Sub-processors

Last reviewed: August 11, 2026

This page is the customer-facing list of sub-processors engaged for the lynox Managed Hosting service. The contractually binding list lives in the Data Processing Agreement — if any version diverges, the DPA prevails. The same list is also mirrored as a public reference at SUBPROCESSORS.md in the source repo.

The self-hosted lynox software (@lynox-ai/core) engages no sub-processors. When you run lynox on your own infrastructure, the software only communicates with the LLM provider whose API key you configure. This list applies only to lynox AI's managed offering.

Current sub-processors

Sub-processor Purpose Location Transfer mechanism
Anthropic, PBC Primary LLM inference (Claude family, direct API) United States SCCs (2021/914, Modules 2/3) + Swiss and UK addenda (per Anthropic's Data Processing Addendum)
Mistral AI SAS Inference and voice in the default managed setup: the background worker profile (ministral-14b-2512), the fallback profile for named sub-agent spawns (mistral-medium-2604), speech-to-text (voxtral-mini-2602) and text-to-speech (Voxtral). Text-to-speech has no alternative implementation — spoken output always goes to Mistral; on a managed instance neither can be switched away — transcription_provider is not tenant-writable and LYNOX_TRANSCRIBE_PROVIDER is self-host-only, so the local whisper.cpp fallback in the image is unreachable there. Mail-triage classification does not run here by default — it follows the instance's main provider, which is Anthropic unless the customer changes it. Any customer may select Mistral as their main inference provider to keep primary inference within the EU. France (EU) EU — processed in France, no third-country transfer. Retention is not zero by default: Mistral keeps API inputs and outputs "for the period necessary to generate the Output and then for thirty (30) rolling days to monitor abuse" (Mistral Privacy Policy, section 5). Mistral's Zero Data Retention is an opt-in option — Scale plan only, stateless endpoints only, granted on request at Mistral's discretion — and its Data Processing Addendum contains no zero-retention commitment. lynox does not hold Zero Data Retention (its Mistral account is on Pay-as-you-go, verified 2026-08-11). Separately, lynox has not enabled training in its Mistral organisation settings and has Labs/Preview off — account configuration rather than contractual terms, checked 2026-08-11. No training on API inputs or outputs — contractual, under Mistral's Commercial Terms of Service §4.2.
Fireworks AI, Inc. LLM inference for the opt-in "Efficient" and "Balanced" model strategies — engaged for a managed instance by one of two routes: the instance selects one of those presets (or a Fireworks model) in its own model settings, or we pin a preset for that instance from the control plane. A pin takes effect only where the instance has not chosen a strategy itself — an instance that has chosen one keeps its choice. We enable the option platform-wide, but neither route is the default: an instance with no selection and no pin routes to Anthropic and Mistral only, and nothing reaches Fireworks until one of the two routes applies. Where a preset is selected, all three model tiers (fast / balanced / deep) run on Fireworks' serverless inference on open-weight models of Chinese origin — DeepSeek v4 Flash, MiniMax M3, GLM 5.2 and Kimi K3. The weights are open; the inference runs on Fireworks' own infrastructure. None of the sub-processors listed in Schedule 4 of its DPA is a Chinese entity. The processing locations named there include the United States, Germany, the United Kingdom, Japan and Iceland; one row, a content-delivery provider, is listed with no fixed country at all. Schedule 4 is Fireworks' list and can change — it is the list as we read it on 2026-08-11, and Fireworks owes 30 days' notice of changes to it (Fireworks DPA, Schedule 4). Fireworks does not retain prompt inputs or model outputs beyond the lifecycle of a request (Zero Data Retention — Fireworks' default for open models, which we have not opted out of by enabling prompt logging, and a contractual obligation under §4.5 of its DPA), and is contractually prohibited from using the data to train, fine-tune or otherwise improve any shared or foundational model (§4.3(f)). United States SCCs (2021/914, Module 2; Irish law, Irish DPC); Zero Data Retention and the no-training commitment as additional safeguards; SOC 2 Type II, ISO 27001 / 27701 / 42001
Stripe, LLC (US) / Stripe Payments Europe, Limited (Ireland) Payment processing and subscription billing Ireland (EU) — as a customer outside North and South America, our contracting entity is Stripe Payments Europe, Limited. The onward transfer to Stripe, LLC in the United States happens inside the Stripe group. For lynox's own leg: EU — no third-country transfer, our counterparty being Stripe Payments Europe, Limited (Ireland). For Stripe's onward transfer to Stripe, LLC (US): EU-US and Swiss-US Data Privacy Framework. Stripe's Data Transfers Addendum §2 makes the mechanisms mutually exclusive and gives the Data Privacy Framework precedence, so the SCCs (2021/914) are a fallback that activates only if the DPF ceases to apply — not a second mechanism running alongside it.
Hetzner Online GmbH Server infrastructure — shared tenant hosts (isolated container per customer); dedicated VPS as Enterprise upgrade Germany (EU) EU
Brevo (Sendinblue SAS) Transactional email delivery (SMTP relay) and contact list management EU (France/Germany) EU
Cloudflare, Inc. DNS, CDN, DDoS protection, tunnel relay. TLS terminates at the Cloudflare edge, so Cloudflare has plaintext visibility on incoming HTTPS traffic before it is re-encrypted to our origin. United States / EU (edge network) EU-US and Swiss-US Data Privacy Framework + SCCs
Plausible Insights OÜ Anonymous website analytics (no personal data) EU (Estonia) EU
Google (entity per the account's Analytics terms — see mechanism) Marketing measurement on lynox.ai only — Google Analytics 4 + Google Tag Manager (Consent Mode v2; fires only with marketing consent via Klaro). Not engaged for any data flow inside the Managed Hosting service. United States, or the EEA where the account contracts with a Google entity there Google's terms name the contracting entity as "Google LLC, Google Ireland Limited or any other Affiliate of Google LLC", and which one applies follows the Analytics terms accepted for the account. lynox's account is Swiss-domiciled and no Swiss variant of those terms is published, so we do not assert which entity it is. Where it is Google LLC (US), Google's EU-US and Swiss-US DPF certification applies (US Department of Commerce register, checked 2026-08-11; certification expires 2026-09-23) with SCCs (2021/914, Module 2) as Google's stated fallback; where it is a Google entity in the EEA, no third-country transfer arises on this leg. Module 3 is not ours — it governs Google's own onward transfers.
Self-hosted (Bugsink) Error reporting (always active for managed instances) EU (self-hosted on lynox infrastructure) No third-party transfer

Prompt caching. Prompt prefixes are cached to cut latency and cost: on Anthropic we set explicit cache breakpoints, while Mistral and Fireworks apply their own automatic prefix caching. Cached data is short-lived and expires on its own: our Anthropic cache breakpoints carry a one-hour time-to-live, and for Fireworks its documentation states the data stays in volatile memory and is never written to persistent storage. Caching is the one carve-out from the Fireworks zero-retention commitment cited in the table.

Customer-configured endpoints (BYOK). If you connect your own LLM provider via Settings → LLM — for example OpenAI, an OpenAI-compatible endpoint, Google Vertex AI, or a self-hosted model — that provider is engaged by you under your own agreement with it. It is not a lynox sub-processor and is not listed above; you act as controller for that transfer. See "Customer-configured endpoints" in the DPA.

Change notification

We notify Managed Hosting customers at least 30 days in advance of any addition or replacement of sub-processors, per section 8.4 of the DPA. To subscribe to sub-processor change notifications or object to a change, contact [email protected].

Contact

For questions about sub-processors:
[email protected] · EU representative: Prighter portal