contents and user queries (processing only, no storage)

EU (Germany West)
Website

Guarantees

DPAISO 27001Zero-RetentionEU data residency
A

AWS Bedrock

Amazon Web Services EMEA SARL

Purpose

AI model API (Claude) for text processing and reasoning

Processed Data

Document contents and user queries (processing only, no storage)

EU (Frankfurt)
Website

Guarantees

DPAISO 27001Zero-RetentionEU data residency
G

Google Cloud (Vertex AI)

Google Ireland Limited

Purpose

OCR and document recognition (Document AI)

Processed Data

Document images and scanned PDFs (processing only, no storage)

EU (Frankfurt)
Website

Guarantees

DPAISO 27001SOC 2EU data region
V

Vercel

Vercel Inc.

Purpose

Website hosting, Edge Functions, CDN

Processed Data

Website requests, IP addresses, performance metrics

EU regions (Frankfurt)
Website

Guarantees

DPASOC 2 Type IIEU data region
S

Stripe

Stripe Payments Europe Ltd.

Purpose

Payment processing and invoicing

Processed Data

Invoice data, payment information, email addresses

Ireland, EU
Website

Guarantees

DPAPCI DSS Level 1SOC 2 Type II
M

Mailgun

Mailgun Technologies Inc.

Purpose

Transactional email delivery (notifications, invitations)

Processed Data

Email addresses, message contents, delivery logs

EU (data region)
Website

Guarantees

DPASOC 2 Type IIEU data residency
S

Sentry

Functional Software Inc.

Purpose

Error monitoring, performance monitoring, crash reporting

Processed Data

Error logs, stack traces, device information (pseudonymized)

EU (data region)
Website

Guarantees

DPASOC 2 Type IIEU data residency
L

LangSmith

LangChain Inc.

Purpose

AI observability, tracing, and quality assurance of LLM calls

Processed Data

AI requests and responses (pseudonymized), latency and error data

EU (eu.smith.langchain.com)
Website

Guarantees

DPASOC 2 Type IIEU SCCs

Notes on Data Processing by AI Providers

The AI services (Azure AI Foundry, AWS Bedrock) process document contents exclusively within the EU to answer API requests. Contractual zero-retention agreements are in place: input data is immediately discarded after processing and is neither stored nor used for model training.

All AI processing takes place in EU data centers (Azure Germany West, AWS Frankfurt). No data transfers to third countries occur as part of AI processing.

Customers have the option to use their own API keys and thus control the processing chain themselves.

Trust Center | Optimaite