Preferium AI Edge — Sub-processor list
Last updated: 2026-05-21 (R174).
Notification cadence: Material changes (additions, transfer-mechanism changes, primary-region changes) are emailed to every Customer admin/owner ≥ 30 days before the change takes effect, per DPA.md §5. Customers may object within 14 days; we work in good faith to reach a substitute solution or accept the objection.
This list catalogues every third party that processes personal data of Customer’s website visitors, Customer’s tenant users, or Customer-published content (which may contain personal data the Customer chose to publish). Required by GDPR Article 28(3) + SOC 2 CC9.2 + ISO 27001 A.15.
If you are a customer reviewing this for procurement, the canonical version is at https://trust.preferium.com/sub-processors post-R174 deploy. Until then, this file in the public repo is canonical.
A. Primary infrastructure
| Vendor |
Service |
Personal data processed |
Primary region |
Transfer mechanism |
DPA link |
| Cloudflare, Inc. |
Workers compute, KV cache, R2 object storage, DNS, AI Gateway, CDN |
Visitor IP (truncated to /24), User-Agent, request path, optimized HTML payload, edge logs |
US/EU (Workers run in 300+ datacenters) |
EU SCCs (Module 2) + UK IDTA + EU-US Data Privacy Framework where US |
cloudflare.com/cloudflare-customer-dpa |
| Supabase, Inc. |
Managed Postgres + Auth + Storage. Project preferium-edge-prod (eu-west-1) |
All Customer tenant data: users, domains, pages, optimizations, audit_logs, billing references |
EU (Frankfurt, eu-west-1) |
No third-country transfer — EU intra-region. Sub-processor: AWS (also EU intra-region) |
supabase.com/legal/dpa |
| Cloudflare AI Gateway |
LLM request proxying with cost-tracking + rate-limit |
Routes through Cloudflare; original prompts (Customer-published HTML) + AI responses cached + logged for cost analytics |
US/EU |
EU SCCs (inherited from Cloudflare DPA) |
cloudflare.com/cloudflare-customer-dpa |
B. LLM providers (for AI generation + citation tracking)
| Vendor |
Service |
Personal data processed |
Primary region |
Transfer mechanism |
DPA link |
| Cloudflare, Inc. (Workers AI) |
ALL generative AI — SEO meta, headings, JSON-LD, alt-text, translations, sentiment (@cf/meta/llama-4-scout-17b-16e-instruct default) |
Customer-published HTML excerpt + AI-generated optimization |
|
|
|
| Anthropic PBC |
Citation-prompt suggestion only. NOT the generative model — generation moved entirely to Cloudflare Workers AI (R940, 2026-06-19) |
Tracked-query text |
|
|
|
| OpenAI, LLC |
ChatGPT API for LLM citation tracking (Phase 13) |
Tracked queries (e.g., “best vet clinic in Oslo”) — no Customer-identifying metadata |
US |
EU SCCs (direct DPA) |
openai.com/policies/dpa |
| Perplexity AI, Inc. |
sonar-pro API for LLM citation tracking |
Same as OpenAI row |
US |
EU SCCs |
perplexity.ai/dpa (Enterprise tier) |
| Google LLC (Gemini) |
Gemini API for LLM citation tracking |
Same as OpenAI row |
US |
EU-US Data Privacy Framework + EU SCCs |
cloud.google.com/terms/data-processing-addendum |
Generativ AI-databehandler = Cloudflare Workers AI, ikke Anthropic. Kilden er
packages/shared/src/ai-models.ts (OPTIMIZATION_MODELS — alle tre valgbare modellene har
provider: 'workers_ai'; ingen Anthropic-modell er valgbar). De eksterne LLM-ene i tabellen
over brukes til å MÅLE sitering i de ekte assistentene, ikke til å generere kundens innhold.
Denne tabellen oppga Anthropic som «default generative model» fram til 2026-08-02, seks uker
etter R940 — og Cloudflare Workers AI var ikke oppført som AI-databehandler i det hele tatt.
Endrer du generativ leverandør: endre ai-models.ts FØRST, deretter denne fila og TERMS.md.
