Skip to content
CIQRA
All legal documents

Subprocessor List


IN FORCE. See 00-README. This is the authoritative subprocessor list referenced by the Privacy Policy and the DPA (it populates DPA Annex IV / SCC Annex III).

Legal basis. Every provision below rests on one of three things: a measured fact about the platform (cited to file and line), a rule of law (cited to the instrument and article in the Legal Basis Register), or a commercial choice CIQRA has made where the law leaves it open. Prepared and adopted by CIQRA OÜ.

Controller/Processor: CIQRA OÜ, registry code 16465907, Veskiposti tn 2, Kesklinna linnaosa, Tallinn, Harju maakond, 10138, Estonia · privacy@ciqra.com In force from: 2026-08-09 · Version: 1.0 · Adopted by: CIQRA OÜ


0. What was measured, and what a source-code measurement cannot tell you

This list was reconciled against the platform source tree on 2026-08-09 (lane/L @ 81807dc44). That reconciliation is authoritative for one direction only:

  • A provider wired into the code is really engaged. If a client, endpoint or service registration exists, that party receives data when the feature runs.
  • ⚠️ Source code cannot establish a hosting region, a contracting entity, or an executed DPA. Those are deployment and contract facts. Where this list states a region or a legal entity, that value is carried forward from an earlier internal version and has not been independently verified here — it is marked accordingly.
  • 🔴 A row removed below was removed because the integration does not exist in the code, not because a contract was cancelled.

Six corrections resulted, all of which change what merchants and regulators are told (rows 1-3 on 2026-08-09, rows 4-5 on 2026-08-26, row 6 on 2026-08-27):

#CorrectionBasis
1Voyage AI and fal.ai added as AI subprocessors — both were entirely absent from this listAiServiceCollectionExtensions.cs:136 VoyageEmbeddingProvider, :143 FalImageProvider, :146 FalGenerativeImageProvider, :149 FalSceneImageProvider (cited as :94,96,99,102 when measured on 2026-08-09; re-measured 2026-08-26; re-pointed 2026-08-28 — see the 🔴 note in §4 on what the 2026-08-27 pass missed here)
2Amazon SES row removed — no SES client, package or sender exists; the only production email sender is Azure Communication ServicesAcsEmailSender.cs:13; grep -rn 'SES|SimpleEmail' src/ → no implementation
3"Self-hosted AI gateway on Azure" claim removed — AI traffic goes directly to the provider APIsAzureOpenAiChatClientFactory.cs:85-96; AiServiceCollectionExtensions.cs:106 options.VoyageBaseUrl, AiServiceCollectionExtensions.cs:116 options.FalBaseUrl (cited as :30-40 and :77,87 on 2026-08-09; re-measured 2026-08-26 against the Anthropic chat-client factory lines 30 to 38 and registration lines 101 and 111; re-pointed 2026-08-27 when that factory was deleted — §4.4; re-pointed again 2026-08-28)
6Anthropic moved from a live row to a removal block (row 7) — the integration left the code§4.4; AiServiceCollectionExtensions.cs:134-149
4Azure OpenAI added as row 10a — engaged 2026-08-26, and §4.2 previously said it was deliberately not listedAiServiceCollectionExtensions.cs:135 AzureOpenAiChatClientFactory (this cell said :126 from 2026-08-26 until 2026-08-28; the 2026-08-27 pass re-pointed row 10a and missed this one — see the 🔴 note in §4)
5Every AI citation in §4 re-pointed — the registrations moved from :92:102 to :124:135 and nothing noticed for seventeen dayssee the ⚠️ note in §4

