Skip to main content

Subprocessors

Last updated: 2026-05-25

AimRank uses a small set of vetted subprocessors to operate the Service. This page is the canonical reference cited by our Privacy Policy §6 (Data Sharing) and the Data Processing Agreement we sign with business customers. Each subprocessor below has its own DPA with us; we impose data-protection obligations on each one that are no less protective than those we owe you under GDPR Art. 28(4).

Change notification: we publish proposed additions to this list at least 30 days before they go live. If you are a controller with a signed AimRank DPA and you want to object to a new subprocessor on data-protection grounds, write to privacy@aimrank.io and we will work with you under the DPA §5 objection process.

Amazon Web Services (AWS) EMEA SARL

Service
Compute, storage, networking, ML inference
Purpose
Hosts the AimRank application (ECS Fargate), database (RDS PostgreSQL), file storage (S3), caching (ElastiCache Redis), and LLM-as-judge inference (Bedrock, Anthropic Claude models)
Data categories
All Personal Data processed in the Service (Account Data, Vote Data, Audit Logs)
Region
eu-central-1 (Frankfurt, Germany) primary; eu-west-1 (Ireland) DR target
Transfer mechanism
Processor located in EU; no third-country transfer for primary processing.
Vendor DPA
https://aws.amazon.com/compliance/eu-data-protection/

Anthropic Ireland Limited

Service
LLM-as-judge inference (via AWS Bedrock)
Purpose
When the customer enables LLM-judge votes (Article 50 disclosed), Claude models process anonymised content snippets to produce preference judgments. Inference happens on AWS Bedrock eu-central-1 under the AWS contract; Anthropic provides the model weights.
Data categories
Pseudonymised entity content (no Account Data; voter_id is null on judge votes)
Region
Inference: eu-central-1 (AWS Bedrock). Anthropic Ireland is the contracting entity.
Transfer mechanism
EU-to-EU; AWS Bedrock zero-data-retention configuration eliminates Anthropic-side storage.
Vendor DPA
https://www.anthropic.com/legal/dpa

Stripe Payments Europe Limited (Ireland)

Service
Subscription billing + payment processing
Purpose
Processes Creator / Scale / Business / Enterprise tier subscriptions; handles invoicing, payment-method tokenisation, VAT-OSS receipts
Data categories
Billing email, address, payment-method tokens (no card numbers stored by AimRank), Stripe customer ID
Region
EU (Stripe Ireland). Some pseudonymous tokens may transit US-located Stripe infrastructure under approved transfer mechanism.
Transfer mechanism
Stripe SCCs + Data Protection Framework (where applicable)
Vendor DPA
https://stripe.com/legal/dpa

Functional Software, Inc. (Sentry)

Service
Error monitoring + performance telemetry
Purpose
Server-side and client-side error capture, performance traces; PII scrubbing is enabled at SDK init (no IP, no email, no session content)
Data categories
Error stack traces, request paths, browser metadata, anonymised performance traces
Region
EU instance (de.sentry.io). Confirm before signing customer DPAs that the Sentry org is on the EU plan, not US
Transfer mechanism
EU-only when on the EU instance; SCCs if US instance used
Vendor DPA
https://sentry.io/legal/dpa/

Amazon Web Services: SES (Simple Email Service)

Service
Transactional email delivery
Purpose
Sends verification emails, password resets, security alerts, anomaly notifications. No marketing emails without separate consent.
Data categories
Email address, IP address (in delivery metadata only), email subject + body
Region
eu-central-1 (Frankfurt)
Transfer mechanism
EU-to-EU (same AWS contract as compute)
Vendor DPA
https://aws.amazon.com/compliance/eu-data-protection/

Google Ireland Limited

Service
OAuth identity provider (optional sign-in)
Purpose
When a user chooses "Sign in with Google", we receive the user's email and Google profile name from Google to create/link an AimRank account
Data categories
OAuth-provided email and name; Google retains its own data per its policy
Region
EU (Google Ireland is the contracting entity for EEA users)
Transfer mechanism
EU SCCs + Data Protection Framework where applicable
Vendor DPA
https://policies.google.com/privacy

GitHub, Inc.

Service
OAuth identity provider (optional sign-in)
Purpose
When a user chooses "Sign in with GitHub", we receive the user's email and GitHub username to create/link an AimRank account
Data categories
OAuth-provided email and login; GitHub retains its own data per its policy
Region
US (Microsoft / GitHub)
Transfer mechanism
SCCs + Data Protection Framework
Vendor DPA
https://docs.github.com/en/site-policy/privacy-policies/github-data-protection-agreement

PostHog Inc. (EU)

Service
Product analytics (opt-in only)
Purpose
When a visitor explicitly consents via the Cookie Banner, we record pageviews + autocaptured UI events for funnel/retention analysis. No PII captured. Session replay is disabled.
Data categories
Anonymous distinct_id (localStorage), URL paths, click + form-submission events, UTM parameters
Region
EU instance (eu.i.posthog.com, Frankfurt)
Transfer mechanism
EU-only when on the EU instance
Vendor DPA
https://posthog.com/handbook/growth/security/dpa

Not subprocessors (excluded by design)

  • OpenAI, Google Gemini, xAI: AimRank does not call these as judges. Bedrock-hosted Claude is the only LLM judge.
  • Scale AI, Surge AI, Mercor: AimRank does not subcontract labelling to US-hosted preference-data vendors. Expert labellers are recruited and engaged directly under the L4 program.
  • Customer-controlled LLM endpoints: if a customer routes their own model through AimRank for evaluation, that endpoint is the customer's processor, not ours.

Contact

Questions, subprocessor objections, or DPA requests: privacy@aimrank.io. EU AI Act and supply-chain compliance questions are handled by iCOMPLY, our sister AI Act audit SaaS.