Our agreements are written in plain language — no marketing, even in legal text.
For enterprise customers we sign a KVKK/GDPR-aligned DPA: purposes, sub-processors, safeguards, deletion commitments and audit rights.
The current list of sub-processors and the data each one touches lives on the Turkish legal page (table is language-neutral).
Prohibited uses, agent rules and content responsibility — for using the service safely and lawfully.
Found a vulnerability? Scope, rules and a safe reporting process.
The sub-processors we use to deliver the service and the scope of data each one accesses. If the list changes, this page is updated; customers who have signed a DPA are notified of any change.
| Sub-processor | Purpose | Location | Data |
|---|---|---|---|
| Contabo GmbH | Server hosting | Germany (EU) | All application data |
| Cloudflare, Inc. | CDN, TLS, DDoS protection, load balancing, object storage (R2) | Global (EU edges) | Traffic (encrypted in transit); files attached to a support or contact thread (stored in R2) |
| AI providers (Anthropic, OpenAI, Google, Together — via our own gateway) | Model inference | EU/US | Query context; endpoints closed to training |
| Resend | Transactional email (outbound and inbound) | US | Email address, notification content; email you send in reply to a request, and its attachments |
| Soniox / ElevenLabs | Speech recognition / synthesis (only on plans with Voice AI enabled) | US | Session audio stream |
| Stripe | Payment processing | EU/US | Billing and payment info (card data is not stored by us) |
Last updated: September 6, 2026. Questions? Contact us.