Sub-processors
Parties that process Personal Data on Kuration AI's behalf. Published per GDPR Article 28(4) and referenced in the Data Processing Agreement.
Last updated 17 April 2026
Last Updated: 17 April 2026
Kuration AI engages a small number of carefully selected sub-processors to help deliver the Services. Each sub-processor is bound by written data protection obligations equivalent to those in our Data Processing Agreement, and we review them on onboarding and on an ongoing basis. In case of conflict between this page and Annex III of the DPA, this page controls.
If you are an enterprise customer with a general authorisation to engage sub-processors and want to receive notice of changes in advance, email privacy@kuration.ai and we will add you to the notification list. See DPA §10 for the change-notice mechanism (minimum 30 days).
Current sub-processors
| Sub-processor | Purpose | Primary location |
|---|---|---|
| Supabase | Database hosting, authentication, real-time data | Customer region (EU, US, or APAC as provisioned) |
| Vercel | Frontend and edge-function hosting | Global edge network |
| Koyeb | Application hosting and compute | Europe |
| Clerk | User authentication and session management | United States |
| Stripe | Payment processing | United States |
| Loops.so | Transactional and marketing email delivery | United States |
| OpenAI | LLM inference for research automation and enrichment | United States |
| Anthropic | LLM inference for research automation and enrichment | United States |
| Mistral AI | LLM inference for research automation and enrichment | European Union |
| Brainsfeed | Human research and data verification network | Various (global network, under individual confidentiality agreements) |
| Third-party enrichment APIs | Data enrichment as needed per workflow | Varies — disclosed on request for enterprise customers |
Notes
- LLM providers. Customer-submitted data is only sent to an LLM provider when the Customer's workflow explicitly requires it (for example, a free-text enrichment or summarisation step). Where available, zero-data-retention API modes are used.
- Sub-processors vs. operational vendors. The list above covers parties that process Personal Data on our behalf. Vendors that do not process Personal Data (for example, analytics processors used on the marketing site only, error-tracking tools that receive redacted payloads) are not listed here but are documented internally and available on request for enterprise due diligence.
- Brainsfeed. Our proprietary human research network is operated by Kuration AI. Individual researchers are engaged under confidentiality agreements and data-handling protocols. They do not receive Client-Submitted Data and only contribute to the compilation of Kuration AI Platform Data.
Change notification
Material changes to the sub-processor list (new sub-processor categories, material change in processing location) are announced by email to the notification list. Minor changes (replacement of a transactional email provider with one offering equivalent protections, for example) are reflected on this page and in the DPA Annex III at the next revision.
Contact
For questions about this list, due-diligence requests, or to be added to the change-notice list, please contact:
- Privacy and data protection: privacy@kuration.ai
- Security incidents: security@kuration.ai
- Legal and contracts: legal@kuration.ai