DocReadi

Sub-processors

Last updated 2026-07-10

DocReadi uses the third-party sub-processors listed below to deliver the service. Sub-processors are bound by written agreements requiring confidentiality, security, and data-protection commitments equivalent to those we commit to our tenants.

We notify tenant account holders by email at least 30 days before activating a new sub-processor. Tenants may object; the parties will discuss a carve-out or termination right where objection is raised.

Current list

Sub-processor Role Data Region Safeguards
Anthropic LLM extraction (primary provider) Document markdown + optional page images United States
  • EU-US DPF certified
  • No training on inputs
  • Published API DPA. Use for tenant default extraction.
OpenAI LLM extraction (tenant opt-in) Document markdown + optional page images United States
  • EU-US DPF certified
  • No training on inputs
  • Published API DPA. 30-day abuse-monitoring retention.
Google (Gemini) LLM extraction (tenant opt-in) Document markdown + optional page images United States / EU
  • EU-US DPF certified
  • No training on inputs
  • Paid API tier only. Cloud DPA covers transfers.
Mistral OCR + LLM extraction (tenant opt-in) PDF bytes or markdown European Union (France)
  • EU-US DPF certified
  • No training on inputs
  • GDPR-native. Recommended default for EU-origin tenants.
xAI (Grok) LLM extraction (tenant opt-in) Document markdown United States
  • EU-US DPF certified
  • No training on inputs
  • Verify DPA before routing EU-origin data; SCCs advisable.
OpenRouter LLM aggregator (tenant opt-in) Document markdown United States (aggregator); downstream provider varies — MAY include PRC (China) region models
  • EU-US DPF certified
  • No training on inputs
  • Pass-through aggregator: posture inherits from the selected downstream model. Some routable models are PRC-region (e.g. Baidu Qianfan, Alibaba Qwen, Meta Llama variants) and MAY use submitted content for training on free tiers — these are DISABLED by default (alembic 0043) and must be explicitly re-enabled by a super-admin. Verify each underlying provider before routing EU/SA-origin data.
Baidu (Qianfan-OCR, via OpenRouter) OCR-tuned vision LLM — free-tier model (tenant opt-in, DISABLED by default) Document images + extracted text China (PRC)
  • EU-US DPF certified
  • No training on inputs
  • Reachable only by explicitly selecting `baidu/qianfan-ocr-fast:free` in the extraction fallback stack. Force-disabled platform-wide by default (alembic 0043); a super-admin must re-enable it. Free-tier ToS may permit training-data use — recommend a paid tier or a different model for any tenant whose data sensitivity requires no-training terms. EU/SA tenants enabling it should disclose PRC processing in their own privacy notice.
Alibaba (Qwen, via OpenRouter) Vision/OCR LLM — Qwen3-VL / Qwen2.5-VL family (tenant opt-in, DISABLED by default) Document text + optional images China (PRC)
  • EU-US DPF certified
  • No training on inputs
  • Reachable only by explicitly selecting a `qwen/*` model in the extraction fallback stack. Force-disabled platform-wide by default (alembic 0043); a super-admin must re-enable it. Same PRC-processing disclosure concern as Baidu above, but Qwen has a published commercial API with stricter retention terms than a free tier.
Meta (Llama, via OpenRouter) Vision LLM — Llama 3.2 11B Vision (tenant opt-in, DISABLED by default) Document text + optional images Varies (US / EU) — open-weight; the OpenRouter-side host (DeepInfra, Groq, etc.) is the actual data recipient and rotates per request
  • EU-US DPF certified
  • Reachable only by explicitly selecting `meta-llama/llama-3.2-11b-vision-instruct` in the extraction fallback stack. Force-disabled platform-wide by default (alembic 0043); a super-admin must re-enable it. Open-weight model — training posture depends on the serving host, not Meta directly.
Railway Application + database hosting All application data at rest and in transit EU West 4 (the Netherlands) for this deployment
  • US-headquartered company; data processed in EU. Provider DPA available; sign before live traffic.
Amazon Web Services (S3) Encrypted pg_dump backup storage Age-encrypted database dumps United States (us-east-1)
  • EU-US DPF certified
  • Backups are age-encrypted (client-side) before upload; AWS receives ciphertext only. Lifecycle: 30d hot, then Glacier Deep Archive, deleted at 365d.
Meta (WhatsApp Business API) Inbound document ingestion from WhatsApp (optional per tenant) Media attachments forwarded from WhatsApp numbers United States / global
  • EU-US DPF certified
  • Only active when a tenant enables WhatsApp routing. Tokens stored Fernet-encrypted at rest.
OpenStreetMap Nominatim Address geocoding (optional per tenant) Vendor address strings European Union
  • Off by default — only active when a workspace enables the map-pin geocoding feature. Public endpoint; no account or API key required.
Sentry Error tracking (active in production) Stack traces + request metadata + company_id/user_id tags Configurable (US or EU)
  • EU-US DPF certified
  • send_default_pii=False — no document bodies or cookie values leave the container; only errors + request metadata + company_id/user_id tags are transmitted.
Polar Merchant of Record — international (USD/EUR/GBP) billing Billing identity (name, email), payment + subscription metadata, company_id United States / global
  • Active for non-ZAR (international) tenants. Handles card processing + global VAT/sales-tax as Merchant of Record. Receives billing identity + plan metadata only — NEVER document content. Provider DPA applies.
Paystack Payment processor — South African (ZAR) billing Billing identity (name, email), payment + subscription metadata, company_id South Africa / Nigeria
  • Active for ZAR tenants. Receives billing identity + plan metadata only — NEVER document content.
Resend Transactional + notification email; Outbox email-delivery destination Recipient email address, name, email subject/body; AND processed document-bundle attachments when a tenant configures an email delivery destination United States
  • Transactional mail (verification, password reset, billing, connection-paused alerts) carries no document content. However the Outbox 'email' delivery destination attaches the processed document bundle (PDF/CSV, up to the size cap) to a Resend email, so Resend DOES receive document content on that tenant-enabled path.
Cloudflare DNS + inbound email routing + email-in document ingestion (Email Worker) DNS queries; inbound email envelope + body forwarded to the operator; and — on the email-in ingestion path — tenant supplier-inbox messages incl. their document attachments United States / global edge
  • Two roles. (1) Email Routing forwards mail sent to the @docreadi.com support/legal/privacy/sales inboxes to the operator's mailbox (receive-only relay). (2) A Cloudflare Email Worker backs the per-tenant supplier-inbox addresses (<prefix>[email protected]): it receives a tenant's forwarded supplier emails and POSTs the attachments (document files) to the pipeline for extraction — so document content transits Cloudflare when email-in ingestion is enabled.
Xero Accounting-system delivery — Bill push (optional per tenant; dormant by default) Approved-document financial data only: supplier/contact name, VAT number, email, invoice number + date, line descriptions, amounts, tax + GL account codes United States / Australia / European Union (Xero's regions)
  • Off unless a tenant connects a Xero organisation (OAuth) and a super-admin enables the `xero_integration` flag. When active, DocReadi pushes the structured fields of an approved bill to the connected org — NEVER the source document file or page images. OAuth tokens stored Fernet-encrypted at rest; the grant is revoked (DELETE /connections) when the tenant disconnects.

Sub-processors marked as providing a specific LLM provider are activated per-tenant: a tenant may choose a default extraction provider and may opt-in / opt-out of alternatives via the tenant settings page. The default provider is Anthropic.

Change history

We maintain an audit trail of sub-processor changes. Current state reflects the list above.

Contact

Sub-processor questions: [email protected].