1. How to read this list

  • CIQRA engages the third parties below to process personal data on its behalf (as subprocessors where CIQRA is a processor for Merchant data, or as processors where CIQRA is a controller for its own data).
  • Core hosting is EU-native. Compute, database, storage and secrets run on Microsoft Azure in Germany (Germany West Central / Germany North). For those, there is no transfer of personal data outside the EU/EEA for core processing.
  • SCCs are needed for the non-EEA-touching providers — Stripe's US flows, three of the four live AI providers (rows 8–10; row 10a is intra-EEA on the condition in §4.3), and Cloudflare's US parent. Those rows are marked "SCCs". ⚠️ Row 7 (Anthropic) left the live set on 2026-08-27 (§4.4); its historical transfers are unaffected by the removal.
  • Stripe acts largely as an independent controller/processor for payment data under its own terms, not merely as CIQRA's subprocessor.
  • Consent-based recipients (ad/analytics platforms) and Merchant-opted-in recipients process personal data only where the relevant Merchant/end-user has enabled them; for those the Merchant is typically the controller.
  • "SCCs" = EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), plus UK IDTA/Addendum and Swiss amendments where relevant; CIQRA maintains a Transfer Impact Assessment for restricted transfers (DPA §11.2).

2. Core platform subprocessors (always engaged)

#Subprocessor (legal entity)Purpose / servicePersonal dataLocationTransfer basis
1Microsoft Azure (Microsoft Ireland Operations Ltd / Microsoft Corp.) — Container Apps (compute), Database for PostgreSQL Flexible Server (data), Blob Storage (media), Key Vault (secrets/keys)Hosting, compute, database, media storage, secrets/key managementAll hosted platform dataEU — Germany West Central (Frankfurt) primary; Germany North paired DRIntra-EEA for core processing; SCCs for any US-parent support access
2Cloudflare, Inc.CDN, DNS, WAF, DDoS mitigation, bot protection, merchant custom hostnames. 🔴 Added 2026-08-10: Cloudflare Web Analytics ("Insights"). cloudflareinsights/beacon.min.js runs on storefront pages and was missing from this list — because it is injected at the edge, not by the application: the origin HTML contains zero occurrences, while the browser's document.scripts contains it. It is analytics, and analytics is not strictly necessary under ePrivacy Art. 5(3) (register 1.6). ⚠️ It cannot be switched off in code — it is a Cloudflare panel setting. PA-0371; see Cookie Policy §4.2.Traffic metadata, IP, request headers; plus page/navigation telemetry via InsightsGlobal edge; EU data-localization applied to EU traffic (not verified here)SCCs (US entity). 🔴 Insights additionally needs an Art. 5(3) consent basis, which is not in place
3Microsoft — Azure Communication Services (ACS) EmailTransactional email delivery — the only production email sender (measured: ciqra-saas/src/Ciqra.Api/Email/AcsEmailSender.cs:13, "EU Data boundary")Recipient email, name, message contentEU (Germany/EU region)Intra-EEA; SCCs for any US-parent access
4Grafana Labs — Grafana Cloud (EU)Observability — metrics, logs, traces via OpenTelemetry OTLP (measured: Ciqra.Api.csproj:81-85)Telemetry, limited PII (IP, user/tenant id)EU region (deployment config, not verified here)Intra-EEA; SCCs if US access
5Functional Software, Inc. — Sentry (EU region)Error monitoring / crash diagnostics (measured: Ciqra.Api.csproj:86 Sentry.AspNetCore)Error/diagnostic data, limited PIIEU data residency (Sentry EU) (deployment config, not verified here)Intra-EEA; SCCs if US access

🔴 Removed: Amazon Web Services — SES. An earlier internal version listed SES as a "fallback" email path. No SES integration exists (measured 2026-08-09: the only IEmailSender implementations are AcsEmailSender (production) and LoggingEmailSender (dev/test); no AWS SDK package, client or configuration section is present). Listing a subprocessor that receives no data misdescribes the processing chain in the opposite direction from the usual error, and it would have been carried into SCC Annex III. If an SES fallback is later built, it re-enters this list under the §7 change-notice procedure.

