Trust Center · version 1.2

Subprocessor List

DeepTech sp. z o.o. · Version 1.2 — pending management approval · October 2026

Document details
FieldValue
OwnerDeepTech sp. z o.o. — CTO (system owner), approved by the Management Board
Version1.2
StatusPending management approval (Management Board of DeepTech sp. z o.o.)
EffectiveOn approval — October 2026 (supersedes v1.1, v1.0 and Draft v0.9)
ReviewEvery 12 months or after a material change
ClassificationPublic

DeepTech sp. z o.o. engages the subprocessors listed below to operate the Audomate platform and the services around it. All platform subprocessors process client data exclusively in EEA regions. This list forms Annex IV to our Data Processing Agreement (DPA; in legal review by an external law firm since 10 October 2026) and is kept current in the Trust Center; the internal supplier register holds the evidence behind each row (contract, DPA, certificates, DPF check).

1. Scope

  • Platform subprocessors (section 2, rows 1–5) — process data that clients entrust to the Audomate platform (uploaded documents, user accounts, audit results). Changes are subject to the 30-day notice in section 4.
  • Website and business-operations providers (section 2, rows 6–9) — process personal data for which DeepTech is controller (website visitors, enquiries, invoicing, support). No CRM and no ticketing system are used; enquiries and support requests are handled by e-mail (sales@deeptech.pl, contact@deeptech.pl, support@audomate.eu). They are listed for completeness and transparency; they do not receive client content from the platform.

2. Subprocessors

#Subprocessor — legal entity and addressRole / purposeProcessing regionCategories of dataTransfer mechanism / safeguards
1Google Cloud Platform — Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland (contracting entity confirmed against invoice, 10 October 2026)Cloud infrastructure: compute (Cloud Run), Cloud SQL (PostgreSQL), Cloud Storage, Memorystore (Redis), Cloud KMS, Secret Manager, Cloud Logging / MonitoringEEA — europe-west1 (Belgium, primary), europe-west3 (Germany, DR), europe-west4 (Netherlands, dual-region storage)Encrypted client content (documents, vectors, reports), account data, audit trail and logsProcessing in the EEA; Google Cloud Data Processing Addendum (art. 28 GDPR). Google LLC is certified under the EU-U.S. Data Privacy Framework for residual support / telemetry access; SCC 2021/914 in the addendum
2OpenAI API (EU data residency) — OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, IrelandLLM inference (GPT-4o) and embeddings (text-embedding-3-large) for the contract-audit engine, via the OpenAI APIEU data residency — EU-region project, endpoint eu.api.openai.comPrompts and completions containing fragments of client documents — transient only; Zero Data Retention (ZDR) and EU data residency enabled on the production project (OpenAI abuse monitoring otherwise keeps API logs for up to 30 days by default); no training on client dataProcessing in the EEA; OpenAI API Services Agreement + OpenAI Data Processing Addendum (SCC 2021/914 included). Parent company OpenAI, L.L.C. (USA) is certified under the EU-U.S. Data Privacy Framework (relevant to support / telemetry only)
3Auth0 (Okta) — Okta, Inc., 100 First Street, San Francisco, CA 94105, USA — tenant in the EU regionIdentity provider: login, SSO (OIDC / SAML 2.0), MFA, federation with the client's own enterprise identity providerEU — eu.auth0.com (AWS Frankfurt, Germany)Platform users: first name, surname, business e-mail, role, authentication logsOkta GDPR Data Processing Addendum in force; EU-U.S. Data Privacy Framework: listed — DPF status verified 10 October 2026 (screenshot on file); SCC 2021/914 in the Okta DPA
4Vercel — Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USAHosting and delivery of the Next.js front end (edge CDN)EEA points of presence; geo-restriction to EEATransit traffic only (IP addresses, request headers); no client content at restVercel Data Processing Addendum (SCC 2021/914); EU-U.S. Data Privacy Framework: listed — DPF status verified 10 October 2026 (screenshot on file)
5PagerDuty — PagerDuty, Inc., 600 Townsend St, San Francisco, CA 94103, USA — EU data residency optionAlerting and on-call paging for platform incidentsEU (data residency enabled on our account)Alert metadata (service name, severity, timestamps, on-call engineer contact); no client contentPagerDuty Data Processing Addendum (SCC 2021/914); EU-U.S. Data Privacy Framework: listed — DPF status verified 10 October 2026 (screenshot on file)
6Plausible Analytics (website audomate.eu) — Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, EstoniaCookieless website statisticsEU (Germany, Hetzner)Anonymised, aggregated statistics; IP address and user agent only in memory with a salt rotated every 24 hoursNo transfer outside the EEA; EU entity; Plausible DPA (art. 28 GDPR)
7mOrganizer finansów (invoicing and accounting) — A service of mBank S.A., ul. Prosta 18, 00-850 Warsaw, Poland, KRS 0000025237 — delivered by mBank in cooperation with CashDirector S.A., WarsawIssuing invoices and keeping invoice records; processor of contact and billing data of clients and vendorsPoland / EEAInvoice data of clients and vendors: company name, NIP, address, contact person, bank account numbersNo transfer outside the EEA; mOrganizer data processing agreement (art. 28 GDPR); the data processing agreement counterparty is CashDirector S.A.
8Business e-mail provider — home.pl sp. z o.o., ul. Zbożowa 4, 70-653 Szczecin, PolandBusiness mailboxes: enquiries and leads (sales@deeptech.pl, contact@deeptech.pl — no CRM system is used), support (support@audomate.eu), privacy@, security@, legal@audomate.eu. Support requests are handled by e-mail (support@audomate.eu); no third-party ticketing tool is usedPoland / EEAName, business e-mail, company, content of enquiries and support requestsHome.pl data processing terms (art. 28 GDPR); no transfer outside the EEA
9External accounting office — EasyTaxes Sp. z o.o., ul. Warszawska 58C/56, 02-496 Warsaw, Poland, NIP 522-300-38-77Bookkeeping and accounting services for DeepTech (controller data only; no platform data)Poland / EEAAccounting documents and invoices: company name, NIP, address, contact person, bank account numbers; personnel and payroll accounting data where within the engagementNo transfer outside the EEA; processing terms under art. 28 GDPR

