Sub-processors
Effective: April 27, 2026 · Last updated: April 27, 2026
This document lists the third-party sub-processors that may process Customer Data on behalf of Tangle Technologies, Inc. ("Tangle") in connection with the Services. We update this list when sub-processors are added, removed, or change their role. See the Privacy Policy for how Tangle handles personal information and the Security Information Page for current security practices.
Notification
Customers can subscribe to sub-processor change notifications by emailing [email protected] with subject line "Sub-processor notifications". We give at least 30 days' notice before adding a new sub-processor that processes Customer Data, except where the change is required by law or to address a security incident.
Active sub-processors
| Sub-processor | Service | Customer Data processed | Region | Legal basis |
|---|---|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure hosting (compute, storage, networking) | All Customer Data within sandboxes | Germany / Finland | Standard Contractual Clauses (SCCs) for EU transfers |
| Cloudflare, Inc. | Edge security, DNS, DDoS protection, R2 object storage | Request metadata, IP addresses, audit artifacts | US, EU edge POPs | SCCs |
| Stripe, Inc. | Payment processing | Billing email, name, payment-method tokens (no full PAN) | US | DPA on file |
| Google LLC (Google Workspace) | Email, calendaring, document collaboration for Tangle staff | Customer support communications | US | DPA on file |
| Sentry (Functional Software, Inc.) | Error reporting, performance telemetry | Error events with credentials, PCI cardholder data, and government IDs scrubbed by the runtime redactor before send | US | DPA on file |
| OpenAI, L.L.C. | LLM inference when Customer selects an OpenAI model in the sandbox | Prompt and completion text the Customer's agent sends; the egress filter scrubs authentication credentials, PCI cardholder data, and government IDs before transmission | US | API DPA; per-request store: false enforced when the Customer hasn't set it |
| Anthropic, PBC | LLM inference when Customer selects an Anthropic model | Same as OpenAI; account-level Zero Data Retention (ZDR) governs vendor retention | US | Commercial Terms + ZDR addendum |
| Resend | Transactional email (account, billing, security notifications) | Email addresses of account holders | US | DPA on file |
Provider that does not process Customer Data
GitHub, Inc. provides source code hosting, CI execution, and a container registry for Tangle internal source. It does not process Customer Data. Its region is the US, under an Enterprise agreement.
Sub-processor categories Customers may opt out of
- Model vendors (OpenAI / Anthropic). Customers select their model vendor at sandbox creation; selecting a different vendor changes which sub-processor receives prompt content. Customers requiring a specific vendor under their own DPA or BAA should contact [email protected].
Outbound data minimization
For observability outputs and JSON sent to model vendors, the Services apply two enforcement layers before Customer Data leaves the sandbox:
- Internal observability redaction. Credentials, PCI cardholder data, and government identifiers are stripped from logs, error events, audit trails, and billing events before they leave the runtime.
- External egress redaction + no-retention. Outbound JSON bodies to model vendors run through the same redactor; OpenAI Chat Completions are augmented with
store: falsewhen the Customer hasn't set it.
Customers can fetch the live posture from any sandbox at GET /privacy (authenticated).