Tebelis AI — Sub-processors
This list reflects the vendors and hosting regions used to provide the Service. It forms part of the DPA (Annex III) and is referenced by the Privacy Policy.
Last updated: 30 July 2026
Tebelis AI (173 rue de Courcelles, 75017 Paris, France) engages the following sub-processors to provide the Service. Each is bound by data-protection terms substantially equivalent to our DPA.
| Sub-processor | Service / purpose | Data processed | Hosting region | Transfer safeguard |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting — application servers (Elastic Beanstalk) + primary database (RDS PostgreSQL) + file/object storage + transactional email (Amazon SES) (verification, password reset, workflow notifications) | All Customer Data at rest and in processing; for email: recipient name + address + email content | EU region | Within EEA (EU region) |
| Cloudflare | DNS, CDN, TLS, and edge security (WAF) in front of the Service | Network/traffic metadata, IP addresses; data in transit | Global edge (incl. EU) | EU SCCs |
| Stripe (EU contracting entity Stripe Payments Europe, Ltd., Ireland) | Subscription billing and payment processing | Billing contact + subscription data; card details are handled by Stripe (Tebelis AI does not store card numbers) | EU contracting/establishment in Ireland; processing is global (incl. Stripe, LLC in the US) — payment processing inherently crosses borders, not EU-resident | EEA SCCs (Modules 1–3) + EU-US Data Privacy Framework; lead authority = Irish DPC |
| Amazon Bedrock (AWS managed AI service — running Anthropic Claude models) | Managed AI features (assistant, summaries, insights) — processes prompts + workspace context to generate output | Prompts and the relevant Customer Data context sent for an AI request; not used to train models. Bedrock does not share request content with the model provider | EU region (Amazon Bedrock, operated by AWS) | Within EEA (EU region) |
| Sentry (Functional Software, Inc. dba Sentry — US) | Application error & performance monitoring — captures crash/error events to alert on and diagnose faults (server, web, mobile) | Diagnostic/technical data: error messages, stack traces, breadcrumbs, app release, device/OS/browser metadata. PII is scrubbed before send (sendDefaultPii:false + beforeSend strips user email/IP/username, request bodies/cookies/headers) | EU (Frankfurt) data region | EU-region storage; vendor is US-incorporated → EU SCCs + EU-US Data Privacy Framework (Functional Software, Inc. is DPF self-certified: EU-US + UK Extension + Swiss-US) |
| Expo (Expo, Inc. — US) | Mobile push-notification delivery for the field app (Expo push service), and delivery of app-code updates (EAS Update — the app checks for updated application code at launch) | Push: device push token, device platform, and the notification title/body in transit (short workflow references — e.g. a record code and hand-off status; no form contents). Updates: device IP, app runtime version, update channel and update id; no customer content | Global (US-based) | EU SCCs via Expo's data-processing terms |
| Google Firebase Cloud Messaging (Google Ireland Ltd / Google LLC) | Android push transport (FCM) — final delivery of push notifications to Android devices | Push routing token and the notification payload in transit | Global | EU SCCs + EU-US Data Privacy Framework (Google LLC is DPF-certified) |
| Microsoft (Microsoft Ireland Operations Ltd / Microsoft Corporation) | Single sign-on (Microsoft Entra ID) — only where a Customer chooses to connect its own Microsoft tenant; the Service supports no other SSO provider | The sign-in exchange only: the signing-in user's email address, name and Microsoft tenant/object identifier, returned to us by Microsoft. No Customer Data — records, form contents, attachments or workspace context — is ever sent to Microsoft. | Global; EU contracting entity in Ireland | EU SCCs + EU-US Data Privacy Framework (Microsoft Corporation is DPF-certified). Where the Customer connects its own tenant, Microsoft acts under the Customer's existing agreement with Microsoft as much as under ours — it is listed here so the table is complete either way |
Bring-your-own AI keys: where a Customer connects its own AI provider, that provider is engaged by the Customer (not a Tebelis AI sub-processor), and that processing is governed by the Customer's agreement with it.
Other third-party services
One outbound service does not sit in the table above, because it is a public API with no contract and therefore cannot be "bound by terms substantially equivalent to our DPA" as the sub-processors are. Disclosed here for completeness:
| Service | When it is called | What is sent | Hosting |
|---|---|---|---|
| Nominatim — address lookup (server-side) | Only when a workspace administrator presses "Locate" in Project Settings to turn a site address into map coordinates. Never automatically. | The address string typed into the Site address field, plus our server's outbound IP and a Tebelis/1.0 User-Agent. No records, form contents, user names or account data. | OSMF infrastructure (UK / EU) |
| OpenStreetMap map tiles — embedded map (in your browser) | Automatically, whenever a user views a record containing a geotagged photo, or opens Project Settings for a located project. No click required. | Loaded directly by the viewer's browser, so OSMF receives that user's own IP address, browser User-Agent and the photo's exact GPS coordinates. | OSMF infrastructure (UK / EU) |
Site addresses are premises locations rather than personal data, though the field is free text, so an administrator could type something personal into it. The embedded map is different: because it loads in the browser rather than on our server, the viewing user's own IP address is visible to OSMF, alongside the coordinates of a geotagged photo. We do not send them any account or record data.
If your organisation cannot accept this, tell us: the feature is optional, the address can be left un-geocoded with no loss of function, and we can disable the lookup for your workspace.
Changes: we give prior notice of new or replacement sub-processors and an objection window as set out in DPA §6. To be notified of changes, email [email protected] to subscribe to sub-processor updates.