This list identifies service providers that DIRI AI may use to process personal data for the functions described below. A function is used only when it is enabled for the relevant service. The contracting entity stated in DIRI AI's applicable provider agreement controls if a provider uses different entities by customer location or service plan.
| Provider / applicable contracting entity | Purpose and categories of data |
|---|---|
| Vercel Inc. | website and application delivery, including BFF request processing; account, request, device, network and security data |
| Render Services, Inc. | API and worker hosting; account, Customer Content, usage, audit and operational-log data |
| Neon database service / entity stated in the applicable agreement | managed PostgreSQL database; account, workspace, Customer Content, subscription and audit data |
| Upstash, Inc. | managed Redis, rate limits, queues and short-lived operational state; identifiers and limited operational data |
| Cloudflare, Inc. | DNS, routing, network security, Turnstile where enabled and object storage where enabled; network, security and object data |
| Plus Five Five, Inc. (Resend) | transactional-email sending, suppression handling and signed delivery events; recipient, message, delivery and complaint data |
| Google Workspace - Google Ireland Limited and/or Google LLC, as stated in the agreement | business-email hosting, routing, spam and security controls, storage and retrieval; sender, recipient, message content, attachments and metadata |
| Google Analytics 4 - Google Ireland Limited, subject to the applicable account agreement | consent-based traffic measurement on allowlisted public diriai.com pages; first-party cookie identifiers, normalized host/path and bounded events, plus browser/network metadata including IP address and user agent |
| Stripe Payments Europe, Limited and relevant Stripe affiliates | Checkout, subscriptions, invoices, payment status, payment-method signals, fraud prevention and tax evidence |
| Functional Software, Inc. (Sentry) | sanitised application-error and performance telemetry; error, path, device/network and limited user identifiers |
| OpenAI Ireland Limited and/or the OpenAI entity stated in the applicable agreement | requested AI simulations, transcription, analysis and reports; prompts and the Customer Content necessary for the requested function |
| Eleven Labs Inc. | requested speech synthesis and voice processing; text, audio, language, voice/profile identifiers and technical metadata |
| GitHub, Inc. | source control and continuous integration; developer identities, code and operational build logs; Customer Content is not intended for this route |
Google Analytics is the only optional marketing-analytics provider covered by this list.
It may load only after affirmative consent on a supported English or Czech public marketing page on
diriai.com or www.diriai.com.
DIRI AI does not send query strings, URL fragments, external referrer URLs, free text, account or
customer identifiers, call content, transcripts, payment data or User-ID in its Analytics event
payload. Google nonetheless receives ordinary browser/network transport metadata when a consented
request is made. The configured Analytics property has one web stream for the supported public
pages. Enhanced Measurement, Google Signals, advertising features, advertising personalisation,
audiences, Google Ads links and User-ID are off. User-level and event-level data retention is two
months, with reset on new activity off.
Umami, Vercel Web Analytics, Vercel Speed Insights, Cloudflare Web Analytics, pixels, replay, heatmaps and advertising services are not included as analytics subprocessors under this list. Vercel and Cloudflare remain listed above only for their separate hosting, DNS, routing, storage or security functions.
Provider locations, remote access and onward transfers depend on the applicable service, customer location and provider agreement. Where GDPR transfer restrictions apply, DIRI AI uses an applicable adequacy decision, the European Commission Standard Contractual Clauses with an assessment and supplementary measures, or another lawful safeguard. No provider location, certification or contractual safeguard is described as exclusive unless the applicable agreement and technical configuration make it so.
Google Ireland Limited is the contracting entity under the applicable Google Analytics account agreement and Google Ads Data Processing Terms. Those processing terms describe Google as a processor for Customer Personal Data within the applicable Processor Services and permit processing where Google or its subprocessors maintain facilities. The applicable account agreement, processing terms and transfer safeguards govern that processing.
Stripe and another provider may act as an independent controller for its own regulated payment, fraud-prevention, security or legal-compliance purposes. Its own privacy notice governs that independent processing. Google Workspace is the direct business-mail and MX service for the role addresses; consumer mailbox services and forwarding to them are not part of this listed route.
Changes and objections for business customers
DIRI AI will give business customers at least 30 days' advance notice before authorising a new subprocessor that will process Customer Personal Data, except where an urgent replacement is needed for security, law or service continuity. A customer may make a reasoned written objection based on data-protection grounds during the notice period. The parties will try to resolve it through reasonable safeguards; if no reasonable solution exists, the affected processing may be stopped or the affected service terminated under the DPA.
Subprocessor questions and notice subscription: privacy@diriai.com. Public list URL: https://diriai.com/en/legal/subprocessors.
Version: 1.2.0. Effective date: 30 August 2026.