Sub-processors
Version 1.0.0, effective from October 4, 2026
Spyral uses a small number of service providers to run the Services. When one of them processes personal data that Spyral handles on behalf of a customer, it is Spyral's sub-processor. This page lists those providers. It forms Annex III of the Data Processing Agreement (the "DPA"), and the DPA governs how the list may change.
Current sub-processors
Service infrastructure
Providers that host, run, secure or deliver the service and process customer data to do so.
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Vercel | Application hosting, server functions and content delivery | All service data in transit; request logs (IP address, user agent) | GermanyServer functions run in Frankfurt; static assets are delivered from a global edge network. |
| Supabase | Database, file storage and real-time updates | Account data, customer documents and their extracted content, chats, activity logs | GermanyAWS eu-central-1 (Frankfurt). |
| Resend | Sending transactional email (codes, invitations, notifications) | Recipient email address, name and the email content | IrelandSending region eu-west-1 (Ireland). |
| Sentry | Error monitoring (no session replay) | Error details, technical identifiers and request metadata | Region to be confirmed.Not yet confirmed |
| Upstash | Rate limiting | Hashed identifiers and request counters | Region to be confirmed.Not yet confirmed |
| Stripe | Subscription billing and payments | Billing contact, company and payment details | Under the provider's own data processing terms.Not yet confirmed |
| Cloudflare | DNS and forwarding of email sent to Spyral addresses | DNS queries; email sent to Spyral addresses | Global network. |
AI inference
Providers that run the AI models on customer content. Only models served from an allowed EU or EEA location are ever used.
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Mistral AI | AI text processing: assistant, extraction, classification and drafting | Document text and prompts sent for processing | European Union, EFTA countries, including SwitzerlandMistral's EU endpoint, served from data centres in EU and EFTA countries, including Switzerland.Not yet confirmedData processing agreement not yet signed: Spyral sends this provider no data until it is.No training on customer data: required by Spyral, written confirmation pending.Zero data retention: requested, not yet confirmed. |
| Nebius | AI image reading (OCR), search embeddings and fallback text processing | Document page images, text chunks for search, prompts on fallback | Finland, FranceOnly models served from Finland or France are used; every response's serving region is checked.No training on customer data: required by Spyral, written confirmation pending.Zero data retention: requested, not yet confirmed. |
Features you turn on
Used only when a firm sends a document for signature through Spyral's own DocuSign account. A firm's own account is a service it connects itself (see below).
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| DocuSign | Electronic signature requests sent through Spyral's own DocuSign account | Signer names, email addresses and the documents to sign | European UnionEU account (eu.docusign.net) once production signing is enabled.Not yet confirmed |
Several providers on this list belong to groups established outside the European Economic Area (EEA), in particular in the United States, while processing Spyral's data inside it. Where such a provider, or a company in its group, may access data from outside the EEA, for example for support or security, clause 11 of the DPA sets out the safeguards that apply. Customers bound by professional secrecy should note the country in which each provider is established as well as where it processes data (clause 14 of the DPA).
AI models
The AI providers on this list run the language, vision and embedding models behind Spyral's AI features. The AI register shows which model is used for which feature and where each model runs. Moving between models of a provider already on this list is not a change of sub-processor, provided the model runs in the EEA or Switzerland. Spyral checks where each model runs before sending it any data, and never sends personal data to a model it knows to run elsewhere (clause 11.4 of the DPA).
What is not on this list
- Services you connect yourself. File storage services, messaging tools such as Slack or Microsoft Teams, and your own electronic signature account, where you connect one, receive data on your instruction under your own agreement with that provider. They are your recipients, not Spyral's sub-processors.
- Processing for Spyral's own purposes. Where a provider only handles data that Spyral holds as controller, such as account and billing data, the Privacy Policy governs that processing, not the DPA.
- Professional advisers. Auditors, lawyers and security testers that Spyral engages may see data where their engagement requires it, under confidentiality obligations.
- Our providers' own processors. A provider on this list may itself use further processors. Spyral's contract with each provider requires it to impose equivalent data protection obligations on them, and each provider publishes or provides its own list.
The services a firm can connect itself, and what each one receives, are:
| Service | What it receives | When |
|---|---|---|
| Google Drive | Spyral receives the files a user picks, with their name, type, size and dates. Google sees the selection made in its own picker. | When a user imports files through the Google file picker. |
| Dropbox | Spyral reads the files in the folders the firm designates, or the files a user picks. | When the firm connects its Dropbox account, or a user picks files. |
| Slack | The text of commands sent to Spyral from the firm's Slack workspace, and Spyral's replies. Commands that would return document content are switched off. | When the firm links its Slack workspace. |
| Microsoft Teams | Account alerts for the firm, posted to the channel it connects. No client data. | When the firm connects a channel, and only once Spyral sends channel alerts. None are sent at present. |
| DocuSign | The documents sent for signature, and the names and email addresses of the signers. | When the firm connects its own DocuSign account and sends a document for signature. |
How changes are notified
We tell customers about any intended addition or replacement of a sub-processor at least 30 days before the new provider processes their personal data:
- by email to the owners of each workspace;
- by a notice in the application; and
- by publishing a new version of this page. Earlier versions remain available in the version history below.
The notice names the provider, the processing it will carry out and where. A provider already on the list that starts to process personal data outside the EEA or Switzerland is treated as an addition. A change that does not affect the processing, such as a provider's new company name, is published as a new version of this page without the notice period.
If a provider must be replaced urgently, to protect the security of personal data or because it has stopped providing its service, the notice period may be shorter. We still give notice before the replacement processes any customer data.
If you are not a workspace owner and want to receive these notices, for example as the data protection officer of a customer firm, write to privacy@spyral.lu and we will add you to the notification list.
How to object
A customer may object to an intended change on reasonable grounds relating to the protection of personal data:
- Write to privacy@spyral.lu within the notice period, on behalf of the customer, and explain the grounds.
- We acknowledge the objection within five business days and discuss it with you in good faith. Where we can, we offer an alternative, such as not using the new provider for your data.
- If the objection is not resolved before the change takes effect, you may terminate the affected services with effect before the change, without penalty, and we refund any prepaid fees for the period after termination.
How we choose providers
Before we engage a provider that will process customer personal data, and at least once a year after that, we check the following:
- Location. The provider processes the data in the EEA, or in a country the European Commission recognises as providing adequate protection, and commits to that location. For AI providers, the location of each model must be published so that we can verify it.
- Contract. A written data processing agreement that meets Article 28 GDPR: processing only on our instructions, confidentiality, security, the same obligations for its own processors, assistance, breach notification, deletion at the end of the service, and information for audits. A provider receives no customer personal data before that agreement is signed.
- Use of data. The provider does not use customer data for its own purposes. AI providers must not use it to train or improve their models, and we ask each of them for zero data retention. The table above shows, for each AI provider, whether these terms are confirmed in writing and whether zero data retention is in effect.
- Security. Measures appropriate to the data, and independent certifications or audit reports, such as ISO/IEC 27001 or SOC 2, where the provider holds them.
- Transfers. Where access from outside the EEA is possible, an adequacy decision or the European Commission's standard contractual clauses, assessed for the country concerned.
- Minimisation. The provider receives only the data it needs for its service.
- Exit. Data can be retrieved and is deleted when the service ends.
We keep the number of providers deliberately small. For AI processing, we limit ourselves to two providers.
Questions
Questions about this list, or requests for a copy of a provider's data protection terms, can be sent to privacy@spyral.lu.
Version history
| Version | Effective from | Status |
|---|---|---|
| 1.0.0 | October 4, 2026 | In force |