About This List
In compliance with GDPR Article 28 and our Data Processing Agreement (DPA), this page lists all third-party subprocessors that Answerplane engages to process personal data on behalf of our customers.
Changes to this list: We will notify customers at least 30 days before adding new subprocessors or making material changes. Customers may object to new subprocessors within 10 days of notification by contacting [email protected].
Current Subprocessors
| Subprocessor | Location | Processing Activity | Data Processed |
|---|---|---|---|
| Microsoft Azure Microsoft Corporation | Germany West Central (EU) Frankfurt, Germany | Cloud infrastructure, data storage, compute resources, database hosting | Account data, metadata, configurations, query history |
| OpenAI OpenAI, Inc. | United States Protected by SCCs | AI/LLM answer planning and validation (optional - only if customer selects OpenAI) | Approved-source request text, database schema metadata (NOT database content) |
| Anthropic Anthropic PBC | United States Protected by SCCs | AI/LLM answer planning and validation (optional - only if customer selects Anthropic) | Approved-source request text, database schema metadata (NOT database content) |
| Google AI Google LLC | United States Protected by SCCs | AI/LLM answer planning and validation (optional - only if customer selects Google AI) | Approved-source request text, database schema metadata (NOT database content) |
| Stripe Stripe, Inc. | United States PCI DSS Level 1 Certified | Payment processing, billing, subscription management | Payment information, billing addresses, transaction data |
| Postmark ActiveCampaign, LLC | United States Protected by SCCs | Transactional email delivery (account verification, password resets, billing notifications) | Email addresses, user names, notification content |
Self-Hosted Infrastructure Components
The following infrastructure components are self-hosted by Answerplane on Microsoft Azure (Germany West Central) and are not separate subprocessors:
- PostgreSQL - Platform database for account data and metadata
- Redis - Session management, caching, and job queue
- RabbitMQ - Message queue for background job processing
These components operate within our Azure infrastructure and are subject to the same security controls and data protection measures as our primary platform.
Data Protection Safeguards
Standard Contractual Clauses (SCCs)
All subprocessors located outside the European Economic Area (EEA) are bound by European Commission-approved Standard Contractual Clauses (EU SCCs 2021/914) to ensure adequate data protection for international transfers.
Contractual Obligations
All subprocessors are contractually obligated to:
- Process personal data only as instructed by Answerplane
- Implement appropriate technical and organizational security measures
- Maintain confidentiality of personal data
- Assist with data subject rights requests
- Notify Answerplane of any data breaches within 24 hours
- Delete or return personal data upon termination
AI Provider Data Handling
Important AI/LLM provider controls:
- Retention Controls: AI providers process requests under their applicable business API terms and configured retention settings; Enterprise customers can request stricter provider routing or zero-retention options where available
- Request-Scoped Processing: Query text and schema metadata are processed to answer the request
- No Full Database Dumps: We do not send wholesale copies of your connected database contents to AI providers
- Customer Choice: You select which AI provider (OpenAI, Anthropic, or Google AI) processes your queries
Change Notification Process
30-Day Advance Notice
Before adding new subprocessors or making material changes to existing ones, Answerplane will:
- Update this subprocessor list at least 30 days in advance
- Send email notification to the account email address on file
- Include the subprocessor name, location, and processing activity
Right to Object
Customers may object to new subprocessors on reasonable data protection grounds by:
- Notifying us in writing within 10 days of receiving notice
- Emailing objections to: [email protected]
- Stating specific data protection concerns
If we cannot resolve your objection, you may terminate the affected services without penalty within 30 days of the original notice.
Contact Information
For questions about our subprocessors or to exercise your right to object:
Data Protection Officer: [email protected]
Enterprise Inquiries: [email protected]
General Inquiries: [email protected]