ES Technical meeting
Menu
01 — Scope

What this list covers and what it does not

A subprocessor is a third party Opendome calls on to process personal data on the customer's behalf. Article 28 of the GDPR requires each one to be assessed, to have a signed processing agreement and to appear in an inventory. We publish that inventory because it is the information an organisation needs before deciding, not after signing.

The relationship varies with the deployment model:

Managed service The full list set out below applies. Opendome operates the infrastructure and answers for the chain.
BYOC The infrastructure is supplied by the customer and is not a subprocessor of Opendome, which operates on top of it. The split is fixed in the agreement with the customer.
Third-party self-host Opendome introduces no subprocessor into the operator's deployment.

This page reflects the inventory as at the date shown. The living register — the criticality of each provider, its contractual status and the evidence of certifications — is maintained at trust.opendome.eu. In the event of any discrepancy, the portal's register prevails.

02 — Providers that process data

All of them reside in the EU or the EEA

No production customer data leaves the EU/EEA. Every provider that processes customer data resides in the EU/EEA. Providers that process only corporate or staff data may reside in a country covered by a European Commission adequacy decision.

Provider Service Data processed Location
Hetzner Online GmbH Compute, storage and DNS for the managed service; hosting of the website and the CMS Customer and corporate data EU · Germany and Finland
HostKey B.V. (Netherlands) GPU for the self-hosted models of the optional inference module Customer business data only where that module is contracted; no customer data flows through it today EU/EEA · contracted locations: Netherlands and Iceland; the provider’s other regions are not used
Infomaniak Network SA Corporate email, documents, video conferencing and calendar Staff data and internal content Switzerland · adequacy decision
Lettermint B.V. Outbound transactional email from the product Recipient addresses EU · Netherlands
Plausible Insights OÜ Website metrics, without cookies Aggregated browsing data, with no personal identifiers EU · Estonia
Netim SARL Domain registration Registration data EU · France
03 — Self-hosted components

Not providers: software that we operate

A good part of the platform consists of open source software that Opendome runs under its own control on the infrastructure described above. These are not independent subprocessors, because there is no third party processing the data: they inherit the assessment of the infrastructure provider.

It is a difference with practical consequences. Every equivalent component contracted as a third-party service would be one more subprocessor to assess, contract and monitor — and, frequently, one more outside the European Union.

Identity and access Identity provider, access plane and encrypted tunnels towards the customer's infrastructure.
Data platform Lakehouse in open formats, query engine, transformation and orchestration, state databases and object storage.
Consumption and inference Semantic layer, policy enforcement point and model gateway, together with the self-hosted models.
Internal support Work tracking, the compliance management system and task automation, all self-hosted.
04 — No access to data

Third parties that process no information

They are listed for transparency even though they are not subprocessors: they take part in the operation without accessing data belonging to Opendome or to its customers.

Provider Function Location
Let's Encrypt · ISRG TLS certificate authority: it validates domains, it does not process data United States
Hugging Face Download origin for the model artefacts: it does not process data United States
Apple Inc. Manufacturer of the team's devices: it does not process company data United States
05 — Documented exceptions

Three corporate tools outside the European Union

They have access to code, to internal technical context or to staff credentials, never to customer data. They are declared as an exception to the sovereignty principle because that is what they are, and because a list of subprocessors that leaves out the uncomfortable entries is of no use to anyone assessing us.

Provider Service Mitigation Target
GitLab Inc. Source code and continuous integration No customer data in the repositories. Staff account data is covered by the EU-US Data Privacy Framework or by standard contractual clauses Self-hosting in the EU or a European region
Anthropic, PBC Development assistance Entering secrets, customer data or personal data is prohibited A European alternative, or a self-hosted model on dedicated GPU in the EU/EEA
1Password · AgileBits, Inc. (Canada) Staff password manager (free choice, BYOPM) and custody of recovery material Organisation secrets do not live here: they reside in self-hosted OpenBao in the EU. EU data residency configured and MFA enforced OpenBao as the sole backend for organisation secrets

The Security Council accepted these exceptions as an assumed risk in a documented session, conditional on their not processing customer data and with the declared aim of migrating to a European alternative. The acceptance is recorded in the risk register with a review date and is reviewed at least once a year.

06 — Governance of the chain

How a provider comes in and how it goes out

No provider with access to data, systems or code is taken on without a prior assessment proportionate to its risk.

Onboarding

Prior assessment

Critical providers — those that host customer data, hold secrets or access the code — are required to hold a current security certification or equivalent evidence, to locate production data in the EU, and to sign a processing agreement where they process personal data. Taking on a critical provider requires collegiate approval by the Security Council.

In force

Contract and review

Every subprocessor that processes personal data has an agreement under Article 28 governing documented instructions, confidentiality, security measures, further subcontracting, assistance with rights and breaches, and return or deletion on termination. The inventory is reviewed at least annually and on every relevant addition or removal.

Offboarding

Controlled exit

When the relationship ends, credentials, keys and permissions are revoked without delay, and closure is verified. The provider is required to return or securely delete the data as agreed, with documented confirmation. The removal is reflected in the inventory and on this page.

The conditions for engaging subprocessors and the duty to inform the customer are governed by the processing agreement signed with each customer. The specific mechanism for communicating additions and removals is the one that agreement establishes.

Documentation for your assessment

If you need the model processing agreement, the contractual evidence for a particular provider or the detail of its assessment, write to us from the contact form or consult the trust portal.

Go to the trust portal