Draft informational page. Content remains subject to final legal review and is not final counsel-approved text.
Closed Beta legal version: bundle 2026-07-28-cb1 · document 2026-07-28
This page discloses third parties that may process personal data to operate ZWIMA AI. It does not claim that DPAs, SCCs, or counsel sign-off are complete, and it is not presented as a final effective legal instrument.
Sub-processors
Unterauftragsverarbeiter
Last updated: 2026-07-21
Purpose of this page
Zwima Technologie GmbH publishes this draft list so customers can see categories and current architecture candidates used to provide the service. Pair with our Privacy Policy and DPA.
AI model providers
- Invoked only when the customer requests them, routing policy allows, and permissions permit
- We do not guarantee that every request is sent to the same provider
- Specific provider, model, version, and processing region should be recorded in operational logs
- Customers may restrict providers or regions where enterprise configuration allows
- While
LIVE_PROVIDER_CALLS_ENABLED=false, the platform must not make real model calls
Current architecture candidates include OpenAI, Google Gemini, Anthropic, DeepSeek, and Qwen — status remains provider-specific and disabled for live inference until Live Provider launch is approved.
International transfers
Processing outside the EU/EEA requires an applicable lawful transfer mechanism. SCCs, adequacy decisions, or other mechanisms that are not yet confirmed are marked LEGAL_REVIEW_REQUIRED. We do not claim that all vendors have completed final legal review.
Draft inventory
| Provider / Sub-processor | Service purpose | Data categories | Location / region | Transfer mechanism | Retention notes | Status |
|---|---|---|---|---|---|---|
| Vercel | Hosting, deployment, edge delivery and application infrastructure | Account-related request data, application logs, technical metadata as required to host the service | POLICY_PENDING / LEGAL_REVIEW_REQUIRED | LEGAL_REVIEW_REQUIRED | POLICY_PENDING | In use (platform infrastructure) |
| Supabase | Database, authentication-related storage where applicable, logs and application data | Application and account data, operational logs, structured platform records | POLICY_PENDING / LEGAL_REVIEW_REQUIRED | LEGAL_REVIEW_REQUIRED | POLICY_PENDING | In use (platform data store) |
| Clerk | User authentication, session management and identity services | Identity, authentication, and session data | POLICY_PENDING / LEGAL_REVIEW_REQUIRED | LEGAL_REVIEW_REQUIRED | POLICY_PENDING | In use (identity) |
| Resend (or current email service) | Transactional email delivery | Email address and message metadata for transactional mail | POLICY_PENDING / LEGAL_REVIEW_REQUIRED | LEGAL_REVIEW_REQUIRED | POLICY_PENDING | PENDING until production email provider is confirmed |
| Stripe | Payments, invoicing and billing | Billing contact and payment-related data as required for charges/invoices | POLICY_PENDING / LEGAL_REVIEW_REQUIRED | LEGAL_REVIEW_REQUIRED | POLICY_PENDING | PENDING / not enabled in Production (this launch phase) |
| AI model providers (category) | AI inference and model processing | Prompts, files, business data, and model outputs submitted via the API when a live call is authorised | Provider-specific — POLICY_PENDING / LEGAL_REVIEW_REQUIRED | LEGAL_REVIEW_REQUIRED (SCC / adequacy / other not finally confirmed) | POLICY_PENDING (also subject to customer instructions where ZWIMA is processor) | Provider-specific (OpenAI, Google Gemini, Anthropic, DeepSeek, Qwen as current architecture candidates); disabled for real calls while LIVE_PROVIDER_CALLS_ENABLED=false |
Last updated: 2026-07-21
Change notification policy
For material additions or replacements of sub-processors, we intend to notify via platform notice and/or the registered account email. Notice period: POLICY_PENDING. Enterprise contracts may set a separate objection period.