Sub-processor Register
Last updated: 13 May 2026
Parat uses the following third-party sub-processors to deliver the service. All sub-processors are bound by Data Processing Agreements (DPAs) as required by GDPR Article 28. This list is updated when sub-processors are added or removed.
| Name | Purpose | Data types | Region | Transfer basis | DPA / Privacy policy |
|---|---|---|---|---|---|
| Anthropic | AI model provider (Claude) for document analysis and case processing | Case documents, interview responses, generated content | US (routed via AWS Bedrock, EU-processed) | Anthropic Privacy Policy + AWS DPA (Bedrock) | Anthropic Privacy Policy |
| Amazon Web Services (AWS) | AI inference (Bedrock), object storage (S3), compute infrastructure | Case documents, interview responses, generated content | EU (eu-west-1 Ireland, eu-central-1 Frankfurt) | AWS GDPR Data Processing Addendum (EU-based) | AWS Service Terms (DPA) |
| Supabase | Database, user authentication, row-level data storage | User accounts, case metadata, subscription status | EU (Frankfurt, eu-central-1) | Supabase DPA (EU-based) | Supabase DPA |
| Vercel | Web application hosting, edge functions, CDN | HTTP requests including session tokens; edge-processed user data | EU primary, US fallback (Standard Contractual Clauses for US transfers) | Vercel DPA + SCCs | Vercel DPA |
| Polar.sh | Subscription billing, payment processing, invoice generation | Email address, subscription tier, payment method (card data not stored by Parat) | EU/US (Standard Contractual Clauses) | Polar Privacy Policy + SCCs | Polar privacy |
| Transactional email provider (TBD) | OTP login codes, billing confirmation emails | Email address, email content | To be confirmed | To be confirmed | To be added when provider is selected |
Questions about this register or Parat's data processing practices may be directed to our data protection officer: dpo@parat.ai