Skip to main content

Subprocessor List

Last updated: October 2026

We use a small number of third-party services ("subprocessors") that may process personal data or tenant content on our behalf. Each is listed below with its purpose, region (where known), when the data path is active, and how it can be disabled or limited.

Keycloak, our authentication provider, is self-hosted software running inside our own infrastructure; it is not a subprocessor. We do not use third-party error telemetry or analytics services.

SubprocessorPurposeData that may be sentRegionWhen activeHow to disable or limit
StripeSaaS billing: payment processing, invoicesCustomer/payment records (name, email, billing details)USSaaS billing (not used in on-prem deployments)Not disable-able while SaaS billing is used; on-prem deployments do not call Stripe
Postmark (SaaS)Transactional email (password resets, invites, billing notices, app email)User emails, names, email contentUSAll SaaS deploymentsOn-prem deployments configure their own email provider
External LLM providers (OpenAI, Anthropic, Groq, Mistral, Google, or a custom endpoint)Assistant, orchestrator, and tool-calling node inferencePrompt and conversation content, which may include personal dataDepends on the provider you bindOnly when your tenant has opted in and an external LLM binding is configured (opt-in gate is on by default: external requests are refused unless your tenant opts in)Remove the binding, or keep the per-tenant opt-in gate off; each provider's own subprocessor list must be flowed down
NVIDIA (NIM endpoints)NIM node execution (CV/grounding inference)Node inputs (images/text) posted to NVIDIA inference endpointsUSWhen NIM nodes run (platform off-switch available)Disable the NIM egress switch; no NIM node runs occur
SlackRun/notification delivery to tenant workspacesNotification payloads (can carry run names)US (Slack's hosting region applies)When your tenant has connected a Slack workspaceDisconnect the tenant's Slack integration
Hugging FaceGated model/repository downloads during node buildsAccess token and tenant model references (tenant-identifying; personal data unlikely)Depends on Hugging Face hostingGated model downloads with an access token configuredDo not use gated repositories; model cache reduces runtime fetches
Tailscale public relaysMesh relaying when direct connections failMesh traffic transits relaysUSOnly if public relays are configured for meshPoint mesh at our self-hosted relay or your own tailnet instead of public relays
MOD hosting (SaaS)SaaS infrastructure: app serving, compute, storage, cacheCustomer data, workflow runs, files, metricsUSSaaS deployments (on-prem installs run on your own network)On-prem deployments do not use MOD-operated infrastructure

Transfers and safeguards​

SaaS customer data is processed in the United States. If you are located in the EU or UK, your personal data is transferred to our US infrastructure under the Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum (IDTA), both included in our Data Processing Agreement.

Where data is transferred to a subprocessor in a different jurisdiction than where your data is stored, we rely on contractual safeguards, including Standard Contractual Clauses (SCCs) where applicable. The DPA/SCC status per processor is a living document; if you need the current status for your compliance records, contact legal@modtechlabs.com.

Changes​

We will update this list when we add or remove subprocessors. Material changes are communicated via email in accordance with our Privacy Policy.

Contact​

Data Protection Officer: privacy@modtechlabs.com Legal: legal@modtechlabs.com