naetive
Log inSign up

Subprocessors

Disclaimer: This is a template document. Not legal advice. Have a Swedish data protection lawyer review before relying on it for production contracts. Last updated 2026-05-11.

Subprocessors

Last updated: 2026-05-11

Naetive engages the following sub-processors to deliver the Service. This list is incorporated by reference into the Data Processing Agreement at /legal/dpa.

A sub-processor is a third-party company that Naetive instructs to process personal data on Naetive's behalf. Not every company Naetive works with is a sub-processor — only those that handle personal data as part of delivering the Service are listed here.

The Routing Tier column indicates under which tiers the sub-processor is engaged (see the DPA Definitions section for a plain-language explanation of each tier).


1.AI providers — inference

These companies receive the text of AI requests (prompts) and return AI-generated responses. Which provider receives a given request depends on the Routing Tier declared in the Customer's Routing Manifest for that task category.

Company What they do Routing tiers Where data is processed
Mistral AI Runs Naetive's EU-Managed inference pool and the Auditor (Naetive's automated compliance reviewer) EU-Managed Routing; Auditor runs for all tiers France (EU)
OVH AI Endpoints Provides the data centre and API infrastructure through which Naetive accesses Mistral models for EU-Managed Routing and the Auditor EU-Managed Routing France (EU)
Scaleway Generative APIs Alternative or parallel infrastructure to OVH for EU-Managed Routing EU-Managed Routing France, Paris region (EU)
Anthropic Runs Claude-family AI models. Accessed only when the Customer selects Cost-Optimised Routing, or when the Customer designates Anthropic as their provider under Customer-Key Routing Cost-Optimised Routing; Customer-Key Routing (if Customer designates Anthropic) United States
OpenAI Runs GPT-family AI models. Same conditions as Anthropic above Cost-Optimised Routing; Customer-Key Routing (if Customer designates OpenAI) United States
Groq Runs open-source AI models at low cost Cost-Optimised Routing United States

1.1Note on Customer-Key Routing

When a Customer activates Customer-Key Routing and supplies their own API credentials for a provider (for example, their own Anthropic account), requests to that provider are made under the Customer's direct account. In this case the provider is not acting as Naetive's sub-processor — it is the Customer's own processor. The Customer is responsible for maintaining their own data processing agreement with that provider before activating this tier.


2.Infrastructure

These companies host Naetive's application, database, and related services. They handle personal data as a result of storing or processing requests that pass through Naetive.

Company What they do Data they handle Where data is stored
Supabase Hosts Naetive's primary database (PostgreSQL). Stores the tamper-evident audit log, Agent configurations, Agent Audit Bundles, compliance classifications, and performance metrics. All structured personal data processed by Naetive EU (Frankfurt, Germany)
Fly.io Hosts the Naetive application server — the software that receives Customer requests, applies routing rules, and returns responses. Application logs, request metadata, prompts and responses while being processed (in transit only) EU (Stockholm, Sweden)

3.Transfer safeguards

For sub-processors located outside the EEA — Anthropic, OpenAI, and Groq — transfers of personal data are governed by Standard Contractual Clauses (Controller-to-Processor clauses, Commission Decision (EU) 2021/914) entered into between Naetive and each sub-processor.

These transfers only occur under the Cost-Optimised Routing tier, or under Customer-Key Routing where the Customer has specifically designated a US-based provider and holds their own DPA with that provider.

Customers who need all inference to remain within the EEA should use the EU-Managed Routing tier for all task categories, or activate EU-only mode on their Agents. When EU-only mode is active, any request that cannot be served within the EEA is blocked automatically and the block is recorded in the audit log.


4.Changes to this list

Naetive will notify customers of additions or replacements to this list at least 30 days before the change takes effect. Customers may object to a new sub-processor. If the objection cannot be reasonably resolved, the Customer may terminate the Service and receive a pro-rated refund of any pre-paid fees for the unused period.

To receive notifications of sub-processor changes, email einar.naslund@naetive.eu.