3. How we vet subprocessors

Before a provider processes any data on our behalf, and at least annually thereafter, the CTO (system owner) performs the following checks and records the result in the internal supplier register:

  1. Contract — a data processing agreement meeting art. 28(3) GDPR is in place (documented instructions, confidentiality, security under art. 32, assistance with data subject rights and breach notification, deletion or return at the end of the service, audit rights, flow-down to the provider's own subprocessors under art. 28(4)).
  2. Location — the service is configured for EEA/EU processing (region, tenant or data-residency setting) and the configuration is verified in the provider console, not only in the contract.
  3. Security assurance — the provider holds current independent certifications or attestations appropriate to its role (ISO/IEC 27001, SOC 2 Type II, CSA STAR for cloud infrastructure); reports are obtained and reviewed.
  4. Third-country check — for providers established in the United States: the entity is verified on the EU-U.S. Data Privacy Framework list (dataprivacyframework.gov/list; Okta, Inc., Vercel Inc. and PagerDuty, Inc. verified on 10 October 2026, screenshots on file) and Standard Contractual Clauses (Decision 2021/914) are in place as the fallback mechanism; a transfer impact assessment is kept where residual access from outside the EEA is possible.
  5. Incident and exit terms — the provider commits to notify DeepTech of security incidents affecting our data without undue delay, and supports data export and deletion on exit (relevant for our clients' DORA obligations under art. 28 and 30 DORA).

4. Change notice

We provide clients with 30 days' written notice before a platform subprocessor is added or replaced, by e-mail to the named contacts recorded at onboarding and by updating this list in the Trust Center. Clients may object on reasonable, data-protection-related grounds within the objection window defined in the DPA; where no solution is found, the client may terminate the affected service as set out in the DPA.

5. Not subprocessors

Self-hosted components running inside DeepTech's own cloud tenancy — PostgreSQL (Cloud SQL), Qdrant / pgvector vector index, Redis (Memorystore), Celery workers — are part of the platform operated by DeepTech, not separate subprocessors. Professional advisers (legal, tax) act under professional secrecy and are not platform subprocessors. No CRM and no ticketing system are used.

6. Contact

Questions about this list: privacy@audomate.eu (Data Protection Coordinator: Kacper Raubo, kacper.raubo@deeptech.pl). Copies of subprocessor DPAs and the current DPF verification record are available to clients on request under NDA.

Document control

VersionDateAuthorApproved byChanges
0.9September 2026DeepTech (CTO / CEO)— (working draft, not adopted)Working draft published for transparency; items marked "to confirm".
1.0October 2026DeepTech (CEO / CTO)— (superseded by 1.1)Changes after the GDPR (RODO) / NIS2 audit of 7–8 October 2026: full legal entities, addresses, processing regions, data categories and transfer mechanisms added for every subprocessor; PagerDuty named as the alerting tool; Plausible Analytics added for the website; new section "How we vet subprocessors"; scope split into platform subprocessors and business-operations providers; billing, ticketing and CRM rows left as decisions.
1.110 October 2026DeepTech (CEO / CTO / data protection coordinator)Management Board — pendingUpdates after Management Board decisions of 10 Oct 2026: row 2 replaced — LLM and embeddings provider is OpenAI Ireland Ltd (OpenAI API, EU data residency, Zero Data Retention), the previously listed cloud-reseller LLM service is not used; Google Cloud EMEA Limited confirmed against invoice; DPF status of Okta, Vercel and PagerDuty verified 10 Oct 2026; mOrganizer finansów (mBank S.A.) added as invoicing provider; ticketing and CRM rows removed (not used — e-mail only); business e-mail provider row kept as open item; DPA in legal review (law firm) since 10 Oct 2026.
1.211 October 2026DeepTech (CEO / CTO / data protection coordinator)Management Board — pendingOpen items closed on the basis of Management Board answers of 11 Oct 2026: row 8 — Home.pl named as business e-mail provider; row 9 added — EasyTaxes Sp. z o.o. (external accounting office); row 7 — data processing agreement counterparty is CashDirector S.A.; row 5 — EU data residency in PagerDuty confirmed; row 2 — EU data residency and Zero Data Retention enabled on the production OpenAI project.

Back to the Trust Center document library