Subprocessor List
Last updated: October 2026
We use a small number of third-party services ("subprocessors") that may process personal data or tenant content on our behalf. Each is listed below with its purpose, region (where known), when the data path is active, and how it can be disabled or limited.
Keycloak, our authentication provider, is self-hosted software running inside our own infrastructure; it is not a subprocessor. We do not use third-party error telemetry or analytics services.
| Subprocessor | Purpose | Data that may be sent | Region | When active | How to disable or limit |
|---|---|---|---|---|---|
| Stripe | SaaS billing: payment processing, invoices | Customer/payment records (name, email, billing details) | US | SaaS billing (not used in on-prem deployments) | Not disable-able while SaaS billing is used; on-prem deployments do not call Stripe |
| Postmark (SaaS) | Transactional email (password resets, invites, billing notices, app email) | User emails, names, email content | US | All SaaS deployments | On-prem deployments configure their own email provider |
| External LLM providers (OpenAI, Anthropic, Groq, Mistral, Google, or a custom endpoint) | Assistant, orchestrator, and tool-calling node inference | Prompt and conversation content, which may include personal data | Depends on the provider you bind | Only when your tenant has opted in and an external LLM binding is configured (opt-in gate is on by default: external requests are refused unless your tenant opts in) | Remove the binding, or keep the per-tenant opt-in gate off; each provider's own subprocessor list must be flowed down |
| NVIDIA (NIM endpoints) | NIM node execution (CV/grounding inference) | Node inputs (images/text) posted to NVIDIA inference endpoints | US | When NIM nodes run (platform off-switch available) | Disable the NIM egress switch; no NIM node runs occur |
| Slack | Run/notification delivery to tenant workspaces | Notification payloads (can carry run names) | US (Slack's hosting region applies) | When your tenant has connected a Slack workspace | Disconnect the tenant's Slack integration |
| Hugging Face | Gated model/repository downloads during node builds | Access token and tenant model references (tenant-identifying; personal data unlikely) | Depends on Hugging Face hosting | Gated model downloads with an access token configured | Do not use gated repositories; model cache reduces runtime fetches |
| Tailscale public relays | Mesh relaying when direct connections fail | Mesh traffic transits relays | US | Only if public relays are configured for mesh | Point mesh at our self-hosted relay or your own tailnet instead of public relays |
| MOD hosting (SaaS) | SaaS infrastructure: app serving, compute, storage, cache | Customer data, workflow runs, files, metrics | US | SaaS deployments (on-prem installs run on your own network) | On-prem deployments do not use MOD-operated infrastructure |
Transfers and safeguards
SaaS customer data is processed in the United States. If you are located in the EU or UK, your personal data is transferred to our US infrastructure under the Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum (IDTA), both included in our Data Processing Agreement.
Where data is transferred to a subprocessor in a different jurisdiction than where your data is stored, we rely on contractual safeguards, including Standard Contractual Clauses (SCCs) where applicable. The DPA/SCC status per processor is a living document; if you need the current status for your compliance records, contact legal@modtechlabs.com.
Changes
We will update this list when we add or remove subprocessors. Material changes are communicated via email in accordance with our Privacy Policy.
Contact
Data Protection Officer: privacy@modtechlabs.com Legal: legal@modtechlabs.com