Skip to main content

Legal · Transparency

Subprocessors

Last updated: 18 May 202612 authorised providers

To deliver the Codaiq platform, we rely on a small set of carefully selected subprocessors. This page lists every third-party service that may process customer Personal Data on our behalf. It is referenced by, and forms Annex 1 to, our DPA.

Get notified of changes

To get notified of subprocessor changes, email info@codaiq.com with the subject "Subprocessor notifications". We will notify you 30 days before any addition or change so you can exercise your right of objection under section 7 of the DPA.

SubprocessorPurposeCountryDPA
Anthropic, PBCLLM (Claude)USADPA
Inngest, Inc.Background JobsUSADPA
MongoDB Atlas (MongoDB, Inc.)Database HostingUSA / IrelandDPA
OpenAI Ireland LtdLLM (GPT)Ireland / USADPA
OpenRouter, Inc.LLM GatewayUSAPrivacy
Pollinations.ai (Stichting Pollinations)AI Image GenerationGermanyDPA on request
Railway Corp.Infrastructure-as-a-ServiceUSADPA
Resend, Inc.Transactional EmailUSADPA
Sentry (Functional Software, Inc.)Error TrackingUSADPA
Stripe Payments Europe LtdPayment ProcessingIrelandDPA
Upstash, Inc.Rate-Limit RedisUSADPA
Vercel, Inc.CDN / Edge Hosting (Frontend)USADPA

All US subprocessors are bound by EU Standard Contractual Clauses Module 2 (Controller-to-Processor) and the UK IDTA Addendum where applicable. Where a subprocessor is certified under the EU-US Data Privacy Framework, we additionally rely on that adequacy decision.

We do not sell customer data. Subprocessors are contractually prohibited from using customer Personal Data for any purpose other than providing services to Codaiq.

For data-protection enquiries, write to info@codaiq.com or by post to Codaiq LTD, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom (Companies House No. 16537316).

Command Palette

Search for a page or run an action.