Definitions
A Subprocessor is a third party engaged by AI Reserve to process Personal Data on our clients' behalf, acting only on our documented instructions.
Under our Data Processing Addendum, a provider that processes data for its own purposes — for example, a model provider whose terms permit it to train or fine-tune on inputs — is an independent controller, not a subprocessor. Such providers are identified separately in the Independent controllers section below. Requests are only sent to those providers when a user or client explicitly selects one of their models.
Per-provider detail on training, retention, and processing region is on the Provider Data Handling page.
Infrastructure & platform subprocessors
These providers support the operation of the AI Reserve platform itself and may process Personal Data in the course of providing their services.
| Subprocessor | Function | Jurisdiction |
|---|---|---|
| Google Cloud Platform | Cloud hosting, compute, databases, object storage, secret management, and logging for all AI Reserve services | United States |
| Google Firebase Authentication | Identity and sign-in for the AI Reserve portal (web application) | United States |
| Auth0 by Okta | OIDC identity brokering for keyless desktop-application sign-in (e.g. Claude Desktop) | United States |
| IPinfo | IP geolocation and anonymizer screening for the machine API. Receives request IP addresses only — never request content | United States |
Model providers acting as subprocessors
When a user or client selects a model, the request content is processed by the model's provider. The following providers process request data only to deliver inference, do not train on API inputs under their current enterprise terms, and act as subprocessors. A request is sent only to the provider serving the specific model selected — no provider receives traffic for models it does not serve.
| Subprocessor | Function | Jurisdiction |
|---|---|---|
| OpenAI, L.L.C. | Model inference (GPT model family; embeddings; image generation) | United States |
| Anthropic, PBC | Model inference (Claude model family, direct API) | United States |
| Amazon Web Services (Bedrock) | Model inference for -bedrock routed models (Anthropic Claude, Meta Llama, Mistral, DeepSeek serverless) — model publishers do not receive request data |
United States |
| Google (Gemini API) | Model inference (Gemini model family; image generation), paid tier | United States (processing may occur globally — see data handling) |
| xAI Corp. | Model inference (Grok model family) | United States |
| Perplexity AI, Inc. | Model inference with web search grounding (Sonar model family) | United States |
| Together Computer, Inc. (Together AI) | Hosted inference of open-weight models (e.g. Qwen, DeepSeek V4 Pro, Kimi K2.7, MiniMax, GPT-OSS-20B) | United States |
| Fireworks AI, Inc. | Hosted inference of open-weight models (e.g. GLM, Qwen, Kimi K2.6, DeepSeek V4 Flash, GPT-OSS-120B) | United States |
| OpenRouter, Inc. | Routing layer for certain open-weight model routes (Meta Llama, Mistral). OpenRouter itself does not store request content by default; the downstream serving endpoint's policy applies — per-route endpoints pending verification | United States (routing); downstream endpoint varies |
| fal — Features & Labels, Inc. (fal.ai) | Hosted video and image generation | United States |
Model providers acting as independent controllers
The following model providers' current terms permit them to process request data for their own purposes (including using inputs to train or improve their services). Under our DPA they are therefore independent controllers, not subprocessors, and are identified as such. Requests reach these providers only when a user or client explicitly selects one of their directly-served models. Open-weight DeepSeek and Moonshot models served by US aggregators (Fireworks, Together) or AWS Bedrock do not send data to these companies.
| Provider | Function | Jurisdiction | Why independent controller |
|---|---|---|---|
| Hangzhou DeepSeek Artificial Intelligence Co., Ltd. | Model inference, direct DeepSeek API (deepseek-chat, deepseek-reasoner) |
China (PRC) — data collected, processed, and stored on servers in the PRC | Privacy policy states inputs are used to train and improve its models and services |
| Moonshot AI (Kimi) | Model inference, Moonshot's own API (kimi-k3, moonshot-v1-*) |
China (PRC-headquartered). International platform terms state Singapore-located servers; endpoint serving our account pending verification | Platform privacy policy states user content is used to train and refine its models |
| NVIDIA Corporation (hosted NIM API catalog) | Model inference (Nemotron model family) | United States | Published API-catalog trial terms permit NVIDIA to use inputs/outputs to improve its products and services, including AI models. Whether different terms govern our account tier: pending verification — classified conservatively as independent controller until confirmed |
Other service providers
Data enrichment (Harmonic). The platform's business-data features use a company-data enrichment provider that receives only public company identifiers (such as company names and website domains) — never client request content, prompts, completions, or personal data of client users.
Updates to this list
This list is maintained on the Platform per Annex 5 of our Data Processing Addendum and is reviewed periodically. When we engage a new subprocessor that will process Personal Data, we update this page and provide any notice required by the DPA. Items marked pending verification reflect characteristics we have not yet confirmed from official documentation — confirm before relying on them.
Questions about this list or our DPA: contact product@aireserve.com.