Search (Typesense). Product/content search uses Typesense (measured: Ciqra.Api.csproj:73; TypesenseSearchIndexer.cs), with a no-op indexer fallback when it is not configured, in which case the storefront falls back to database search (Program.cs:669-674). CIQRA's determination: an earlier internal version asserted Typesense "runs self-hosted on CIQRA's Azure infrastructure in Germany and is an internal component, not a separate subprocessor". Whether the deployed instance is self-hosted on CIQRA's own Azure infrastructure or a managed third-party service is a deployment fact this reconciliation could not measure. If it is ever run as a managed third-party service, it becomes a subprocessor and must be listed. This must be confirmed against the production deployment before the list is published.

3. Payments (independent controller/processor)

#PartyPurposePersonal dataLocationBasis
6Stripe (Stripe Payments Europe, Ltd. — Ireland; Stripe, Inc. — US)Payment processing, Stripe Connect, KYC/KYB, fraud, payoutsPayment/transaction data, KYC/beneficial-owner data — no raw PAN reaches CIQRA (see §3.1)EU + USStripe's own terms + SCCs for US flows; Stripe is largely an independent controller/processor

3.1 The no-raw-PAN statement is measured, and it has a named condition (2026-08-09). Card fields on the storefront checkout are Stripe Elements iframes, not CIQRA inputs — the number, expiry and CVC are rendered as data-stripe-field mount points (ciqra-saas/src/Ciqra.Api/Storefront/Themes/default/checkout-payment.liquid:99,110,117). The platform defines a raw-PAN seam, IRawCardPaymentProvider / RawCardPaymentRequest, explicitly labelled SAQ D (Ciqra.Modules.Payment/PaymentAbstractions.cs:103-119) — and nothing implements it: grep -rn 'IRawCardPaymentProvider' src/ tests/ returns only the declaration and one doc-comment cross-reference. The local acquirers (İyzico, PayTR, bank virtual-POS) all route through INativePaymentProvider : IHostedPaymentProvider (INativePaymentProvider.cs:48), i.e. the hosted/3DS-redirect path, with BankVposSessionStore acting as the 3DS hand-off (NativePaymentsServiceCollectionExtensions.cs:53).

Condition, stated because it is one line of code away: the SAQ A posture holds only while IRawCardPaymentProvider has no implementation. Implementing it puts raw PAN into CIQRA's systems and moves the attestation to SAQ D. This should be a monitored invariant, not a fact recorded once.

4. AI subprocessors (feature-triggered)

🔴 Three of the four live rows are third-country transfers; one is not. There is still no gateway terminating AI traffic inside the EEA — the earlier "self-hosted AI gateway on Azure" statement was incorrect and has been removed (measured 2026-08-09, re-measured 2026-08-26, re-pointed 2026-08-27 and 2026-08-28: AzureOpenAiChatClientFactory.cs:85-96 hands the provider SDK a pooled HttpClient and calls the vendor endpoint directly; AiServiceCollectionExtensions.cs:106 options.VoyageBaseUrl and AiServiceCollectionExtensions.cs:116 options.FalBaseUrl point BaseAddress at the Voyage and fal.ai vendor endpoints). What changed on 2026-08-26 is that one provider's endpoint is now an EU-region Azure account of CIQRA's own; the request still goes straight to it. See AI Terms §1 and §2.4.

⚠️ The 2026-08-26 version of the sentence above evidenced the no-gateway finding from the Anthropic chat-client factory, lines 30 to 38. That file was deleted on 2026-08-27 (§4.4), so the citation was re-pointed to the factory that carries the same behaviour today. (Written as prose for the reason the note at the end of this section gives — and CITATIONS did fail the first draft of this sentence for writing it in citation format, which is the check working.) The finding did not change; the file that evidences it did. A deletion elsewhere in the repository can unback a sentence in this document — that is the failure mode CITATIONS exists to make loud, and here it was loud.

⚠️ Every line number in this section was re-measured on 2026-08-26 and every one of them had moved. The 2026-08-09 version cited AiServiceCollectionExtensions.cs lines 92 to 102; the registrations moved to lines 124 through 135, shifted by an options-validation block and the Azure OpenAI client added between them. Line 92 of that file was services.TryAddSingleton(TimeProvider.System); when this note was written — a line about clocks, offered as the evidence that Anthropic is the platform default for text. It is AiDbContext.UseVectors(npgsql); as at 2026-08-28; the illustration drifted along with everything else, which is the point being made rather than an error in making it. Nothing failed when the original move happened: a positional citation goes stale in silence.

