Preferium AI Edge — Sub-processor list

Last updated: 2026-05-21 (R174). Notification cadence: Material changes (additions, transfer-mechanism changes, primary-region changes) are emailed to every Customer admin/owner ≥ 30 days before the change takes effect, per DPA.md §5. Customers may object within 14 days; we work in good faith to reach a substitute solution or accept the objection.

This list catalogues every third party that processes personal data of Customer’s website visitors, Customer’s tenant users, or Customer-published content (which may contain personal data the Customer chose to publish). Required by GDPR Article 28(3) + SOC 2 CC9.2 + ISO 27001 A.15.

If you are a customer reviewing this for procurement, the canonical version is at https://trust.preferium.com/sub-processors post-R174 deploy. Until then, this file in the public repo is canonical.


A. Primary infrastructure

Vendor Service Personal data processed Primary region Transfer mechanism DPA link
Cloudflare, Inc. Workers compute, KV cache, R2 object storage, DNS, AI Gateway, CDN Visitor IP (truncated to /24), User-Agent, request path, optimized HTML payload, edge logs US/EU (Workers run in 300+ datacenters) EU SCCs (Module 2) + UK IDTA + EU-US Data Privacy Framework where US cloudflare.com/cloudflare-customer-dpa
Supabase, Inc. Managed Postgres + Auth + Storage. Project preferium-edge-prod (eu-west-1) All Customer tenant data: users, domains, pages, optimizations, audit_logs, billing references EU (Frankfurt, eu-west-1) No third-country transfer — EU intra-region. Sub-processor: AWS (also EU intra-region) supabase.com/legal/dpa
Cloudflare AI Gateway LLM request proxying with cost-tracking + rate-limit Routes through Cloudflare; original prompts (Customer-published HTML) + AI responses cached + logged for cost analytics US/EU EU SCCs (inherited from Cloudflare DPA) cloudflare.com/cloudflare-customer-dpa

B. LLM providers (for AI generation + citation tracking)

Vendor Service Personal data processed Primary region Transfer mechanism DPA link
Cloudflare, Inc. (Workers AI) ALL generative AI — SEO meta, headings, JSON-LD, alt-text, translations, sentiment (@cf/meta/llama-4-scout-17b-16e-instruct default) Customer-published HTML excerpt + AI-generated optimization
Anthropic PBC Citation-prompt suggestion only. NOT the generative model — generation moved entirely to Cloudflare Workers AI (R940, 2026-06-19) Tracked-query text
OpenAI, LLC ChatGPT API for LLM citation tracking (Phase 13) Tracked queries (e.g., “best vet clinic in Oslo”) — no Customer-identifying metadata US EU SCCs (direct DPA) openai.com/policies/dpa
Perplexity AI, Inc. sonar-pro API for LLM citation tracking Same as OpenAI row US EU SCCs perplexity.ai/dpa (Enterprise tier)
Google LLC (Gemini) Gemini API for LLM citation tracking Same as OpenAI row US EU-US Data Privacy Framework + EU SCCs cloud.google.com/terms/data-processing-addendum

Generativ AI-databehandler = Cloudflare Workers AI, ikke Anthropic. Kilden er packages/shared/src/ai-models.ts (OPTIMIZATION_MODELS — alle tre valgbare modellene har provider: 'workers_ai'; ingen Anthropic-modell er valgbar). De eksterne LLM-ene i tabellen over brukes til å MÅLE sitering i de ekte assistentene, ikke til å generere kundens innhold. Denne tabellen oppga Anthropic som «default generative model» fram til 2026-08-02, seks uker etter R940 — og Cloudflare Workers AI var ikke oppført som AI-databehandler i det hele tatt. Endrer du generativ leverandør: endre ai-models.ts FØRST, deretter denne fila og TERMS.md.

