Subprocessors List
1. Notice and objection
ENTIA will give at least 30 days' notice before adding or replacing a subprocessor that will process Customer Personal Data. The customer may object on reasonable data-protection grounds during the period stated in the DPA.
2. Active or conditional
SP-001 — Cloudflare, Inc.
- Services: DNS, CDN, WAF and security, Workers, Pages, R2, KV, Access, Tunnel and Logpush, according to the route and module.
- Data: request, authentication, security and audit metadata; payloads or outputs only where the route or store processes them.
- Location: distributed network and service-specific configured locations.
- Transfer: Cloudflare DPA, SCCs, DPF or another applicable mechanism.
- Status: operationally active; authorised only for the services and module in the snapshot.
SP-002 — Hetzner Online GmbH
- Services: origin compute, hosts, containers, storage and SMTP where used by the flow.
- Data: payloads, outputs, logs and communications processed by those components.
- Location: EEA; exact location is recorded in the snapshot.
- Transfer: no Chapter V mechanism where processing remains in the EEA.
- Status: operationally active; unverified encryption, backup or availability controls are not generalised.
SP-003 — ENTIA Google Workspace contracting entity
- Services: email and collaboration for support, contracting and communications.
- Data: contacts, correspondence and intentionally submitted attachments.
- Modules: P2 Support by default; other modules require an express record.
- Status: conditional. Restricted categories must not be sent through ordinary email.
3. Outside the DPA by default
- Stripe and payment providers: billing and collection for ENTIA's own controller activities.
- Signature and trust-service providers: conditional where they receive module personal data.
- GitHub and build services: Customer Personal Data is prohibited.
- Telegram and alert channels: non-sensitive identifiers and severity only.
4. External model providers
OpenAI, Anthropic, Google Models, OpenRouter, xAI, DeepSeek, Perplexity and other external providers are blocked by default for Customer Personal Data. Activation requires Rider A, named entity and model, region, purpose, fields sent, retention, training settings, human access, DPA, downstream subprocessors, transfer mechanism, logging and deletion.
5. Transfers and changes
Mechanisms may include adequacy, the DPF where applicable, the 2021 SCCs or another valid mechanism with supplementary measures. Each version records provider, modules, location, mechanism, notice date, objection period and incorporated snapshot.
6. Contact
Privacy and subprocessors: dpo@entia.systems. Trust and security: atc@entia.systems.
Approved by ENTIA as operational register v2.0. It does not authorise conditional or blocked providers outside a valid Order Form.