QMS Nordic
PrivacyTermsSecuritySub-processorsAI ActValidation

QMS Nordic — Sub-processor List

DRAFT — REVIEW BY COUNSEL BEFORE RELIANCE.

The vendors, their roles and the data each receives are taken from the application as deployed on the date below, not from memory.

Confirmed on 2026-09-09 and no longer marked: the database region, read from the Neon console; and the EU-US Data Privacy Framework status of Vercel, ElevenLabs, Resend and Sentry, each read from the Department of Commerce register rather than from the vendor's own description of itself.

Still to confirm, and marked (confirm) where they appear: that a data-processing agreement is signed with each engaged vendor; the DPF status of Anthropic and OpenAI; and whether Neon is a covered entity under Databricks' certification following the acquisition.

Document ID: QMSN-LEGAL-SUBP-001 Version: 2.0-draft Last updated: 2026-09-05 Controller of this list: Aitech International ApS, Nydamsvej 43, 8362 Hørning, Denmark, CVR 46545354

This page lists the sub-processors Aitech International ApS ("Aitech") engages to provide the QMS Nordic service. Each engaged sub-processor is bound by a written agreement imposing data-protection obligations substantially equivalent to those Aitech owes its customers under the Data Processing Addendum (DPA).

The list is updated whenever a sub-processor is added, replaced or removed. Customers are notified per the DPA's change-notification clause at least 30 days before any addition or replacement takes effect. A vendor in the second table below is not yet processing customer data; enabling one is an addition and triggers that notice.

Definitions

  • Role — what the sub-processor does for the service.
  • Personal data it receives — the categories that actually reach the vendor. "Any customer content" means text a customer's users authored in the platform — a procedure, a complaint narrative, a CAPA — which may contain personal data the customer chose to put there.
  • Location — where the vendor processes the data.
  • Transfer mechanism — the legal basis for any transfer outside the EU/EEA: the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914) and, for a US vendor certified under it, the EU-US Data Privacy Framework.

Engaged sub-processors

These process customer data today.

Infrastructure

Infrastructure
Sub-processorRolePersonal data it receivesLocationTransfer mechanism
Neon, Inc.Managed PostgreSQL — the platform database, on AWSAll customer data at rest, encryptedEU, Frankfurt — the project overview reads "AWS Europe Central 1 (Frankfurt)", confirmed in the Neon console 2026-09-09EU SCCs. Not EU-US DPF: a register search for "Neon" returns Databricks, Inc. with covered entities, and whether Neon is among them is (confirm) — Neon was acquired by Databricks, so the contracting entity itself needs confirming
Vercel, Inc.Application hosting: web and API runtime, scheduled jobs, build pipeline, edge network and TLSAuthentication cookies and request data in transit; HTTP request logs (short retention)Global edge network; server functions in the project's configured regionEU SCCs; EU-US DPF — Vercel Inc. (Covina, CA) listed Active on the DPF register, checked 2026-09-09

AI

AI
Sub-processorRolePersonal data it receivesLocationTransfer mechanism
Anthropic, PBC (Claude)Language-model inference for the AI features: document drafting and population, plain-language explanations, hazard and root-cause suggestions, helpdesk reply suggestions, audit-scope drafting, technical-documentation assembly, document translationThe prompt for each request: the user's instruction and any customer content it draws on, including retrieved passages from the customer's own documentsUnited StatesEU SCCs; EU-US DPF (confirm)
OpenAI, L.L.C.(1) Text embeddings for document retrieval (text-embedding-3-small). (2) Real-time voice conversation with the assistant, when a user starts one(1) Chunks of the customer's document text. (2) The user's microphone audio, streamed from the browser directly to OpenAI for the duration of a voice conversation the user starts, and the assistant's spoken repliesUnited StatesEU SCCs; EU-US DPF (confirm)
ElevenLabs, Inc.Spoken playback of the assistant's written replies, when a user turns voice onThe text of the assistant's reply to be spoken — not the user's voiceUnited StatesEU SCCs; EU-US DPF — ElevenLabs (New York, NY) listed Active on the DPF register, checked 2026-09-09

AI data note. Under both vendors' commercial API terms, inputs are not used to train models, and Aitech has not opted in to any programme that would change that. The platform records every AI call in the audit trail by hash, not by content.

