Sub-processors
Version: July 18, 2026DPF certification statuses last verified against the U.S. Department of Commerce register (dataprivacyframework.gov): June 11, 2026Introduction
To provide the Blank service, Ambre LLC ("Blank") relies on a limited number of third-party providers ("sub-processors") that may process data on our behalf. In keeping with our commitment to transparency, the full named list is published below, with each provider's function, the location of processing and the safeguards governing data transfers, in accordance with Article 28 GDPR. This list corresponds to Annex 2 of our data processing agreement (DPA).
Sub-processor list
| Sub-processor | Function | Location of processing | Transfer safeguards | Documentation |
|---|---|---|---|---|
| Anthropic | Deliverable generation (AI models) | United States | EU Standard Contractual Clauses (2021/914), incorporated in provider DPA | DPA |
| Amazon Web Services (Bedrock) | Deliverable generation — EU residency flow (Claude via AWS Bedrock) | European Union (Paris, eu-west-3) | Processing within the EU (eu-west-3); US entity — SCCs (2021/914) + DPF in reserve | DPA |
| Mistral AI | Optical character recognition (document analysis) | France (EU) | Processing within the European Union — no transfer outside the EEA. Zero Data Retention enabled on Blank's account: no retention of transmitted data beyond request processing. | DPA |
| Cloudflare | Temporary file storage (EU-located bucket) | European Union | EU Standard Contractual Clauses (2021/914), incorporated in provider DPA | DPA |
| Railway | API and database hosting | United States | SCCs (provider DPA); EU-U.S. DPF + UK Extension + Swiss-U.S. DPF (active) | DPA |
| Vercel | Web frontend hosting | United States (global edge network) | SCCs (provider DPA); EU-U.S. DPF + UK Extension + Swiss-U.S. DPF (active) | DPA |
| Clerk | Authentication and account management | United States | SCCs (provider DPA); EU-U.S. DPF + UK Extension + Swiss-U.S. DPF (active) | DPA |
| Resend | Transactional email delivery | United States | SCCs (provider DPA); EU-U.S. DPF + UK Extension + Swiss-U.S. DPF (active) | DPA |
| Sentry | Frontend and backend error monitoring (technical data only — no document content, no personal data deliberately transmitted) | EU data region (ingestion in the EU); US entity | EU data region; EU-U.S. DPF + SCCs (2021/914) as transfer safeguard | DPA |
The documentation links above point to each provider's publicly available data processing terms and are provided for convenience only; the commitments applicable between Blank and its sub-processors are those of the agreements concluded between them.
Documents transmitted to AI sub-processors (Anthropic or AWS Bedrock depending on data residency, and Mistral AI for OCR) are used solely to fulfil the requested generation. These providers may retain transmitted data temporarily for safety and abuse-detection purposes, in accordance with their contractual commitments, before permanent deletion. They are never authorised to use your data to train or fine-tune models; where a provider offers training opt-out settings, Blank has activated them on its accounts. For Mistral AI (OCR), Blank has additionally activated Zero Data Retention: transmitted data is not retained beyond the processing of the request.
Our commitments
- None of the sub-processors that receive your document content (Anthropic, AWS Bedrock, Mistral AI) is authorised to use it to train or improve artificial intelligence models. Sentry receives only technical error data (no document content, no personal data deliberately transmitted).
- None sells or shares your data for commercial or advertising purposes.
- Blank uses no third-party behavioural analytics or marketing tracking. Technical error monitoring only (Sentry, EU region, no personal data deliberately transmitted), for the sole purpose of service reliability.
- Document content is stored and processed for OCR within the European Union (file storage in an EU-located bucket; OCR in France).
- Each sub-processor is bound by a written data processing agreement imposing data protection obligations at least equivalent to those Blank undertakes towards its clients, and Blank remains liable for their performance.
International transfers
Where data is transferred outside the European Economic Area (in particular to the United States), such transfers are governed by appropriate safeguards under Chapter V of the GDPR: the European Commission Standard Contractual Clauses (Decision 2021/914) incorporated in each provider's data processing agreement and, where the provider holds an active certification, the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, as indicated in the table above.
Sub-processor changes
Before adding or replacing a sub-processor that will process personal data, Blank notifies its clients by email to the registered contact address at least thirty (30) days before the change takes effect. Clients may object on legitimate, documented data protection grounds within ten (10) days of the notice, in accordance with Article 28(2) GDPR and the data processing agreement. The version date at the top of this page is updated on each change, and certification statuses are re-verified periodically.
Contact
For any questions regarding our sub-processors or the processing of your data: [email protected]