OWNER-APPROVED ENGLISH VERSION — EFFECTIVE 26 AUGUST 2026. Version 1.0.0. Independent Czech legal review is recommended but has not been obtained. This English document applies only where English satisfies applicable language requirements. Publication does not enable paid signup, Stripe Live, a blocked territory or an unverified product capability.
This list covers providers that may process personal data for DIRI AI. A provider shown as “gated” must not receive public-production Customer Personal Data until its gate is complete.
| Provider / contracting entity to verify | Purpose and likely data | Configured or intended region | Status on effective date |
|---|---|---|---|
| Vercel Inc. | public web hosting, application delivery and BFF request processing; network and account data | global edge; region and transfer paths to verify | infrastructure in use; exact production data path and DPA evidence to approve |
| Render Services, Inc. | API and worker hosting; account, content, usage and logs | Frankfurt, Germany intended | configured; production readiness remains approval-gated |
| Neon / applicable Databricks or Neon contracting entity | PostgreSQL database; account, workspace, content, subscription and audit data | Frankfurt, Germany intended | configured; current contracting entity, DPA and backup/deletion cycle to verify |
| Upstash, Inc. | Redis caching, rate limits, queues or ephemeral state; identifiers and limited operational data | Frankfurt, Germany intended | configured; DPA, persistence and deletion settings to verify |
| Cloudflare, Inc. | DNS, routing, security, email routing, optional Turnstile and R2 object storage; network, security and stored-object data | global network; R2 Eastern Europe intended | partial infrastructure configured; each feature's activation and transfer path to verify |
| Plus Five Five, Inc. (Resend) | transactional email delivery, suppression and signed delivery webhooks; contact and message metadata/content | selected regional sending where available | configured and controlled delivery tested; ordinary customer sending remains launch-gated |
| Stripe Payments Europe, Limited and relevant Stripe affiliates | Checkout, subscriptions, invoices, payment status, fraud and tax evidence | EEA and global Stripe network | sandbox/test only; Stripe Live, tax treatment and final DPA/controller roles unresolved |
| Functional Software, Inc. (Sentry) | sanitised application error and performance telemetry; path, error, device/network and limited user identifiers | EU data region intended | configured; quota and exact-release issue/alert evidence incomplete |
| OpenAI Ireland Limited and/or applicable affiliate | text model processing for requested simulations, analysis or reports; prompts and necessary Customer Content | provider-controlled locations subject to enterprise settings | public production calls fail closed; contract, zero/limited-retention settings and transfer assessment required |
| Eleven Labs Inc. | speech synthesis or voice processing for requested training sessions; text, audio and technical metadata | provider-controlled locations | public production calls fail closed; DPA, retention settings, approved models/languages and transfer assessment required |
| GitHub, Inc. | source control and CI; developer identities, code and operational build logs | provider global infrastructure | operational provider; Customer Content must not be placed in source or ordinary CI logs |
The effective list must remove providers that do not process personal data and must clearly distinguish a processor from an independent controller. Stripe may act independently for regulated payment, fraud and compliance purposes; the effective Privacy Policy must describe that role.
Changes and objections for business customers
DIRI AI will give business customers at least 30 days' advance notice before authorising a new subprocessor that will process Customer Personal Data, except where an urgent replacement is needed for security, law or service continuity. A customer may make a reasoned written objection based on data-protection grounds during the notice period. The parties will try to resolve it through reasonable safeguards; if no reasonable solution exists, the affected processing may be stopped or the affected service terminated under the DPA.
Paid activation remains disabled unless a subscription mechanism, versioned archive and delivery path can support the 30-day notice commitment.
Subprocessor questions and notice subscription: privacy@diriai.com. Public list URL: https://diriai.com/legal/subprocessors. Effective version: 1.0.0. Effective date: 26 August 2026.