⚠️ They moved again on 2026-08-27, to lines 123 through 138 of that file, when the Anthropic registration was deleted out of the middle of the block. Every citation in this section was re-pointed in the same commit as the deletion, and CITATIONS + AIWIRING were run against that tree. The difference between this move and the 2026-08-09 one is not care, it is the mechanism: the first went unnoticed for seventeen days, the second could not be committed without the checks being green. (Those numbers are written as prose for the reason the closing note of this section gives; in backticked form they would be live claims about a tree that no longer exists.)

⚠️ And a third time on 2026-08-28, to lines 134 through 149 — an IRequestContext registration (AI-06) was added above the block by a second lane, moving every registration down eleven lines. Nobody re-read these documents; AIWIRING dereferenced the citations, found them landing on comments, and failed the release preflight before the deploy went out. Every AI citation in this section and in AI Terms §1/§1.1 was re-measured against the current tree and re-pointed here.

🔴 That run also exposed the limit of the token test, and it is the reason AIWIRING gained a second arm in the same commit. Change-log row 4 above cited :126 for the claim "Azure OpenAI added as row 10a". That citation had been correct against the 2026-08-26 tree and stale since 2026-08-27 — the 2026-08-27 pass re-pointed row 10a in §4 and missed the change-log cell describing the same fact. AIWIRING did not fire on it either time, because line 126 happened to be .AddHttpMessageHandler<AzureOpenAiTransportHandler>();, which contains the token azure: a citation can land on the wrong line of the right file and still name a provider. The check now also resolves each AI citation to the SYMBOL it landed on when it was written, and reports where that symbol moved to when the line no longer carries it — so a drift onto a plausible neighbour reads as "drifted, the registration is now at :NNN" rather than passing in silence. A stale citation nobody can see is the exact defect this section was written about; one arm of the check could not see this instance of it.

Also corrected on 2026-08-27: rows 10 and (in AI Terms §1) fal.ai cited :129, :132, :135. Lines 129 and 135 were comment lines, not registrations — the fal citations had been stale since 2026-08-26 and neither check saw it, because a bare :NNN continuation is invisible to both patterns (the limit legalgate.py declares and counts). They are now :143, :146, :149, re-measured 2026-08-28. A declared limit is still a hole: this one had three stale citations sitting in it, in two in-force documents.

The stale line numbers in the paragraph above are deliberately written as prose ("lines 92 to 102") rather than in the backticked file:line form. In that form they are CITATIONS, and legalgate.py's new AIWIRING check reads them as live claims and fails the build — which it did, on the first run, on this very sentence. A document cannot quote a broken citation in the citation format without asserting it. Two checks now stand behind this section: CITATIONS dereferences every file:line in the set and fails when the file or the line does not exist, and AIWIRING fails when a citation into the AI registration file lands on a line that names no provider — which is the shape THIS defect actually had, and the one CITATIONS alone would have passed.

#PartyPurposePersonal dataLocationBasis
8OpenAI (OpenAI Ireland Ltd / OpenAI, L.L.C.)LLM inference; embeddings (AiServiceCollectionExtensions.cs:134 OpenAiChatClientFactory, :137 OpenAiEmbeddingProvider)Minimised feature inputs/outputsUSNo-training by default (business/API terms) + SCCsnot verified, §4.1
9Voyage AIEmbeddings — default embedding provider (:136 VoyageEmbeddingProvider; https://api.voyageai.com/v1/embeddings, VoyageEmbeddingProvider.cs:25)Text submitted for embeddingUSSCCs requirednot verified, §4.1
10fal.aiImage generation / editing (:143 FalImageProvider, :146 FalGenerativeImageProvider, :149 FalSceneImageProvider)Submitted and generated imagesUSSCCs requirednot verified, §4.1
10aMicrosoft — Azure OpenAI (Microsoft Ireland Operations Ltd / Microsoft Corp.), account ciqra-openai-prodLLM inference for text — engaged 2026-08-26; the resolved text provider since 2026-08-27 (AiServiceCollectionExtensions.cs:135 IAiChatClientFactory, AzureOpenAiChatClientFactory; Providers/AzureOpenAiChatClientFactory.cs)Minimised feature inputs/outputsEU — Germany West Central, on the SKU condition in §4.3Intra-EEA for the DataZoneStandard deployment; Microsoft's Azure OpenAI service terms (no training on customer prompts/completions) — executed agreement not verified, §4.1 applies identically

