Sub-processors and security measures
Status: 12 September 2026 – inventory for legal and technical review
1. Sub-processor inventory
| Service / category | Provider | Purpose | Data categories | Region and transfer basis | DPA / contract | Status |
|---|---|---|---|---|---|---|
| Hosting and database | [ENTER] | Portal operation, storage | Accounts, productions, technical logs | [ENTER] | [ENTER] | Open |
| [ENTER] | Account confirmation, invoices, support | Email, messages, contract data | [ENTER] | [ENTER] | Open | |
| Payment service | [ENTER] | Payment and payment status | Order/payment data | [ENTER] | [ENTER] | Open |
| Text / AI model | [ENTER] | Text generation, analysis | Briefs, text, potentially metadata | [ENTER] | [ENTER] | Open |
| Image / video AI | [ENTER] | Generation and editing | Prompts, images, videos, references | [ENTER] | [ENTER] | Open |
| Audio, TTS, transcription | [ENTER] | Audio processing | Audio, text, speaker/voice references | [ENTER] | [ENTER] | Open |
| Error analysis / monitoring | [ENTER] | Error diagnosis and security | Technical logs, potentially account ID | [ENTER] | [ENTER] | Open |
| Social platforms | Google, Meta, LinkedIn, TikTok | Connection and customer-requested API features | Account/profile data, tokens, content | [ENTER] | Review own role and terms | Open |
2. Draft technical and organisational measures
Physical and access protection
- Production systems, domain, email, source code, cloud and social developer accounts are protected by individual accounts and multi-factor authentication.
- Secrets, API keys and OAuth tokens are not stored in source code or browsers; server-side tokens are stored encrypted.
- Access rights follow the need-to-know principle and are removed promptly when roles change or access is no longer required.
Disclosure and separation
- Customer data is logically separated by customer account.
- External providers receive only data necessary for the selected feature.
- Accesses and production starts are logged where technically necessary.
Availability and recovery
- Backups and recovery procedures are set up and tested regularly.
- Security updates and critical fixes are prioritised.
- An incident runbook covers detection, containment, assessment, communication and recovery.
Review
- Security measures, service providers and data flows are reviewed for new features and at least annually.
- Employees or contractors with data access are bound to confidentiality.
[TECHNICAL REVIEW: Keep these statements only if every item is actually implemented and documented. Add backup intervals, encryption methods, roles, log and deletion periods.]
3. Data-breach process
- Record the incident, protect systems and limit access.
- Assess categories of data, affected people, scope, cause and risk.
- Involve legal advice/data-protection contact; assess required notification to authority and data subjects in time.
- Document measures and decisions; fix the cause and perform follow-up review.
[LEGAL AND ORGANISATIONAL REVIEW: Responsible person, reporting channels, 72-hour period and communication templates.]