AllAddin

Sub-processor Register

Maintained in our compliance database.

Under UK GDPR Article 28, we disclose every sub-processor that handles personal data on behalf of AllAddin customers. The DPA column links to each provider's own Data Processing Agreement. A machine-readable copy of this register is available at /api/sub-processors.

Active sub-processors

Name Purpose Data categories Transfer region DPA
RailwayApplication hosting and managed Postgresapplication data, request logs, postgres rowsUS-DPFDPA
AnthropicClaude API for code generation and analysisprompts, completionsUS-SCCDPA
GitHubSource code hosting, issue tracking, CIsource code, CI artefactsUS-DPFDPA
SentryError monitoring with send_default_pii disabledstack traces, request metadataEEADPA
MistralText embeddings for corpus and keynote searchchat query text, corpus text snippets, keynote textEEADPA
Cloudflare R2Object storage for published share-link payloadsshare-link ciphertext (client-side-encrypted dashboard workspaces)EEADPA

Notifications of changes

When we add or remove a sub-processor, the change is recorded in our internal Trust Ledger (a hash-chained audit log) and this page updates immediately. Customers under an active Data Processing Agreement are notified in advance by email.

Contact

Questions about this register go to security@alladdin.dev.