🔴 Removed 2026-08-27: Anthropic (Anthropic Ireland, Ltd / Anthropic, PBC) — row 7. LLM inference, formerly the platform default for text. The integration left the code, not a contract. (measured 2026-08-27: AnthropicChatClientFactory.cs deleted; its services.AddSingleton<IAiChatClientFactory, …> registration and its named HttpClient deleted from AiServiceCollectionExtensions.cs; the Anthropic SDK removed from Ciqra.Modules.Ai.csproj and from Directory.Packages.props. AiTextService.cs:314 and AiCopilot.cs:165 each resolve AiProviders.AzureOpenAi and nothing else, and AiModelCatalog.IsKnownTextModel admits only the Azure deployment's model id, so no merchant setting can route back to it.) Written in the shape §4.2 required for this event: a removal block with the measurement that made the removal true.

What this does NOT say. It does not say no personal data was ever transferred to Anthropic: ai_usage_records rows written before this date carry the provider string anthropic, that transfer was a US third-country transfer while it ran, and §4.1's disclosed-but-unpapered determination applied to it throughout and is not retro-cured by the deletion. Data-subject rights, retention and any SCC obligations attaching to those past transfers are unaffected. It does not say a contract was terminated. And it does not retire rows 8 and 9 — see §4.4.

AiProviders.Anthropic deliberately remains in the code as a stored vocabulary constant so historical usage rows keep resolving and stay priceable; a constant retained to keep the past readable is not a live recipient. If routing to Anthropic is ever rebuilt, it re-enters this list under the §7 change-notice procedure.

Numbered 10a rather than 11 on purpose: rows 11–17 below are cited by number from the DPA and the Privacy Policy, and renumbering them to make room would silently re-point every one of those references at a different party. A stable identifier is worth more than a tidy sequence.

4.1 CIQRA's determination on rows 8–10a, and on retired row 7. Rows 9 and 10 were absent from every earlier internal version of this list, which means they were also absent from DPA Annex IV / SCC Annex III. Embedding text and image content were therefore being sent to two undisclosed US recipients. Adding them here is the correction; it is not a statement that SCCs are in place. For every live row — including 10a — CIQRA has not verified within this workstream that an Art. 28 DPA and, where applicable, an Art. 46 transfer mechanism are executed and on file. Treat rows 8–10a as disclosed-but-unpapered until each executed agreement is located. ⚠️ This determination applied to row 7 (Anthropic) for the whole period it was live and is not cured by its removal on 2026-08-27: transfers already made under an unpapered basis stay unpapered, and the paperwork obligation for them survives the code deletion.

4.2 Azure OpenAI — engaged 2026-08-26. 🔴 This section previously read "intended, not engaged" and stated that the azure-openai identifier existed "only as a constant with no client, no HTTP registration and no service registration", and that it would enter this list under §7 when it was wired. It is now wired, and this list has been updated in consequence — that is the commitment being honoured, not abandoned. The old text is retained here so a reader who remembers it can see what changed:

4.2 Azure OpenAI (intended, not engaged). (superseded 2026-08-26) CIQRA has decided to migrate inference to Azure OpenAI (ciqra-openai-prod, germanywestcentral), which would make AI processing intra-EEA and retire rows 7–8. As at 2026-08-09 that provider is not engaged: the azure-openai identifier exists only as a constant with no client, no HTTP registration and no service registration (AiVocabulary.cs:35, :45). It is therefore deliberately not listed as a subprocessor — listing it would be the same error as the SES row. It enters this list under §7 when it is wired.