C. Google APIs (for SEO data integration)
| Vendor |
Service |
Personal data processed |
Primary region |
Transfer mechanism |
DPA link |
| Google LLC (OAuth + APIs) |
OAuth flow, Search Console, Analytics, PageSpeed Insights, Knowledge Graph |
Tenant user email, OAuth tokens (encrypted at rest), GSC + GA4 metrics on Customer’s site |
US |
EU-US Data Privacy Framework + EU SCCs |
cloud.google.com/terms/data-processing-addendum |
D. Billing + email
| Vendor |
Service |
Personal data processed |
Primary region |
Transfer mechanism |
DPA link |
| Stripe Payments Europe Ltd. |
Subscription billing, customer portal, Checkout, webhooks |
Email, name, Stripe customer ID, plan tier, payment method (held by Stripe — we never see card data) |
EU (Dublin) |
No third-country transfer |
stripe.com/legal/dpa |
| Resend, Inc. |
Transactional email (invitations, notifications, password resets) |
Email, name, message content |
US (with EU pop) |
EU SCCs |
resend.com/legal/dpa |
E. SEO data
| Vendor |
Service |
Personal data processed |
Primary region |
Transfer mechanism |
DPA link |
| DataForSEO LLC |
Keywords, SERP, Backlinks v3, Competitor data |
Query terms (e.g., “best vet clinic in Oslo”) — no Customer identifying data, no end-user data |
EU (Vilnius) |
No third-country transfer |
dataforseo.com/dpa |
F. Observability + status
| Vendor |
Service |
Personal data processed |
Primary region |
Transfer mechanism |
DPA link |
| Sentry, Inc. |
Application error monitoring (api + edge + dashboard) |
Stack traces. PII scrubbing enabled on transport (no request bodies stored, IPs masked). |
US/EU |
EU SCCs (EU pop enabled per Sentry DPA) |
sentry.io/legal/dpa |
| Better Stack Inc. |
Uptime monitoring + hosted status page (status.preferium.com) |
Status-page subscriber email (opt-in) |
US (with EU pop) |
EU SCCs |
betterstack.com/legal/dpa |
G. Support + analytics (minimal-PII)
| Vendor |
Service |
Personal data processed |
Primary region |
Transfer mechanism |
DPA link |
| Cloudflare Web Analytics |
Page-view + bounce rate on app.preferium.com dashboard |
None — cookieless, no IPs stored |
Inherited from Cloudflare |
Inherited |
cloudflare.com/cloudflare-customer-dpa |
Customer-support correspondence inbox (post@preferium.com) is hosted on Robert’s personal email infrastructure pending Q3 2026 migration to a managed B2B mailbox (likely Microsoft 365 or Resend Inbox). Not technically a sub-processor; documented here for transparency.
H. Pending evaluations / candidate vendors
These services are mentioned in docs/MASTERPLAN.md or enterprise-readiness.md as planned integrations but are NOT yet active sub-processors. They will be added to the active list with proper 30-day Customer notice when they go live.
| Vendor |
Planned service |
Round when activated |
Status |
| Anthropic PBC |
Direct DPA without AI Gateway (today routed via CF) |
Not planned |
Routing via AI Gateway acceptable for v1 |
| Resend, Inc. (Inbox) |
Replace post@preferium.com Robert-hosted mailbox |
Q3 2026 |
Pending procurement |
| Vanta or Drata |
SOC 2 evidence collection (R170+) |
R170-R200 |
Not yet contracted |
| External pen-test firm |
First annual pen-test (~$8-15k) |
R174 |
Vendor selection 2026-06 |
I. Change-notification process
Per DPA.md §5:
- Detect change — adding/removing a sub-processor, changing region, or changing transfer mechanism.
- Update this file + bump the “Last updated” header. Commit as
docs(sub-processors): <vendor>: <change>.
- Notify Customers via email to every tenant owner/admin AND post to
trust.preferium.com/sub-processors-changelog. Notification ≥ 30 days before effective date.
- Receive objections during the 14-day window (Customer emails
dpo@preferium.com).
- Resolution path — if objection cannot be resolved (e.g., we cannot deliver Service without the new sub-processor), Customer can terminate Service per DPA.md §11 with pro-rated refund.
J. Change log
| Date |
Round |
Change |
| 2026-05-21 |
R174 |
Initial publication. Catalogued 11 active sub-processors. 4 pending. Aligned with DPA.md §5 + gdpr-article-30-records.md §C. |