C. Google APIs (for SEO data integration)

Vendor Service Personal data processed Primary region Transfer mechanism DPA link
Google LLC (OAuth + APIs) OAuth flow, Search Console, Analytics, PageSpeed Insights, Knowledge Graph Tenant user email, OAuth tokens (encrypted at rest), GSC + GA4 metrics on Customer’s site US EU-US Data Privacy Framework + EU SCCs cloud.google.com/terms/data-processing-addendum

D. Billing + email

Vendor Service Personal data processed Primary region Transfer mechanism DPA link
Stripe Payments Europe Ltd. Subscription billing, customer portal, Checkout, webhooks Email, name, Stripe customer ID, plan tier, payment method (held by Stripe — we never see card data) EU (Dublin) No third-country transfer stripe.com/legal/dpa
Resend, Inc. Transactional email (invitations, notifications, password resets) Email, name, message content US (with EU pop) EU SCCs resend.com/legal/dpa

E. SEO data

Vendor Service Personal data processed Primary region Transfer mechanism DPA link
DataForSEO LLC Keywords, SERP, Backlinks v3, Competitor data Query terms (e.g., “best vet clinic in Oslo”) — no Customer identifying data, no end-user data EU (Vilnius) No third-country transfer dataforseo.com/dpa

F. Observability + status

Vendor Service Personal data processed Primary region Transfer mechanism DPA link
Sentry, Inc. Application error monitoring (api + edge + dashboard) Stack traces. PII scrubbing enabled on transport (no request bodies stored, IPs masked). US/EU EU SCCs (EU pop enabled per Sentry DPA) sentry.io/legal/dpa
Better Stack Inc. Uptime monitoring + hosted status page (status.preferium.com) Status-page subscriber email (opt-in) US (with EU pop) EU SCCs betterstack.com/legal/dpa

G. Support + analytics (minimal-PII)

Vendor Service Personal data processed Primary region Transfer mechanism DPA link
Cloudflare Web Analytics Page-view + bounce rate on app.preferium.com dashboard None — cookieless, no IPs stored Inherited from Cloudflare Inherited cloudflare.com/cloudflare-customer-dpa

Customer-support correspondence inbox (post@preferium.com) is hosted on Robert’s personal email infrastructure pending Q3 2026 migration to a managed B2B mailbox (likely Microsoft 365 or Resend Inbox). Not technically a sub-processor; documented here for transparency.


H. Pending evaluations / candidate vendors

These services are mentioned in docs/MASTERPLAN.md or enterprise-readiness.md as planned integrations but are NOT yet active sub-processors. They will be added to the active list with proper 30-day Customer notice when they go live.

Vendor Planned service Round when activated Status
Anthropic PBC Direct DPA without AI Gateway (today routed via CF) Not planned Routing via AI Gateway acceptable for v1
Resend, Inc. (Inbox) Replace post@preferium.com Robert-hosted mailbox Q3 2026 Pending procurement
Vanta or Drata SOC 2 evidence collection (R170+) R170-R200 Not yet contracted
External pen-test firm First annual pen-test (~$8-15k) R174 Vendor selection 2026-06

I. Change-notification process

Per DPA.md §5:

  1. Detect change — adding/removing a sub-processor, changing region, or changing transfer mechanism.
  2. Update this file + bump the “Last updated” header. Commit as docs(sub-processors): <vendor>: <change>.
  3. Notify Customers via email to every tenant owner/admin AND post to trust.preferium.com/sub-processors-changelog. Notification ≥ 30 days before effective date.
  4. Receive objections during the 14-day window (Customer emails dpo@preferium.com).
  5. Resolution path — if objection cannot be resolved (e.g., we cannot deliver Service without the new sub-processor), Customer can terminate Service per DPA.md §11 with pro-rated refund.

J. Change log

Date Round Change
2026-05-21 R174 Initial publication. Catalogued 11 active sub-processors. 4 pending. Aligned with DPA.md §5 + gdpr-article-30-records.md §C.