Skip to content
DIRI AI

DIRI AI legal

DIRI AI Subprocessor List

Version 1.0.0Effective 26 August 2026Owner-approved English version

OWNER-APPROVED ENGLISH VERSION — EFFECTIVE 26 AUGUST 2026. Version 1.0.0. Independent Czech legal review is recommended but has not been obtained. This English document applies only where English satisfies applicable language requirements. Publication does not enable paid signup, Stripe Live, a blocked territory or an unverified product capability.

This list covers providers that may process personal data for DIRI AI. A provider shown as “gated” must not receive public-production Customer Personal Data until its gate is complete.

Provider / contracting entity to verifyPurpose and likely dataConfigured or intended regionStatus on effective date
Vercel Inc.public web hosting, application delivery and BFF request processing; network and account dataglobal edge; region and transfer paths to verifyinfrastructure in use; exact production data path and DPA evidence to approve
Render Services, Inc.API and worker hosting; account, content, usage and logsFrankfurt, Germany intendedconfigured; production readiness remains approval-gated
Neon / applicable Databricks or Neon contracting entityPostgreSQL database; account, workspace, content, subscription and audit dataFrankfurt, Germany intendedconfigured; current contracting entity, DPA and backup/deletion cycle to verify
Upstash, Inc.Redis caching, rate limits, queues or ephemeral state; identifiers and limited operational dataFrankfurt, Germany intendedconfigured; DPA, persistence and deletion settings to verify
Cloudflare, Inc.DNS, routing, security, email routing, optional Turnstile and R2 object storage; network, security and stored-object dataglobal network; R2 Eastern Europe intendedpartial infrastructure configured; each feature's activation and transfer path to verify
Plus Five Five, Inc. (Resend)transactional email delivery, suppression and signed delivery webhooks; contact and message metadata/contentselected regional sending where availableconfigured and controlled delivery tested; ordinary customer sending remains launch-gated
Stripe Payments Europe, Limited and relevant Stripe affiliatesCheckout, subscriptions, invoices, payment status, fraud and tax evidenceEEA and global Stripe networksandbox/test only; Stripe Live, tax treatment and final DPA/controller roles unresolved
Functional Software, Inc. (Sentry)sanitised application error and performance telemetry; path, error, device/network and limited user identifiersEU data region intendedconfigured; quota and exact-release issue/alert evidence incomplete
OpenAI Ireland Limited and/or applicable affiliatetext model processing for requested simulations, analysis or reports; prompts and necessary Customer Contentprovider-controlled locations subject to enterprise settingspublic production calls fail closed; contract, zero/limited-retention settings and transfer assessment required
Eleven Labs Inc.speech synthesis or voice processing for requested training sessions; text, audio and technical metadataprovider-controlled locationspublic production calls fail closed; DPA, retention settings, approved models/languages and transfer assessment required
GitHub, Inc.source control and CI; developer identities, code and operational build logsprovider global infrastructureoperational provider; Customer Content must not be placed in source or ordinary CI logs

The effective list must remove providers that do not process personal data and must clearly distinguish a processor from an independent controller. Stripe may act independently for regulated payment, fraud and compliance purposes; the effective Privacy Policy must describe that role.

Changes and objections for business customers

DIRI AI will give business customers at least 30 days' advance notice before authorising a new subprocessor that will process Customer Personal Data, except where an urgent replacement is needed for security, law or service continuity. A customer may make a reasoned written objection based on data-protection grounds during the notice period. The parties will try to resolve it through reasonable safeguards; if no reasonable solution exists, the affected processing may be stopped or the affected service terminated under the DPA.

Paid activation remains disabled unless a subscription mechanism, versioned archive and delivery path can support the 30-day notice commitment.

Subprocessor questions and notice subscription: privacy@diriai.com. Public list URL: https://diriai.com/legal/subprocessors. Effective version: 1.0.0. Effective date: 26 August 2026.

DIRI AI Subprocessor List | DIRI AI