Sub-processors
Last updated: September 21, 2026
Isodora engages the third-party service providers below to process personal data on our behalf in order to deliver our ISO compliance management platform. We maintain a Data Processing Agreement with each provider and rely on the transfer mechanism listed for any transfer of personal data outside the European Economic Area, in accordance with GDPR Article 28 and Article 13(1)(e)–(f).
EU-hosted AI models
Which AI providers process your organization's prompts, retrieved document excerpts, generated text, and interview speech-to-text depends on the model profile Isodora assigned to your tenant. The default profile uses OpenAI in the United States via the Vercel AI Gateway. EU-hosted packs send that traffic through Opper (Sweden) to Azure OpenAI in Sweden and/or Mistral in France — those packs do not send chat, analysis, document generation, or transcription to OpenAI in the US. Embeddings for document search follow your tenancy region, not the model profile. Your active profile is shown in Settings → AI & data residency.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| OpenAI, L.L.C. | AI inference, embeddings, and interview speech-to-text for the default US model profile. Not used for chat, analysis, document generation, or transcription when the tenant is assigned an EU-hosted pack. | United States | Standard Contractual Clauses (Commission Decision 2021/914) |
| Opper Technology AB | EU AI gateway (Stockholm). Routes prompts and model output for Opper-backed profiles, including EU-hosted Azure and Mistral packs. | Sweden (AWS eu-north-1, Stockholm) | Data Processing Agreement (processing in the EEA; no third-country transfer) |
| Microsoft Ireland Operations Limited (Azure OpenAI) | Azure OpenAI inference in Sweden for organizations assigned the Azure GPT or mixed EU model pack (chat, analysis, document generation, and related speech-to-text via the EU catalog). | Sweden (Azure Sweden) | Data Processing Agreement (processing in the EEA; no third-country transfer) |
| Mistral AI SAS | EU-hosted large language models and Voxtral speech-to-text in France for organizations assigned the Mistral or mixed EU model pack. | France | Data Processing Agreement (processing in the EEA; no third-country transfer) |
| Supabase, Inc. | Database, file storage, and authentication | EU (eu-north-1, Stockholm) or US (us-east-1) — matching your tenancy region | Data Processing Agreement (data held in your tenancy’s region; never crosses the EU/US boundary) |
| Vercel, Inc. | Serverless compute and content delivery (CDN) | United States (EU edge regions for delivery) | EU-US Data Privacy Framework |
| Stripe, Inc. | Subscription and payment processing | United States | EU-US Data Privacy Framework and Standard Contractual Clauses |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | United States | Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | Application error tracking and monitoring | European Union where available, otherwise United States | Data Processing Agreement and Standard Contractual Clauses |
| LangChain, Inc. (LangSmith) | AI agent observability and tracing | European Union (LangSmith EU, eu.smith.langchain.com) | Data Processing Agreement (data hosted in the EU); Standard Contractual Clauses for any residual transfer |
Connected systems
The systems below are not sub-processors. We do not send your data to them for processing. They are systems your organization already owns, and which you can authorise Isodora to read from so that compliance evidence is collected for you. For each one, Isodora operates a registered application that makes that authorisation possible. Your own agreement with the vendor continues to govern the data held there.
| System | Used by | What Isodora operates | What leaves Isodora |
|---|---|---|---|
| Amazon Web Services | AWS connector | An Isodora-owned AWS account and the IAM principal that assumes the read-only role you deploy in your own account. | Authentication and read requests against your account. None of your AWS content is stored in the Isodora AWS account. |
| GitHub | GitHub connector | An Isodora-owned GitHub App that you install on the organization you choose. | Authentication and read requests against the repositories you grant. Source code is not copied into Isodora. |
| Google Workspace connector | An Isodora-owned OAuth client in Google Cloud. | Authentication and read requests against the Workspace settings and reports an administrator grants. | |
| Atlassian | Jira connector | An Isodora-owned OAuth integration with Atlassian. | Authentication and read requests against the Jira site you authorise. |
| Microsoft | Microsoft 365, Intune, Azure and SharePoint import | Two Isodora-owned Entra app registrations: one for the monitoring connectors, one used only by SharePoint import. | Authentication and read requests against the tenant you authorise. SharePoint import additionally downloads the files you pick, which are then stored in Isodora as uploaded documents. |
A connection exists only while you keep it connected and can be revoked at any time under Connectors. Connectors that authenticate with credentials you supply yourself involve no Isodora registration and are therefore not listed here.
Changes to this list
We update this page whenever we add or replace a sub-processor. Customers with an active agreement are notified of any new sub-processor at least 30 days before it begins processing their personal data, as required by GDPR Article 28(2) and the DPA. To request advance notification of changes, contact us at the address below.
Contact
For questions about our sub-processors, our Data Processing Agreement, or to request the underlying transfer documentation, contact:
Email: privacy@isodora.se
Data Protection Officer: dpo@isodora.se