4.4 🔴 AI-02 landed for row 7 only. Rows 8 and 9 are NOT retired, and this list will not pretend they are. The superseded text expected Azure OpenAI to "retire rows 7–8", and the 2026-08-26 version of this paragraph recorded that none of them had gone. Row 7 (Anthropic) has now gone — the removal block above the table carries the measurement that made it true, which is the procedure this paragraph itself set: "rows 7, 8 and 9 are moved to a removal block in the shape of the SES block in §2, with the measurement that made the removal true." That procedure was followed for one row and not stretched to the other two.

Rows 8 and 9 stay live. OpenAI-direct and Voyage remain registered and callable (AiServiceCollectionExtensions.cs:134 OpenAiChatClientFactory, :136 VoyageEmbeddingProvider, :137 OpenAiEmbeddingProvider). Removing a row for a provider the code can still call would misdescribe the processing chain in the opposite direction from the SES error — and that direction is worse, because a shopper's data would be going somewhere this list said it did not. AI-02 is therefore partially landed, and this list says "partially" rather than choosing whichever whole number is easier to write. Rows 8 and 9 move only when the same measurement can be made for them. Not before.

4.3 🔴 The intra-EEA basis for row 10a rests on a deployment SKU, not on the account's region. An Azure OpenAI account in germanywestcentral can still be served from capacity outside the EEA when the deployment is a Global SKU. The account carries two deployments and they differ (measured 2026-08-26, AiOptions.cs:74-78, Providers/AzureOpenAiChatClientFactory.cs:104-107):

  • gpt-5-4-miniDataZoneStandard. Capacity confined to the EU data zone. This is the deployment the platform calls, and it is what row 10a's Intra-EEA basis is claimed for.
  • gpt-5-4-batchGlobalBatch. A Global SKU, i.e. not confined to the EEA. No personal data reaches it: the factory refuses any deployment declared Batch rather than calling it (AzureOpenAiChatClientFactory.cs:120-127). If it is ever put into service, row 10a's intra-EEA basis does not extend to it and that path needs an Art. 46 mechanism.

Stating "germanywestcentral" and stopping there would have been an upgrade of the platform's posture on the strength of a region field. The region says where the account is; the SKU says where a request may be served.

5. Consent-based & Merchant-opt-in recipients (not default subprocessors)

Process personal data only where enabled by the relevant Merchant/end-user; the Merchant is typically the controller.

#PartyPurposeTriggerBasis
11Google (Ireland Ltd) — GA4 / Tag Manager / Google Ads; reCAPTCHA v3Analytics & advertising; bot protectionCookie/ad consent. 🔴 reCAPTCHA: corrected 2026-08-10 — the earlier entry read "(reCAPTCHA: security)" and that is not a basis. Loading reCAPTCHA reads and writes the visitor's terminal equipment, which under ePrivacy Art. 5(3) (register 1.4) permits only consent or a statutory exemption — "security" is neither, and Art. 5(3) has no legitimate-interest gateway. See PA-0371; the ruling is in Cookie Policy §4.2.Consent (Art. 5(3)) for the terminal-equipment access; Art. 6 separately for the processing; SCCs for the onward transfer. 🟢 Corrected 2026-08-10 — the server-side IP transfer has been removed. An earlier version of this row recorded that the siteverify call also sent the visitor's IP to Google server-side, independent of anything the browser did. Re-measured: the request body now carries secret and response only, and the remoteIp parameter is deleted from the call chain rather than left unread (CaptchaVerifiers.cs:14-36). 🔑 That closes the one channel a browser could never have shown. The script tag and the challenge remain, and they are what §4.2 of the Cookie Policy is about.
12Meta Platforms (Ireland Ltd) — Pixel & Conversions APIAdvertising measurement (incl. server-side)Cookie/ad consentConsent + SCCs; possible joint controllership (Fashion ID)
13TikTok (Technology Ltd, Ireland)Advertising measurementCookie/ad consentConsent + SCCs
14hCaptcha (Intuition Machines, Inc.)Bot protection — accepted alongside reCAPTCHA and Cloudflare Turnstile (measured: Ciqra.Api/Cms/FormEndpoints.cs:40 accepts g-recaptcha-response, cf-turnstile-response, h-captcha-response)Merchant selects the providerSCCs (US entity)
15Shipping carriers (DHL, UPS, FedEx, Yurtiçi Kargo, PTT)Rate quotes, label creation, trackingMerchant enables the carrierRecipient/processor per carrier — contracting entity and basis not verified here
16SMS providers (Netgsm, İletimerkezi)Transactional SMS (measured: api.netgsm.com.tr, api.iletimerkezi.com in source)Merchant enables SMSTurkey — third country; transfer basis not established, see §5.1
17Marketplace channels (as connected by the Merchant)Channel listing & order syncMerchant opt-in connectionPer channel; transfer safeguards not yet assessed

