← Legal Center · Español

Subprocessors List

Version 2.0.0 · 24 July 2026

A provider is a subprocessor only where it processes personal data on ENTIA's behalf within an activated DPA module. An integration, account or credential does not itself authorise Customer Personal Data processing. The Order Form incorporates a dated snapshot.

1. Notice and objection

ENTIA will give at least 30 days' notice before adding or replacing a subprocessor that will process Customer Personal Data. The customer may object on reasonable data-protection grounds during the period stated in the DPA.

2. Active or conditional

SP-001 — Cloudflare, Inc.

SP-002 — Hetzner Online GmbH

SP-003 — ENTIA Google Workspace contracting entity

3. Outside the DPA by default

4. External model providers

OpenAI, Anthropic, Google Models, OpenRouter, xAI, DeepSeek, Perplexity and other external providers are blocked by default for Customer Personal Data. Activation requires Rider A, named entity and model, region, purpose, fields sent, retention, training settings, human access, DPA, downstream subprocessors, transfer mechanism, logging and deletion.

5. Transfers and changes

Mechanisms may include adequacy, the DPF where applicable, the 2021 SCCs or another valid mechanism with supplementary measures. Each version records provider, modules, location, mechanism, notice date, objection period and incorporated snapshot.

6. Contact

Privacy and subprocessors: dpo@entia.systems. Trust and security: atc@entia.systems.

Approved by ENTIA as operational register v2.0. It does not authorise conditional or blocked providers outside a valid Order Form.