GDPR Art. 28(2) Subprocessor Disclosure
Subprocessors
Effective Date: September 12, 2026
Askdepth engages the third-party subprocessors listed below to provide the platform. Each is bound by a Data Processing Agreement and, where processing occurs outside the European Economic Area, an approved transfer mechanism under GDPR Chapter V. This page is generated from a machine-readable register in our codebase, and an automated test in CI checks that register against the integrations the platform declares.
To object to a new subprocessor, or for questions about this list, contact privacy@askdepth.com.
Google Cloud & Vertex AI
European Economic Area (EEA)- Legal entity
- Google Ireland Limited / Google LLC
- Category
- Vector embeddings
- Purpose
- Vector embeddings (text-embedding-004) and generative AI inference (Gemini)
- Transfer mechanism
- EU Data Boundary — processing pinned to EEA regions — Google LLC (DPF certified)
- Scope & safeguards
- Pinned to europe-west4 (Eemshaven, Netherlands). Vertex AI Customer Data non-training guaranteed.
Anthropic
United States- Legal entity
- Anthropic, PBC
- Category
- LLM inference & analysis
- Purpose
- Core qualitative reasoning, coding, synthesis, and conversational analysis
- Transfer mechanism
- Standard Contractual Clauses (SCCs)
- Scope & safeguards
- Governed by Anthropic Commercial DPA + Standard Contractual Clauses (SCCs). Non-training contractually guaranteed.
AssemblyAI
European Economic Area (EEA)- Legal entity
- AssemblyAI, Inc.
- Category
- Speech-to-text transcription
- Purpose
- Real-time streaming speech-to-text transcription during interviews
- Transfer mechanism
- EU Data Boundary — processing pinned to EEA regions — AssemblyAI, Inc. (DPF certified)
- Scope & safeguards
- Real-time WebSocket pinned to EU streaming endpoint wss://streaming.eu.assemblyai.com/v3/ws.
Amazon SES
European Economic Area (EEA)- Legal entity
- Amazon Web Services EMEA SARL / Amazon Web Services, Inc.
- Category
- Transactional email delivery
- Purpose
- Sending-domain verification (DKIM/SPF) and transactional email delivery for respondent invitations
- Transfer mechanism
- EEA-incorporated entity — processing in the EEA
- Scope & safeguards
- Pinned to eu-central-1 (Frankfurt). Contracted through AWS EMEA SARL (Luxembourg) and governed by the AWS GDPR DPA, auto-incorporated into the AWS Service Terms. These are standard AWS regions, not the EU Sovereign Cloud: AWS support personnel outside the EEA may access data under the Standard Contractual Clauses the DPA incorporates. Data limited to email addresses, recipient display names, and DNS configuration. ZDR here means no training and no retention of message content beyond delivery — SES does retain delivery metadata (send, bounce, complaint events).
Resend
United States- Legal entity
- Resend, Inc.
- Category
- Transactional email delivery
- Purpose
- Transactional email delivery for respondent invitations and workspace notifications
- Transfer mechanism
- EU-U.S. Data Privacy Framework (DPF) — Resend, Inc. (DPF certified)
- Scope & safeguards
- Transactional email delivery. Data Protection Addendum signed.
Stripe
European Economic Area (EEA)- Legal entity
- Stripe Payments Europe, Limited / Stripe, Inc.
- Category
- Payment processing
- Purpose
- Payment processing, billing, and subscription management
- Transfer mechanism
- EEA-incorporated entity — processing in the EEA — Stripe, Inc. (DPF certified)
- Scope & safeguards
- B2B subscription billing. Operates through Irish entity with SCCs/DPF fallback.