Sub-processor List
About this list
Org AI LLC ("Org AI") provides the organization.ai platform. Where we process personal data on behalf of a customer organization, we act as a processor and the customer acts as the controller, as set out in our Data Processing Agreement (DPA).
To deliver the Services we engage the third parties listed below ("sub-processors"). Each is engaged under the terms that apply to our use of it, which:
- restrict them to processing personal data in order to provide their service to us;
- impose confidentiality and security obligations; and
- where relevant, incorporate the European Commission's Standard Contractual Clauses (and the UK Addendum) for transfers out of the EEA, UK, or Switzerland.
Where the sub-processor is an AI provider, we configure the controls it makes available and rely on the terms that apply to our use of it so that content we submit is not used to train, fine-tune, or otherwise improve its models. This applies to requests we make through our own provider accounts; where a customer uses its own provider account (see section 5), that provider's own terms govern instead.
1. Infrastructure sub-processors
These are engaged for every customer. They host and protect the Services.
| Sub-processor | Service provided | Personal data processed | Primary processing location |
|---|---|---|---|
| Amazon Web Services (AWS) | Core infrastructure: compute, document and file storage, key management and encryption, databases, and outbound email delivery | All categories, including account data and Customer Content at rest | EU (Frankfurt, eu-central-1) by default; additional regions where a customer selects a different home region |
| Cloudflare | Website and application delivery, and protection against abuse | Connection metadata, including IP address and request headers | Global edge network |
| PlanetScale | Managed database for account, workspace, and configuration data | Account and member records, workspace configuration, document metadata, encrypted credentials | EU (eu-central-1) |
| Qdrant | Managed vector search index used to search a Company Brain | Vector representations (embeddings) of Customer Content, short text excerpts, and related metadata | EU (eu-central-1) |
2. Connector sub-processor
Engaged only where a customer chooses to connect a third-party application to its Company Brain.
| Sub-processor | Service provided | Personal data processed | Primary processing location |
|---|---|---|---|
| Pipedream | Authorizing a customer's connected applications and retrieving data from them | OAuth authorizations and credentials for the connected application, and the Customer Content retrieved through it | United States |
3. Business operations sub-processors
| Sub-processor | Service provided | Personal data processed | Primary processing location |
|---|---|---|---|
| Stripe | Payment processing, billing, and invoicing | Billing contact details, payment instrument data, transaction records | United States and global |
| Google (Analytics, Tag Manager) | Usage analytics on our own websites and platform-hosted pages | Usage and device data, including IP address and online identifiers | United States and global |
4. AI sub-processors
Engaged when a user invokes an AI feature. Which provider handles a given request depends on the feature and on the configuration chosen by the customer's administrators, who can restrict or disable providers. For every provider below, we configure the controls it makes available and rely on the terms that apply to our use of it so that submitted content is not used to train or improve models.
| Sub-processor | Service provided | Personal data processed | Primary processing location |
|---|---|---|---|
| Anthropic | Large language model inference | Text submitted for the request, and the output | United States |
| OpenAI | Large language model inference | Text submitted for the request, and the output | United States |
| Google Cloud AI | Large language model inference | Text submitted for the request, and the output | United States |
| Microsoft Azure AI | Large language model inference | Text submitted for the request, and the output | United States |
| Amazon Bedrock | Large language model inference | Text submitted for the request, and the output | United States |
| Together.ai | Open-model inference | Text submitted for the request, and the output | United States |
| Groq | Low-latency open-model inference; image captioning | Text or image submitted for the request, and the output | United States |
| Hugging Face | Text embedding for search indexing and query matching | Text of Customer Content and of search queries | United States |
| Perplexity | Retrieval-augmented model inference | Text submitted for the request, and the output | United States |
| xAI | Large language model inference | Text submitted for the request, and the output | United States |
| DeepSeek | Open-model inference, reached via OpenRouter | Text submitted for the request, and the output | See OpenRouter note below |
| OpenRouter | Model routing (aggregator). Forwards a request to a further model host | Text submitted for the request, and the output | United States, plus the onward host's location |
Note on OpenRouter. OpenRouter is an aggregator rather than a model host. Where a request is routed through OpenRouter, it is forwarded to a further model host to produce the output. That onward host processes the submitted text under its own terms; our configuration reaches the aggregator, not the onward host. Customers who do not wish requests to be routed through an aggregator can disable OpenRouter for their organization.
5. Customers who use their own AI provider account (BYOK)
A customer may supply its own AI provider API key ("bring your own key"). Where it does, requests for that customer are sent to that provider through the customer's own account, under the agreement between the customer and that provider. In that arrangement the provider is not our sub-processor for that customer's requests, and that provider's own data-retention and training terms apply. We store the supplied key encrypted and use it only to make requests on that customer's behalf.
6. Affiliates
We may use our own group companies to provide parts of the Services. Any such affiliate is bound by the same obligations as a third-party sub-processor.
7. Changes to this list
We will update this page before engaging a new sub-processor, or before an existing sub-processor takes on a materially different role.
Change notice. Customers may email support@organization.ai to be notified of changes to this list, and receive notice at least 30 days before a new sub-processor begins processing personal data.
Objection. As set out in the DPA, a customer may object on reasonable data-protection grounds within the notice period. We will work in good faith to address the objection, for example by making the relevant sub-processor optional for that customer where technically possible. If we cannot, the customer may terminate the affected part of the Services in line with the DPA.
8. Contact
Questions about this list, or about our DPA, can be sent to support@organization.ai.
Org AI LLC
1007 N. Orange Street
4th Floor, Suite 1382
Wilmington, DE 19801
United States
1007 N. Orange Street
4th Floor, Suite 1382
Wilmington, DE 19801
United States