Legal · Controlled draft
Subprocessor List
Draft register of providers that may process information on OperelliOS’s behalf.
1. Purpose and Definition
OperelliOS may use service providers to help deliver the Service. A provider is a subprocessor when it processes personal information on OperelliOS’s behalf in a processor or service-provider capacity.
This draft is a verification register, not a final vendor disclosure. A provider should appear as active only after production use, purpose, data categories, location, contract, and retention have been confirmed.
2. Controlled Inventory
The following entries reflect known architecture signals and unresolved verification. They must not be treated as final public representations.
| Provider | Purpose | Data Categories | Product Layer | Processing Location | Status | Verification Source | Last Verified |
|---|---|---|---|---|---|---|---|
| Auth0 (unconfirmed) | Identity and account recovery | Account identifiers, authentication metadata | Core identity | [ENGINEERING VERIFICATION REQUIRED: Confirm location] | [ENGINEERING/LEGAL VERIFICATION REQUIRED: confirm production scope and contract] | [ENGINEERING VERIFICATION REQUIRED] | Unverified |
| Mailgun (unconfirmed) | Transactional email delivery | Recipient email, message metadata and content required for delivery | Core communications | [ENGINEERING VERIFICATION REQUIRED: Confirm location] | [ENGINEERING/LEGAL VERIFICATION REQUIRED: confirm production scope, region, retention, and contract] | [ENGINEERING VERIFICATION REQUIRED] | Unverified |
| Hosting and infrastructure provider (unconfirmed) | Application, database, storage, networking, backups | Customer Data and operational metadata | Core infrastructure | [ENGINEERING VERIFICATION REQUIRED: identify provider(s), services, regions] | [ENGINEERING VERIFICATION REQUIRED: identify provider(s), services, regions, and data categories] | [ENGINEERING VERIFICATION REQUIRED] | Unverified |
| AI model or infrastructure provider (unconfirmed) | AI-assisted drafting, extraction, summarization or classification | Prompts, source content, outputs and telemetry as configured | AI layer | [ENGINEERING VERIFICATION REQUIRED: Confirm location] | [PRODUCT/ENGINEERING DECISION REQUIRED: identify provider and approve data-use controls] | [ENGINEERING VERIFICATION REQUIRED] | Unverified |
| Monitoring or error provider (unconfirmed) | Reliability, diagnostics, security monitoring | Device, request, error, log and tenant metadata as configured | Control plane | [ENGINEERING VERIFICATION REQUIRED: Confirm location] | [ENGINEERING VERIFICATION REQUIRED] | [ENGINEERING VERIFICATION REQUIRED] | Unverified |
| Support provider (unconfirmed) | Customer support and issue management | Contact details, tickets and attachments | Support | [ENGINEERING VERIFICATION REQUIRED: Confirm location] | [ENGINEERING VERIFICATION REQUIRED] | [ENGINEERING VERIFICATION REQUIRED] | Unverified |
3. Provider Selection and Controls
Before a provider is approved, OperelliOS should evaluate purpose, minimum data access, security posture, contract terms, confidentiality, incident duties, retention, deletion, locations, downstream subprocessors, business continuity, and exit procedures.
AI providers require additional review of prompt and output retention, human review by provider personnel, model-training rights, abuse monitoring, and regional processing.
4. Changes to Subprocessors
The final policy should state how the list is updated and whether notice or an objection process applies to particular customers.
[LEGAL REVIEW REQUIRED: Approve change-notice obligations and any enterprise objection process.]
5. Questions
Questions about subprocessors: [LEGAL REVIEW REQUIRED: Confirm legal and privacy contact email]
Related documents:
**Contact placeholder:** [LEGAL REVIEW REQUIRED: Confirm legal and privacy contact email]
Questions
Questions about subprocessors or this list.
[LEGAL REVIEW REQUIRED: Confirm legal and privacy contact email]