Sub-processors

Effective: April 27, 2026 · Last updated: October 8, 2026

This document lists the third-party sub-processors that may process Customer Data on behalf of Tangle Technologies, Inc. ("Tangle") in connection with Tangle-operated websites, applications, and services at tangle.tools and any of its subdomains (*.tangle.tools), together with our APIs and related services. We update this list when sub-processors are added, removed, or change their role. See the Privacy Policy for how Tangle handles personal information and the Security Information Page for current security practices.

Notification

Customers can subscribe to sub-processor change notifications by emailing [email protected] with subject line "Sub-processor notifications". We give at least 30 days' notice before adding a new sub-processor that processes Customer Data, except where the change is required by law or to address a security incident.

Active sub-processors

Sub-processorServiceCustomer Data processedRegionLegal basis
Hetzner Online GmbHCloud infrastructure hosting (compute, storage, networking)All Customer Data within sandboxesGermany / FinlandStandard Contractual Clauses (SCCs) for EU transfers
Cloudflare, Inc.Edge processing and security, DNS, DDoS protection, D1 databases, KV and R2 storageRequest metadata, IP addresses, application and account records, conversation and knowledge content, files, and audit artifactsUS, EU edge POPsSCCs
Stripe, Inc.Payment processingBilling email, name, payment-method tokens (no full PAN)USDPA on file
Google LLC (Google Workspace)Email, calendaring, document collaboration for Tangle staffCustomer support communicationsUSDPA on file
Sentry (Functional Software, Inc.)Error reporting, performance telemetryError events with credentials, PCI cardholder data, and government IDs scrubbed by the runtime redactor before sendUSDPA on file
OpenAI, L.L.C.LLM inference when Customer selects an OpenAI model in the sandboxPrompt and completion text the Customer's agent sends; the egress filter scrubs authentication credentials, PCI cardholder data, and government IDs before transmissionUSAPI DPA; per-request store: false enforced when the Customer hasn't set it
Anthropic, PBCLLM inference when Customer selects an Anthropic modelSame as OpenAI; account-level Zero Data Retention (ZDR) governs vendor retentionUSCommercial Terms + ZDR addendum
ResendTransactional email (account, billing, security notifications)Email addresses of account holdersUSDPA on file

Model providers

These providers may receive request content through the Tangle Router, sandboxes, or agent applications according to the configured model and route. An application or agent can configure a default model. A model developer can differ from the inference provider that receives the request; for example, GLM models can be hosted by Together AI. Review the model and provider configuration before submitting data that requires a particular provider. Providers marked "No" in the last column must not receive EEA, UK, or Swiss personal data.

Model ProviderServiceCountry of establishmentEEA/UK/Swiss personal data
OpenAIText, image, audio modelsUnited StatesYes (SCCs)
AnthropicText modelsUnited StatesYes (SCCs)
Google (Gemini API)Text, image, video modelsUnited StatesYes (SCCs)
xAIText modelsUnited StatesYes (SCCs)
Mistral AIText modelsFranceYes
CohereText and embedding modelsCanadaYes (adequacy)
AI21 LabsText modelsIsraelYes (adequacy)
GroqOpen-model inferenceUnited StatesYes (SCCs)
Together AIOpen-model inferenceUnited StatesYes (SCCs)
Fireworks AIOpen-model inferenceUnited StatesYes (SCCs)
CerebrasOpen-model inferenceUnited StatesYes (SCCs)
SambaNovaOpen-model inferenceUnited StatesYes (SCCs)
NVIDIAOpen-model inferenceUnited StatesYes (SCCs)
Hugging FaceOpen-model inferenceUnited StatesYes (SCCs)
ReplicateOpen-model and media inferenceUnited StatesYes (SCCs)
falImage and video modelsUnited StatesYes (SCCs)
Black Forest LabsImage modelsGermanyYes
RunwayVideo modelsUnited StatesYes (SCCs)
HeyGenVideo avatar modelsUnited StatesYes (SCCs)
Sync LabsLip-sync video modelsUnited StatesYes (SCCs)
D-IDVideo avatar modelsIsraelYes (adequacy)
Twelve LabsVideo understanding modelsUnited StatesYes (SCCs)
You.comWeb searchUnited StatesYes (SCCs)
OpenRouterModel aggregation; routes requests to configured inference providersUnited StatesYes (SCCs)
ph0nyVoice models; operated by an affiliate under common control, hosted on HetznerGermanyYes
DeepSeekText modelsChinaNo
Moonshot AIText modelsChinaNo
Zhipu AI (Z.ai)Text modelsChinaNo
Kling (Kuaishou)Video modelsChinaNo
MoonMathOpen-model inferenceNot yet confirmedNo

Retention by each Model Provider follows its own terms. On the sandbox egress path, OpenAI Chat Completions receive store: false when the caller has not set that field. This setting controls response storage; it is not a general zero-retention guarantee. Anthropic processing under the applicable account is covered by a Zero Data Retention addendum. The applicable customer agreement governs provider selection and notice requirements. This inventory does not by itself establish that any required customer notice or vendor assessment has been completed.

Provider that does not process Customer Data

GitHub, Inc. provides source code hosting, CI execution, and a container registry for Tangle internal source. It does not process Customer Data. Its region is the US, under an Enterprise agreement.

Sub-processor categories Customers may opt out of

  • Model providers. Customers can select a model where the product exposes that choice; otherwise the app or agent configuration selects it. The routing configuration determines which provider receives request content. Customers requiring a specific vendor under their own DPA or BAA should contact [email protected].

Outbound data minimization

Tangle sandbox runtime controls include the following layers where that runtime and egress path are used:

  1. Internal observability redaction. Credentials, PCI cardholder data, and government identifiers are stripped from logs, error events, audit trails, and billing events before they leave the runtime.
  2. External egress redaction and request-storage settings. Outbound JSON bodies to model vendors run through the same redactor; OpenAI Chat Completions are augmented with store: false when the Customer hasn't set it.

The sandbox runtime exposes its configured posture at GET /privacy (authenticated). These sandbox controls are not a claim that every direct API request, agent application, or third-party tool passes through that egress path. Provider retention depends on the request settings and the applicable provider agreement.