Skip to content

Subprocessors

Last updated: September 7, 2026

These are the third parties that may receive data while providing INFRO. Infrastructure and model vendors process data on our behalf and form part of our data processing agreement. Payment providers may instead act as independent controllers for buyer information, as identified below. The list is kept current — see Changes below for how you are told when it moves.

Infrastructure

SubprocessorRoleWhat it processesLocation
Cloudflare, Inc.Compute, edge network, object storage, key-value cache, email deliveryAll API traffic in transit. Generated media at rest. Transactional email bodies and recipient addresses.Global edge; requests are served from the location nearest the caller
Neon, Inc.Managed PostgreSQL — the source of truth for accounts, usage and the credit ledgerAccount and organisation records, API key hashes, usage metadata, the credit ledger. Prompt and completion content only if you have opted in to logging.eu-central-1 (Frankfurt)

Payment providers

The provider shown at checkout receives the information needed to complete and support that transaction. Payment providers do not receive API request content: no prompts, no completions, and no API keys. Where the provider acts as merchant of record it is an independent controller of buyer information and its own buyer privacy notice applies in addition to ours. It is named before you pay and on every receipt.

SubprocessorRoleWhat it processesLocation
Payment provider — named at checkoutProcessing the purchase and, where it acts as merchant of record, selling the credit to you and handling tax, receipts, refunds, and chargebacksBuyer identity and contact data, payment method details, tax location, transaction records, receipts, refunds, and fraud signals. Card details are entered on the provider's hosted checkout and never reach INFRO.Varies by provider and by buyer location; named before you pay

Model providers are not INFRO subprocessors

This is the section most likely to be skimmed, and it is the one that changes a vendor review, so it is stated plainly.

INFRO does not engage any AI provider on your behalf. You connect provider accounts you already hold. The contract is between you and that provider, you accepted their terms, and you are their controller directly. When your request reaches OpenAI or Anthropic or Bedrock, it reaches them under your credentials on your account — exactly as it would if your application had called them without INFRO in the path.

A subprocessor is a party we engage to process your data. No model provider is in that position, so none is listed here and none can be. The parties above — hosting, database, storage, email, payments — are the complete set of subprocessors, because they are the complete set of vendors INFRO has engaged.

The practical consequence for a review: the model providers in your AI stack are governed by the agreements you already have with them, and you can name them, locate them and audit them without asking us. The page that used to sit here offered a categorised list with the names available under NDA, because INFRO held those accounts. It no longer does, and the question that arrangement existed to answer does not arise.

If an agreement with INFRO ever includes capacity we provide ourselves rather than routing to your own accounts, the providers behind it are named in that agreement before it is signed. It is not part of the standard product and nothing on this site sells it.

What none of them see

  • Your prompts and completions are not stored by default. Content logging is a per-organisation opt-in with a retention window you choose. See privacy.
  • No provider is used to train a model on your data. Every commercial agreement we hold excludes it.
  • No analytics vendor sees API traffic. The marketing site uses cookieless analytics; the API and the console carry none.

Changes

We add subprocessors as the platform grows. Adding a model provider is not one of them — those are yours, not ours. Account owners are notified by email at least 30 days before a new subprocessor begins processing customer data, and you may object in writing during that window; if we cannot accommodate an objection, you may terminate the affected processing. Your subscription remains available for compatible INFRO services and is governed by the refund policy.

Emergency additions — infrastructure brought in to restore service during an outage — are notified within 72 hours instead, because the alternative is an outage we could have ended sooner.

Questions, or a vendor questionnaire to complete: sales@infro.io.