Subprocessors
Last updated: April 20, 2026
Orqesa uses a small number of trusted providers to operate the service. We commit to 30 days' advance notice before adding or replacing any subprocessor that processes customer personal data.
1. Our commitment
- Zero training. None of our subprocessors use your data to train AI models. Where a provider offers a Zero Data Retention (ZDR) tier, Orqesa is on it.
- Narrow scope. Each subprocessor only receives the data strictly required for its function.
- Contracts in place. We have executed a Data Processing Agreement (DPA), Standard Contractual Clauses (SCCs), or equivalent with every subprocessor that handles personal data.
- Change notice. We give at least 30 days' advance notice before adding or replacing a subprocessor that processes personal data.
- Government requests transparency. We challenge overbroad or unlawful government data requests where we can and report totals in this page below. To date: we have received zero government requests for user data.
2. Infrastructure and product
| Provider | Purpose | Region | DPA |
|---|---|---|---|
| Vercel Inc. | Hosting, CDN, edge functions, rate-limiting, runtime logs | Global edge; primary US | DPA |
| Supabase Inc. | Primary database + authentication (when product access is live; not used by the public website) | EU (selectable) | DPA |
| Namecheap, Inc. | Domain registration, DNS, Private Email mailbox for hi@ | US | Privacy Policy |
3. AI model providers
Orqesa advisors are powered by third-party AI models. We maintain Zero Data Retention agreements with these providers wherever offered — inputs and outputs are not retained beyond the request and are never used for training.
| Provider | Model family | Region | Training & retention |
|---|---|---|---|
| Anthropic PBC | Claude | US; EU routing available | Commercial API terms; no training on customer data; ZDR enabled. Privacy Center |
| OpenAI, L.L.C. | GPT series | US; EU residency available | Enterprise/Business terms; no training on API data; ZDR enabled. Policies |
| Google LLC (Vertex AI) | Gemini | Configurable (US or EU) | Vertex AI customer data not used to train foundation models; ZDR via Vertex settings. DPA |
4. Email and communications
| Provider | Purpose | Region | DPA |
|---|---|---|---|
| Resend, Inc. | Transactional email (waitlist confirmations, account notices) | US (AWS us-east) | DPA |
5. Analytics (consent-gated for EU/UK)
Analytics providers only receive data when you consent, if you are in the EU, EEA, UK, or Switzerland. Elsewhere, they load on the basis of legitimate interest and you can still opt out in the banner.
| Provider | Purpose | Region | DPA |
|---|---|---|---|
| Google LLC (Google Analytics 4) | Aggregated site analytics, event tracking | Global; IP anonymization enabled | DPA |
| Vercel Inc. (Web Analytics) | Cookieless page and Web Vitals analytics | Global edge | DPA |
6. Transfer safeguards
Where personal data is transferred outside the EU/EEA or UK, we rely on:
- Standard Contractual Clauses (SCCs) — Decision 2021/914 Module 2 for processor-to-processor transfers;
- UK International Data Transfer Addendum for UK transfers;
- EU–US Data Privacy Framework certification where the subprocessor is certified.
7. Objections and notifications
If you object to a new subprocessor on reasonable data-protection grounds, email hi@orqesa.com within 14 days of the announcement. We will either (a) not use that subprocessor for your data, or (b) give you the option to terminate the Service without penalty if we cannot reasonably accommodate your objection.
To receive announcements about subprocessor changes, email hi@orqesa.comwith subject "Subprocessor updates".