Sub-processors

    Last updated: 14 Jul 2026 · We notify active account holders of additions or material changes at least 30 days in advance, except where the new sub-processor is replacing one we have stopped using.

    Sub-processors that may handle personal data

    Amazon Web Services EMEA SARL

    Privacy / DPA ↗
    Purpose:
    AWS Lightsail (single VM in Frankfurt running the entire Artifakt Vigilance stack - Caddy reverse proxy, FastAPI backend, self-hosted PostgreSQL) and Amazon Bedrock (generative-AI model inference for query normalisation, the AI Vigilance Analyst chat, and PMS report drafting).
    Data categories:
    Account profile (email and Cognito subject), search activity, export logs, alert subscriptions, survey responses, AI prompt content (search query strings + server-aggregated dashboard summaries), HTTP access logs. No account-level identifiers are forwarded to Bedrock.
    Location:
    EU regions only. The host VM and the PostgreSQL data volume live in eu-central-1 (Frankfurt). Bedrock inference uses the `eu.` cross-region inference profile (eu-central-1 / eu-west-1 / eu-west-3 etc.) - inputs and outputs remain inside the EU.
    Transfer safeguard:
    AWS Service Terms with the EU GDPR addendum (Luxembourg-based controller-to-processor SCCs). EU-region Bedrock inference avoids US transfer entirely. Database is self-hosted on the same VM and never leaves the EU region.

    Anthropic PBC (Claude models, served via Amazon Bedrock)

    Privacy / DPA ↗
    Purpose:
    Generative-AI model owner. Models accessed via Amazon Bedrock; no direct contractual relationship between Artifakt Vigilance and Anthropic - Bedrock is the contracting sub-processor.
    Data categories:
    Same as Bedrock above.
    Location:
    Inference happens inside AWS's EU regions under the EU cross-region inference profile; Anthropic does not see request payloads outside that boundary.
    Transfer safeguard:
    Covered by the AWS Bedrock terms above. Anthropic confirms via Bedrock DPA that inputs are not used for model training.

    Stripe Payments Europe Ltd.

    Privacy / DPA ↗
    Purpose:
    Subscription billing - Stripe Checkout (collect payment method, mint subscription) and Stripe Customer Portal (manage / cancel subscription). Billing webhooks update our subscription state.
    Data categories:
    Email address (passed to Stripe at customer-create time), billing address (collected by Stripe), payment-method details (collected and stored by Stripe - never touches our infrastructure), subscription status.
    Location:
    Stripe Ireland (EU). US parent-company access governed by SCCs.
    Transfer safeguard:
    Stripe DPA + EU-region payment processing. Card data and full account information are stored by Stripe, not us - we only retain the Stripe customer ID and subscription state.

    Resend (Resend.com Inc.)

    Privacy / DPA ↗
    Purpose:
    Transactional email delivery: account emails (sign-up verification codes and password-reset codes, sent via the Cognito custom email sender), PMS alert digests, and product notifications.
    Data categories:
    Recipient email address, message subject, and message body (which may include a one-time verification / reset code). Billing data is never included.
    Location:
    EU region (Ireland). Operated by Resend.com Inc. (US parent).
    Transfer safeguard:
    Resend DPA + EU regional delivery. SCCs cover any US-parent corporate access. We do not retain message bodies after dispatch.
    Purpose:
    Form-to-email backend for the public "Request access / contact" form only (the /request-access page). It forwards the submitted message to our inbox. It is not used anywhere a signed-in user's account data is processed.
    Data categories:
    Only what the sender types into the contact form: name, email address, and message text. These submissions are not stored in our own database.
    Location:
    United States (Web3Forms is a US-operated service).
    Transfer safeguard:
    Minimised, self-submitted contact data only - no account, search, or report data is sent. We are migrating this contact form to our own EU backend to remove the US transfer; until then, please do not include sensitive information in the contact form.

    Public-data sources we read from (not sub-processors)

    The following are public regulatory or scientific databases. We send your search query to them in order to fetch results. They are independent controllers, not our sub-processors, and their own privacy notices apply.

    Objecting to a sub-processor

    If you have a legitimate concern about a specific sub-processor, write to hello@artifaktmedical.com. We will respond within 30 days; if we cannot accommodate your objection, you may exercise your right to terminate the service and request erasure of your data.

    See also: Privacy Policy · Terms of Service