Subprocessor List
DeepTech sp. z o.o. · Version 1.2 — pending management approval · October 2026
| Field | Value |
|---|---|
| Owner | DeepTech sp. z o.o. — CTO (system owner), approved by the Management Board |
| Version | 1.2 |
| Status | Pending management approval (Management Board of DeepTech sp. z o.o.) |
| Effective | On approval — October 2026 (supersedes v1.1, v1.0 and Draft v0.9) |
| Review | Every 12 months or after a material change |
| Classification | Public |
DeepTech sp. z o.o. engages the subprocessors listed below to operate the Audomate platform and the services around it. All platform subprocessors process client data exclusively in EEA regions. This list forms Annex IV to our Data Processing Agreement (DPA; in legal review by an external law firm since 10 October 2026) and is kept current in the Trust Center; the internal supplier register holds the evidence behind each row (contract, DPA, certificates, DPF check).
1. Scope
- Platform subprocessors (section 2, rows 1–5) — process data that clients entrust to the Audomate platform (uploaded documents, user accounts, audit results). Changes are subject to the 30-day notice in section 4.
- Website and business-operations providers (section 2, rows 6–9) — process personal data for which DeepTech is controller (website visitors, enquiries, invoicing, support). No CRM and no ticketing system are used; enquiries and support requests are handled by e-mail (sales@deeptech.pl, contact@deeptech.pl, support@audomate.eu). They are listed for completeness and transparency; they do not receive client content from the platform.
2. Subprocessors
| # | Subprocessor — legal entity and address | Role / purpose | Processing region | Categories of data | Transfer mechanism / safeguards |
|---|---|---|---|---|---|
| 1 | Google Cloud Platform — Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland (contracting entity confirmed against invoice, 10 October 2026) | Cloud infrastructure: compute (Cloud Run), Cloud SQL (PostgreSQL), Cloud Storage, Memorystore (Redis), Cloud KMS, Secret Manager, Cloud Logging / Monitoring | EEA — europe-west1 (Belgium, primary), europe-west3 (Germany, DR), europe-west4 (Netherlands, dual-region storage) | Encrypted client content (documents, vectors, reports), account data, audit trail and logs | Processing in the EEA; Google Cloud Data Processing Addendum (art. 28 GDPR). Google LLC is certified under the EU-U.S. Data Privacy Framework for residual support / telemetry access; SCC 2021/914 in the addendum |
| 2 | OpenAI API (EU data residency) — OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland | LLM inference (GPT-4o) and embeddings (text-embedding-3-large) for the contract-audit engine, via the OpenAI API | EU data residency — EU-region project, endpoint eu.api.openai.com | Prompts and completions containing fragments of client documents — transient only; Zero Data Retention (ZDR) and EU data residency enabled on the production project (OpenAI abuse monitoring otherwise keeps API logs for up to 30 days by default); no training on client data | Processing in the EEA; OpenAI API Services Agreement + OpenAI Data Processing Addendum (SCC 2021/914 included). Parent company OpenAI, L.L.C. (USA) is certified under the EU-U.S. Data Privacy Framework (relevant to support / telemetry only) |
| 3 | Auth0 (Okta) — Okta, Inc., 100 First Street, San Francisco, CA 94105, USA — tenant in the EU region | Identity provider: login, SSO (OIDC / SAML 2.0), MFA, federation with the client's own enterprise identity provider | EU — eu.auth0.com (AWS Frankfurt, Germany) | Platform users: first name, surname, business e-mail, role, authentication logs | Okta GDPR Data Processing Addendum in force; EU-U.S. Data Privacy Framework: listed — DPF status verified 10 October 2026 (screenshot on file); SCC 2021/914 in the Okta DPA |
| 4 | Vercel — Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA | Hosting and delivery of the Next.js front end (edge CDN) | EEA points of presence; geo-restriction to EEA | Transit traffic only (IP addresses, request headers); no client content at rest | Vercel Data Processing Addendum (SCC 2021/914); EU-U.S. Data Privacy Framework: listed — DPF status verified 10 October 2026 (screenshot on file) |
| 5 | PagerDuty — PagerDuty, Inc., 600 Townsend St, San Francisco, CA 94103, USA — EU data residency option | Alerting and on-call paging for platform incidents | EU (data residency enabled on our account) | Alert metadata (service name, severity, timestamps, on-call engineer contact); no client content | PagerDuty Data Processing Addendum (SCC 2021/914); EU-U.S. Data Privacy Framework: listed — DPF status verified 10 October 2026 (screenshot on file) |
| 6 | Plausible Analytics (website audomate.eu) — Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia | Cookieless website statistics | EU (Germany, Hetzner) | Anonymised, aggregated statistics; IP address and user agent only in memory with a salt rotated every 24 hours | No transfer outside the EEA; EU entity; Plausible DPA (art. 28 GDPR) |
| 7 | mOrganizer finansów (invoicing and accounting) — A service of mBank S.A., ul. Prosta 18, 00-850 Warsaw, Poland, KRS 0000025237 — delivered by mBank in cooperation with CashDirector S.A., Warsaw | Issuing invoices and keeping invoice records; processor of contact and billing data of clients and vendors | Poland / EEA | Invoice data of clients and vendors: company name, NIP, address, contact person, bank account numbers | No transfer outside the EEA; mOrganizer data processing agreement (art. 28 GDPR); the data processing agreement counterparty is CashDirector S.A. |
| 8 | Business e-mail provider — home.pl sp. z o.o., ul. Zbożowa 4, 70-653 Szczecin, Poland | Business mailboxes: enquiries and leads (sales@deeptech.pl, contact@deeptech.pl — no CRM system is used), support (support@audomate.eu), privacy@, security@, legal@audomate.eu. Support requests are handled by e-mail (support@audomate.eu); no third-party ticketing tool is used | Poland / EEA | Name, business e-mail, company, content of enquiries and support requests | Home.pl data processing terms (art. 28 GDPR); no transfer outside the EEA |
| 9 | External accounting office — EasyTaxes Sp. z o.o., ul. Warszawska 58C/56, 02-496 Warsaw, Poland, NIP 522-300-38-77 | Bookkeeping and accounting services for DeepTech (controller data only; no platform data) | Poland / EEA | Accounting documents and invoices: company name, NIP, address, contact person, bank account numbers; personnel and payroll accounting data where within the engagement | No transfer outside the EEA; processing terms under art. 28 GDPR |
3. How we vet subprocessors
Before a provider processes any data on our behalf, and at least annually thereafter, the CTO (system owner) performs the following checks and records the result in the internal supplier register:
- Contract — a data processing agreement meeting art. 28(3) GDPR is in place (documented instructions, confidentiality, security under art. 32, assistance with data subject rights and breach notification, deletion or return at the end of the service, audit rights, flow-down to the provider's own subprocessors under art. 28(4)).