5.1 CIQRA's determination on rows 15–16. Carrier and SMS integrations were not represented in any previous version of this list, yet they receive recipient name, address and phone number — ordinary personal data of shoppers, not telemetry. The Turkish SMS providers in row 16 are recipients in a third country without an EU adequacy decision for transfers of this kind, and no transfer mechanism has been identified. These rows are added so the omission is visible; their transfer basis is an open item.

6. Professional & occasional recipients

Auditors, legal/financial advisers, and authorities — only where legally required or to establish/defend legal claims; and an acquirer/successor in a corporate transaction (subject to confidentiality). Not ongoing subprocessors.


7. Change management

  • CIQRA notifies Controllers of intended additions or replacements ≥30 days in advance (subprocessor page + email/subscription), with a reasonable-grounds objection right (DPA §5.2) and an emergency-addition carve-out for security/continuity (DPA §5.3).
  • The Azure OpenAI migration (§4.2) is a subprocessor change and triggers this procedure.
  • 🔴 Status of that notice, stated rather than left to be inferred. The addition of row 10a shipped in code on 2026-08-26. A change notice has been drafted in full and is held for the provider's decision on whether and when it is issued; it is recorded in the commit that made this edit. This list does not state that the notice has been sent, and must not until it has been. The clause above is not weakened by the fact that the change has already landed — if anything the reverse, and the ≥30-day window as written has been overrun rather than started, which is a judgement for the provider and not a formality. Note that the removal of rows 7–9 is a second, separate change on this clause and has not happened at all.

8. Before this list is published

CIQRA's determination: the following are open, and this list must not be presented as a completed Annex III until they are closed. They are listed here rather than left as flags so that the gaps are countable.

  1. Confirm each entity's exact legal name and contracting entity — carried forward from an earlier internal version, not verified here.
  2. Locate the executed DPA + Art. 46 transfer mechanism for rows 8–10 (AI) and for retired row 7 (Anthropic), whose past transfers the 2026-08-27 removal does not cure (§4.1), the executed Art. 28 DPA for row 10a (Azure OpenAI — no Art. 46 mechanism is needed while §4.3's SKU condition holds), and establish one for row 16 (TR SMS).
  3. Confirm the hosting model for Typesense (§2 note) — self-hosted or managed third party.
  4. Confirm the deployment region claims for Grafana Cloud and Sentry (rows 4–5); these are configuration, not code.
  5. Re-run this reconciliation against the production stack on launch day, not against the source tree — a provider can be configured in production without appearing in source, and this measurement would not see it.

Composition of this document: 11 measured facts · 6 declared positions · 5 corrections to earlier assertions. (2026-08-26 added: the Azure OpenAI engagement, the deployment-SKU limb of its residency claim, and the re-measured registration line numbers as measured facts; the held change notice as a declared position; the stale §4 citations and the superseded §4.2 as corrections.)

End of Subprocessor List . Referenced by: Privacy Policy · DPA (Annex IV / SCC Annex III) · AI Terms.