legal

Subprocessors.

version 1.0 · effective may 15, 2026

We use a small set of third-party services to operate the Zentrr platform. The list below is the current set. We will provide at least thirty (30) days' notice before adding or replacing a sub-processor that handles Customer Content materially, via email to account admins or via in-product notification, so that Customer can raise reasonable objections.

Amazon Web Services, Inc.

infrastructure

Cloud infrastructure: AI inference (Bedrock), identity (Cognito), database (Aurora), storage (S3), email (SES), CDN (CloudFront), compute (ECS / Lambda), workflow orchestration (Step Functions), encryption (KMS), audit logging (CloudTrail).

location
United States (us-east-1)
notes
HIPAA-eligible under the AWS Business Associate Addendum.

Stripe, Inc.

billing

Subscription billing, Checkout, and Customer Portal. Payment card data flows directly to Stripe; Zentrr does not store full card numbers.

location
United States

Google LLC (Google Analytics + Google Ads + Google Tag Manager)

analytics

Marketing-site analytics and ad-conversion measurement.

location
United States / European Union
notes
Loaded only on the marketing site, and only when consent is granted via the cookie banner. Disabled in the authenticated application.

Anthropic, PBC

model provider

Foundation model provider (Claude models). Listed for transparency. For the default model lineup, not a direct Zentrr sub-processor — those Claude models run entirely inside AWS Bedrock and Anthropic does not have access to customer prompts, completions, or logs.

location
United States (only for opted-in provider-data-share models; otherwise n/a)
notes
Anthropic's Usage Policy and commercial terms are flowed down through our Acceptable Use Policy. Exception — provider-data-share models: a small set of frontier models (currently Claude Fable 5) are offered by AWS Bedrock only under data_retention_mode=provider_data_share. These are OFF by default. If an org admin explicitly opts a specific agent into one, that agent's prompts and completions are shared with Anthropic and retained up to 30 days for trust & safety and abuse detection — never for model training. The opt-in is per agent and recorded in the org's audit log; all other agents and models keep the no-provider-access default.

Channel and connector sub-processors

When you connect a channel (Slack, Microsoft Teams, WhatsApp, Outlook, Gmail, etc.) or a knowledge connector (Epic on FHIR, QuickBooks, Salesforce, Confluence, SharePoint, Google Drive, Notion, etc.) to your Zentrr workspace, that third party becomes a sub-processor for the data you send through the connection. Each connection is opt-in by your admin; the active list for your workspace is visible at /connections inside the product. Documents you upload as exports (for example AMS or GL exports) do not create a sub-processor relationship — they are files processed inside Zentrr.

Questions

Contact privacy@zentrr.com for sub-processor questions or to subscribe to change notifications.