- Location — the service is configured for EEA/EU processing (region, tenant or data-residency setting) and the configuration is verified in the provider console, not only in the contract.
- Security assurance — the provider holds current independent certifications or attestations appropriate to its role (ISO/IEC 27001, SOC 2 Type II, CSA STAR for cloud infrastructure); reports are obtained and reviewed.
- Third-country check — for providers established in the United States: the entity is verified on the EU-U.S. Data Privacy Framework list (dataprivacyframework.gov/list; Okta, Inc., Vercel Inc. and PagerDuty, Inc. verified on 10 October 2026, screenshots on file) and Standard Contractual Clauses (Decision 2021/914) are in place as the fallback mechanism; a transfer impact assessment is kept where residual access from outside the EEA is possible.
- Incident and exit terms — the provider commits to notify DeepTech of security incidents affecting our data without undue delay, and supports data export and deletion on exit (relevant for our clients' DORA obligations under art. 28 and 30 DORA).
4. Change notice
We provide clients with 30 days' written notice before a platform subprocessor is added or replaced, by e-mail to the named contacts recorded at onboarding and by updating this list in the Trust Center. Clients may object on reasonable, data-protection-related grounds within the objection window defined in the DPA; where no solution is found, the client may terminate the affected service as set out in the DPA.
5. Not subprocessors
Self-hosted components running inside DeepTech's own cloud tenancy — PostgreSQL (Cloud SQL), Qdrant / pgvector vector index, Redis (Memorystore), Celery workers — are part of the platform operated by DeepTech, not separate subprocessors. Professional advisers (legal, tax) act under professional secrecy and are not platform subprocessors. No CRM and no ticketing system are used.
6. Contact
Questions about this list: privacy@audomate.eu (Data Protection Coordinator: Kacper Raubo, kacper.raubo@deeptech.pl). Copies of subprocessor DPAs and the current DPF verification record are available to clients on request under NDA.
Document control
| Version | Date | Author | Approved by | Changes |
|---|---|---|---|---|
| 0.9 | September 2026 | DeepTech (CTO / CEO) | — (working draft, not adopted) | Working draft published for transparency; items marked "to confirm". |
| 1.0 | October 2026 | DeepTech (CEO / CTO) | — (superseded by 1.1) | Changes after the GDPR (RODO) / NIS2 audit of 7–8 October 2026: full legal entities, addresses, processing regions, data categories and transfer mechanisms added for every subprocessor; PagerDuty named as the alerting tool; Plausible Analytics added for the website; new section "How we vet subprocessors"; scope split into platform subprocessors and business-operations providers; billing, ticketing and CRM rows left as decisions. |
| 1.1 | 10 October 2026 | DeepTech (CEO / CTO / data protection coordinator) | Management Board — pending | Updates after Management Board decisions of 10 Oct 2026: row 2 replaced — LLM and embeddings provider is OpenAI Ireland Ltd (OpenAI API, EU data residency, Zero Data Retention), the previously listed cloud-reseller LLM service is not used; Google Cloud EMEA Limited confirmed against invoice; DPF status of Okta, Vercel and PagerDuty verified 10 Oct 2026; mOrganizer finansów (mBank S.A.) added as invoicing provider; ticketing and CRM rows removed (not used — e-mail only); business e-mail provider row kept as open item; DPA in legal review (law firm) since 10 Oct 2026. |
| 1.2 | 11 October 2026 | DeepTech (CEO / CTO / data protection coordinator) | Management Board — pending | Open items closed on the basis of Management Board answers of 11 Oct 2026: row 8 — Home.pl named as business e-mail provider; row 9 added — EasyTaxes Sp. z o.o. (external accounting office); row 7 — data processing agreement counterparty is CashDirector S.A.; row 5 — EU data residency in PagerDuty confirmed; row 2 — EU data residency and Zero Data Retention enabled on the production OpenAI project. |