Sub-processors

Last updated: September 21, 2026

Isodora engages the third-party service providers below to process personal data on our behalf in order to deliver our ISO compliance management platform. We maintain a Data Processing Agreement with each provider and rely on the transfer mechanism listed for any transfer of personal data outside the European Economic Area, in accordance with GDPR Article 28 and Article 13(1)(e)–(f).

EU-hosted AI models

Which AI providers process your organization's prompts, retrieved document excerpts, generated text, and interview speech-to-text depends on the model profile Isodora assigned to your tenant. The default profile uses OpenAI in the United States via the Vercel AI Gateway. EU-hosted packs send that traffic through Opper (Sweden) to Azure OpenAI in Sweden and/or Mistral in France — those packs do not send chat, analysis, document generation, or transcription to OpenAI in the US. Embeddings for document search follow your tenancy region, not the model profile. Your active profile is shown in Settings → AI & data residency.

Sub-processorPurposeLocationTransfer mechanism
OpenAI, L.L.C.AI inference, embeddings, and interview speech-to-text for the default US model profile. Not used for chat, analysis, document generation, or transcription when the tenant is assigned an EU-hosted pack.United StatesStandard Contractual Clauses (Commission Decision 2021/914)
Opper Technology ABEU AI gateway (Stockholm). Routes prompts and model output for Opper-backed profiles, including EU-hosted Azure and Mistral packs.Sweden (AWS eu-north-1, Stockholm)Data Processing Agreement (processing in the EEA; no third-country transfer)
Microsoft Ireland Operations Limited (Azure OpenAI)Azure OpenAI inference in Sweden for organizations assigned the Azure GPT or mixed EU model pack (chat, analysis, document generation, and related speech-to-text via the EU catalog).Sweden (Azure Sweden)Data Processing Agreement (processing in the EEA; no third-country transfer)
Mistral AI SASEU-hosted large language models and Voxtral speech-to-text in France for organizations assigned the Mistral or mixed EU model pack.FranceData Processing Agreement (processing in the EEA; no third-country transfer)
Supabase, Inc.Database, file storage, and authenticationEU (eu-north-1, Stockholm) or US (us-east-1) — matching your tenancy regionData Processing Agreement (data held in your tenancy’s region; never crosses the EU/US boundary)
Vercel, Inc.Serverless compute and content delivery (CDN)United States (EU edge regions for delivery)EU-US Data Privacy Framework
Stripe, Inc.Subscription and payment processingUnited StatesEU-US Data Privacy Framework and Standard Contractual Clauses
Resend (Plus Five Five, Inc.)Transactional email deliveryUnited StatesStandard Contractual Clauses
Functional Software, Inc. (Sentry)Application error tracking and monitoringEuropean Union where available, otherwise United StatesData Processing Agreement and Standard Contractual Clauses
LangChain, Inc. (LangSmith)AI agent observability and tracingEuropean Union (LangSmith EU, eu.smith.langchain.com)Data Processing Agreement (data hosted in the EU); Standard Contractual Clauses for any residual transfer

Connected systems

The systems below are not sub-processors. We do not send your data to them for processing. They are systems your organization already owns, and which you can authorise Isodora to read from so that compliance evidence is collected for you. For each one, Isodora operates a registered application that makes that authorisation possible. Your own agreement with the vendor continues to govern the data held there.

SystemUsed byWhat Isodora operatesWhat leaves Isodora
Amazon Web ServicesAWS connectorAn Isodora-owned AWS account and the IAM principal that assumes the read-only role you deploy in your own account.Authentication and read requests against your account. None of your AWS content is stored in the Isodora AWS account.
GitHubGitHub connectorAn Isodora-owned GitHub App that you install on the organization you choose.Authentication and read requests against the repositories you grant. Source code is not copied into Isodora.
GoogleGoogle Workspace connectorAn Isodora-owned OAuth client in Google Cloud.Authentication and read requests against the Workspace settings and reports an administrator grants.
AtlassianJira connectorAn Isodora-owned OAuth integration with Atlassian.Authentication and read requests against the Jira site you authorise.
MicrosoftMicrosoft 365, Intune, Azure and SharePoint importTwo Isodora-owned Entra app registrations: one for the monitoring connectors, one used only by SharePoint import.Authentication and read requests against the tenant you authorise. SharePoint import additionally downloads the files you pick, which are then stored in Isodora as uploaded documents.

A connection exists only while you keep it connected and can be revoked at any time under Connectors. Connectors that authenticate with credentials you supply yourself involve no Isodora registration and are therefore not listed here.

Changes to this list

We update this page whenever we add or replace a sub-processor. Customers with an active agreement are notified of any new sub-processor at least 30 days before it begins processing their personal data, as required by GDPR Article 28(2) and the DPA. To request advance notification of changes, contact us at the address below.

Contact

For questions about our sub-processors, our Data Processing Agreement, or to request the underlying transfer documentation, contact:

Email: privacy@isodora.se
Data Protection Officer: dpo@isodora.se