QMS Nordic
PrivacyTermsSecuritySub-processorsAI Act

Caelum — Sub-processor List

DRAFT — REVIEW BY COUNSEL BEFORE EXECUTION.

Document ID: CAELUM-LEGAL-SUBP-001 Version: 1.0-draft Last updated: 2026-04-30

This page lists the sub-processors Caelum engages to provide the Services. Each sub-processor is bound by a written agreement imposing data protection obligations substantially equivalent to those Caelum owes its Customers under the DPA, and where a sub-processor handles PHI, by a HIPAA Business Associate Agreement.

The list is updated whenever a sub-processor is added, replaced, or removed. Customers are notified per DPA section 5.3 at least 30 days before any addition or replacement takes effect.

Definitions

  • "Role" describes what the sub-processor does.
  • "Personal Data categories" lists what types of Personal Data

the sub-processor may Process. "All" means any Personal Data Customer chooses to upload.

  • "Location" is the region where the sub-processor stores or

processes data.

  • "Transfer mechanism" is the legal basis for any cross-border

transfer (Adequacy / SCCs / DPF / etc.).

  • "PHI" indicates whether a HIPAA BAA is in place; "n/a" means

the sub-processor does not Process PHI.

  • "Certifications" lists the sub-processor's relevant

certifications.


Active sub-processors

Infrastructure

Sub-processorRolePersonal Data categoriesLocationTransfer mechanismPHICertifications
Neon, Inc.Managed Postgres database hosting; underlying compute/storage on AWSAllEU (eu-central-1) by default; alternate regions on Customer electionSCCs Module 3 (Caelum → Neon, where Neon entity in US) + EU-US Data Privacy FrameworkBAA in placeSOC 2 Type II; ISO 27001; HIPAA-eligible
Vercel, Inc.Application runtime, edge network, build pipelineAuthentication tokens; request metadata; HTTP logs (15-day retention)Multi-region (EU edges preferred for EU tenants)SCCs Module 3 + DPFBAA available on Enterprise (sub-)planSOC 2 Type II; ISO 27001; HIPAA-eligible
Cloudflare, Inc.DDoS protection, WAF, CDN for static assetsSource IP, user agent, request URLGlobal (anycast)SCCs + DPFn/a — Cloudflare does not Process PHI in the configured deploymentSOC 2 Type II; ISO 27001

AI

Sub-processorRolePersonal Data categoriesLocationTransfer mechanismPHICertifications
Anthropic, PBC (Claude)LLM inference for Document drafting, Suggest hazards, Suggest root cause, AI HelpdeskPrompt content (which may include any text Customer authored), retrieved chunk contentUS (with EU regions on Anthropic roadmap)SCCs Module 3 + DPFBAA in place; PHI eligibleSOC 2 Type II; HIPAA-eligible
OpenAI, L.L.C.Embedding generation for the RAG pipeline (text-embedding-3 family)Document chunks for embedding (text content)US (with EU regions available)SCCs Module 3 + DPFBAA in place via OpenAI Enterprise; PHI eligibleSOC 2 Type II; HIPAA-eligible

Important AI data note. Caelum disables training-on-inputs for both Anthropic and OpenAI via the respective enterprise API agreements. Customer Personal Data is not used to train any model.

Communications

Sub-processorRolePersonal Data categoriesLocationTransfer mechanismPHICertifications
Resend, Inc.Transactional email (verification codes, daily digests, helpdesk replies)Email address, message content, message metadataUS (with EU regions available)SCCs Module 3 + DPFn/a — outbound email, Customer responsible for PHI in message content; if PHI may be in messages, Customer must request configuration to use a PHI-eligible providerSOC 2 Type II
Twilio, Inc.SMS verification (optional fallback for /signup)Phone number, message contentUS/EUSCCs + DPFn/a — Twilio is HIPAA-eligible but PHI in SMS is discouragedSOC 2 Type II; HIPAA-eligible

Payments

Sub-processorRolePersonal Data categoriesLocationTransfer mechanismPHICertifications
Stripe, Inc.Payment processing, subscription management, customer portal, webhook deliveryBilling contact name, billing email, billing address, card token (Caelum never sees PAN)US/EU/UKSCCs + DPF; PCI DSS Level 1n/aPCI DSS Level 1; SOC 1 + 2; ISO 27001

Observability and Support tooling

Sub-processorRolePersonal Data categoriesLocationTransfer mechanismPHICertifications
Sentry (Functional Software, Inc.)Application error monitoringUser id (pseudonymous), tenant id, error stack traces (Caelum scrubs request bodies and PII fields before send via Sentry beforeSend hook)US (EU region election available — sentry.io/eu)SCCs + DPFn/a — Caelum's Sentry config explicitly excludes paths that may contain PHISOC 2 Type II

Affiliated entities

Caelum has no group company affiliates that Process Customer Personal Data. If that changes, the affected entities will be added to this list with the same notice procedure as third-party sub-processors.


Out of scope

The following providers are used by Caelum-the-company but do not Process Customer Personal Data and are therefore not Sub-processors under the DPA:

  • Notion (internal documentation)
  • Google Workspace (Caelum staff email — does not relay Customer email)
  • GitHub (source code hosting)
  • Linear (internal task tracker)

If any of these begin to Process Customer Personal Data, they will be added to the active list with notice.


Change history

DateChangeSub-processorEffect
2026-04-30Initial publicationAll listedEstablishes the list as of v1.0-draft
© 2026 Aitech International ApS · Denmark · All rights reserved.QMS Nordic™ is owned, developed, and copyright-protected by Aitech International ApS.
PrivacyTermsSecuritySub-processorsAI ActHome