Subprocessors
The third parties Praesidia engages to help provide the Service, and what each one does.
Last reviewed: July 2026. We will update this list, and give notice here (and by email on request), before adding or replacing a sub-processor, consistent with Article 28(2)–(3) GDPR. To be notified of changes directly, email privacy@praesidia.ai with the subject "Subprocessor updates."
| Subprocessor | Purpose | Data involved | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure: compute, storage, key management, and message queuing for the platform | All account and platform data | Region varies by deployment — contact privacy@praesidia.ai to confirm the region for your account |
| Stripe, Inc. | Payment processing, invoicing, and subscription billing | Billing contact details and payment data | United States (PCI DSS Level 1 certified) |
| Mailgun (Sinch) | Transactional email delivery (account, security, and product notifications) | Name, email address, and the content of transactional emails | United States |
| Sentry | Application error monitoring and crash diagnostics | Technical error data, which may incidentally include limited account identifiers | Confirm with privacy@praesidia.ai |
| Sigstore (Rekor public transparency log) | Optional independent anchoring of audit-log integrity proofs, where enabled for your organization | A cryptographic hash of a Merkle root only — never your underlying records | Public, community-operated infrastructure (not a commercial vendor) |
| OpenAI, L.L.C. (platform-operated) | Default model inference for organizations that have not connected their own model-provider API key | Prompt and response content for agent runs on the platform default model | United States |
Platform-default model inference
An organization that has not connected its own API key for a model provider still runs on a working default so agents function out of the box. That default is Praesidia's own OpenAI account, under Praesidia's own key — this is the common state for a new or trial organization, not an edge case, and it is a Praesidia-selected sub-processor: prompt and response content for that organization's agent runs is sent to OpenAI under our account, not yours. Connecting your own model-provider key (see below) replaces this default for your organization.
Your own configured AI model providers
If you connect your own API key for a model provider (for example OpenAI, Google Gemini, Mistral AI, or Cohere), Praesidia routes your requests to that provider under your own account and key, and only to the provider(s) you configure — replacing the platform default described above. If you run a self-hosted provider (for example Ollama), no third party receives your data through that connection at all. We treat this as processing you direct, on your own account with that provider, rather than a Praesidia-selected sub-processor — but it is listed here for completeness, since prompt and response content does leave Praesidia's infrastructure to reach whichever provider you choose.
Questions
For anything not covered above, or to request more detail for a vendor-security questionnaire, email privacy@praesidia.ai. See also our Data Processing Agreement and Privacy Policy.