Communications

Communications
Sub-processorRolePersonal data it receivesLocationTransfer mechanism
Resend, Inc.Transactional email: sign-up verification, invitations, daily digests, task and approval notifications, helpdesk repliesRecipient email address, message content and delivery metadataUnited StatesEU SCCs; EU-US DPF — Resend (San Francisco, CA) listed on the DPF register as "Active — Re-certification under Review", checked 2026-09-09

Observability

Observability
Sub-processorRolePersonal data it receivesLocationTransfer mechanism
Sentry (Functional Software, Inc.)Application error monitoringPseudonymous user id, tenant id and the error's stack trace. The client is configured not to send personally identifiable defaults, and a scrubber removes customer-data fields before anything is sentUnited States (EU-hosted region available on election) (confirm which)EU SCCs; EU-US DPF — Sentry.io (San Francisco, CA) listed Active on the DPF register, checked 2026-09-09

Wired but not enabled

The application is built to use these vendors, and the operator can enable each by configuration. None is processing customer data as of the date above. Enabling one adds a sub-processor and triggers the 30-day notice.

Wired but not enabled
VendorRole when enabledPersonal data it would receiveLocation
Stripe, Inc. (Stripe Payments Europe, Ltd. for EU customers)Card payment and subscription billing. Today customers are invoiced directly; Stripe is not in useBilling contact name, email and address; card details are entered on Stripe's own pages and never reach the platformIreland / United States
Twilio, Inc.SMS as a second factor for sign-up verification. Sign-up currently verifies by email onlyMobile number and the one-time codeUnited States / Ireland

Not sub-processors

These touch personal data in connection with the service but are not sub-processors of Aitech under the DPA, for the reason given.

  • The customer's identity provider — sign-in with Microsoft Entra ID is available. The customer's own tenant authenticates its users and sends the platform a name, email address and identifier; Microsoft acts for the customer, under the customer's agreement with Microsoft, not for Aitech.
  • Customer-elected integrations — a customer may connect its own ERP (Rackbeat is supported) so that goods receipts and production orders flow into the platform. The connection uses the customer's credentials; the ERP vendor is the customer's processor.
  • GitHub, Inc. — source code and continuous integration. The CI pipeline rebuilds an empty database from the migration history to prove it can; no customer data is present.
  • Website analytics and advertising pixels — none are set on the public site as of the date above; the Privacy Policy governs any that are added.

Internal tooling that does not process customer data — email for Aitech's own staff, documentation, task tracking — is not listed. If any such tool begins to process customer data it is added to the engaged table with notice.

Affiliated entities

Aitech International ApS has no group companies that process customer personal data.


Change history

Change history
DateVersionChange
2026-04-301.0-draftInitial draft, written under the platform's former name.
2026-09-052.0-draftRe-issued under Aitech International ApS / QMS Nordic with the registered office and CVR. Every entry re-derived from the deployed application. Removed: Cloudflare — the domain has never been behind it (DNS at the registrar, traffic direct to Vercel). Added: ElevenLabs (spoken replies, live in production) and OpenAI's real-time voice conversation, both of which the application calls and the April list omitted. Moved to "wired but not enabled": Stripe and Twilio — neither processes customer data today; the deployment's own health endpoint says so. Removed the claims of HIPAA business-associate agreements and named certifications, which nobody had verified, in favour of the confirmations counsel is asked for above. Replaced the out-of-scope list of internal tools, which named products Aitech does not use, with the categories that actually apply. A second public page that served a different, placeholder list now redirects here, and a test fails the build if the application gains a provider this list does not name.
© 2026 Aitech International ApS · Denmark · All rights reserved.QMS Nordic™ is owned, developed, and copyright-protected by Aitech International ApS.
PrivacyTermsSecuritySub-processorsAI ActValidationHome