Cedreon Sub-processors
This page is Annex 2 to the Cedreon Data Processing Agreement and forms part of it. It lists the sub-processors Cedreon engages under clause 7 of that DPA, in the sense of Article 28(2) and (4) GDPR and Article 9 of the Swiss Federal Act on Data Protection.
It is written from the deployment as it is actually configured. Where a third party is engaged only when a customer switches an optional feature on, this page says so rather than listing it as though every account used it.
Cedreon is operated by SFF S26 AG, St. Gallen, Switzerland.
How to read this page
A sub-processor is a third party that processes Customer Content, meaning the messages, documents and files you submit, on Cedreon's behalf and on your instructions. Those are in section 1, and they are what Annex 2 to the DPA consists of.
A processor for data where Cedreon is its own controller, such as your billing contact or your login address, is not a sub-processor under the DPA. Clause 2 of the DPA puts that processing in the Privacy Policy instead. Section 2 lists those anyway, because you are entitled to know who touches your data and a list that hides behind a definition is not a disclosure.
Engaging a third party for ancillary services that involve no access to Customer Content, such as telecommunications, connectivity or office facilities, is not the engagement of a sub-processor. See DPA clause 7.
1. Sub-processors of Customer Content
1.1 Model routing
Eden AI (France)
- What it does: the single gateway through which every model request is made. Cedreon calls its European endpoint, which routes only to providers cleared for processing in Europe and rejects a request that no such provider can serve, rather than forwarding it elsewhere. Cedreon additionally pins each request to the one Model Provider named below for the model chosen, with provider fallback disabled.
- What it receives: the screened prompt. Recognised sensitive values have already been replaced with placeholders before the request leaves Cedreon, so what the gateway forwards carries placeholders in their place. It also receives the model identifier and token counts.
- Processing location: European Union.
- Transfer mechanism: none required for the EU. Transfers from Switzerland to the EEA rest on the Federal Council's adequacy recognition of the EEA.
- Retention: the gateway states that it does not store prompt or completion content, and logs metadata only. That is a statement about the gateway. What each Model Provider retains is a separate question, addressed in section 1.2.
- Use: neither the gateway nor any Model Provider may train on Customer Content or use it for its own purposes. This obligation is contractual, in Cedreon's agreement with the gateway and in the gateway's own agreements with the Model Providers.
1.2 Model Providers
These are engaged through Eden AI. Which one serves a given request depends on the model chosen for it, and on any Compliance Profile in force for the account. Every one of them is established in Europe and processes there, and each request is pinned to the single provider for its model with fallback disabled: the request is served by the company named here, or it fails.
The maker of a model and the processor that serves it are different companies, and this page names the second. For an open-weight model the two are routinely unrelated; naming the maker as the processor would name a company that never receives the request.
- Mistral rows: served by Mistral AI SAS (France), in the European Union. Maker: Mistral AI.
- Claude rows: served by Amazon Web Services EMEA SARL (Luxembourg) via Amazon Bedrock, in eu-west-1, Ireland. Maker: Anthropic.
- GPT rows: served by Microsoft Ireland Operations Limited via the Azure OpenAI Service, in the EU Data Zone. Maker: OpenAI.
- Gemini rows: served by Google Cloud EMEA Limited (Ireland), in the European Union. Maker: Google.
- Qwen rows: served by Alibaba Cloud, in the European Union. Maker: Alibaba Group.
- Kimi rows: served by Nebius B.V. (Netherlands), in the European Union. Maker: Moonshot AI.
- Transfer mechanism: none required. Every processor above is established in the EU or EEA and serves the request there. Transfers from Switzerland rest on the Federal Council's adequacy recognition of the EEA.
- Retention: each processor operates its own retention and abuse-monitoring regime, and Cedreon does not make a single platform-wide retention statement covering all of them. No model row is presented as zero-retention.
- A European processing region is not a European maker. Most of the models above were built outside Europe. An organisation that requires the model to have been built by a European company as well as run by one can use the EU-only Compliance Profile, which restricts the account to the Mistral rows.
The current mapping of model rows to providers is shown in the model menu inside the product, on every account, before a model is chosen.
1.3 Engaged only when you switch a feature on
Both of the following are off by default, are latched per conversation, and are re-resolved on the server, so a modified client cannot enable them for itself.
Linkup (France)
- What it does: web search, used only in a conversation where web search has been explicitly switched on.
- What it receives: the search query as you typed it. This is deliberate and it is disclosed on the toggle itself. Masking the query does not degrade a search, it changes it: a question about a named company, sent with the name replaced, returns results about something else, and the model is then handed those results as though they answered you. Switching web search on is therefore the disclosure, and the feature is off until you do.
- What it does not receive: your documents, your conversation history, and any part of a message other than the question being searched.
- Processing location: European routing, not yet contractually pinned. Linkup is a French company and Cedreon's search requests are routed to its European serving. A contractual commitment pinning the serving region to Europe is being put in place; until it is signed, this entry states the operational position and claims no pin. A vendor's country of establishment is not the location of processing, and this page does not treat it as one.
- Transfer mechanism: Standard Contractual Clauses (Implementing Decision (EU) 2021/914) with the Swiss addendum recognised by the FDPIC, for any processing outside the EEA.
- Withheld entirely from organisations under the EU-only Compliance Profile, and under both professional-secrecy profiles, because the processing region is not pinned.
Google LLC (United States), for connected Drive and Gmail sources
- What it does: read-only search of a Google account that the account holder has explicitly connected through Google's own consent screen.
- What it receives: a search query derived from your question, destructively masked before it is sent. Google is already the custodian of the files being searched.
- Processing location: Google's infrastructure.
- Transfer mechanism: Google's data processing terms incorporating Standard Contractual Clauses.
- Withheld from organisations under the EU-only Compliance Profile for the in-chat search path.
1.4 Infrastructure
Amazon Web Services EMEA SARL (Luxembourg), operating AWS Lightsail
- What it does: hosts the application and its database.
- What it receives: everything the service stores, in the form in which it is stored.
- Processing location: eu-central-1, Frankfurt, Germany. Daily automatic instance snapshots are taken and held in the same region.
- Transfer mechanism: none required. The contracting entity is European and the region is European.
- Note on what a snapshot contains: stored message copies, the placeholder mapping and stored integration credentials are encrypted by Cedreon before they reach the disk. A volume or snapshot on its own decrypts nothing, because the encryption key is not held on the data volume.
Cloudflare, Inc. (United States), contracting through Cloudflare Germany GmbH for EEA customers
- What it does: authoritative DNS, TLS termination at the edge, DDoS protection, and the outbound-only tunnel that carries requests to the application. Nothing listens publicly on the server itself.
- What it receives: inbound requests transit Cloudflare's edge, where TLS is terminated. Request content is therefore processed in the clear at the edge, transiently and in memory, before being re-encrypted to the origin. We state this plainly because it is true of every service behind a reverse proxy and is usually left unsaid.
- Processing location: Cloudflare's global network. Requests from Europe are ordinarily served by European points of presence.
- Transfer mechanism: Cloudflare's data processing addendum incorporating Standard Contractual Clauses.
2. Processors for data where Cedreon is the controller
These are not sub-processors under the DPA. They do not receive Customer Content. They are listed for completeness.
Stripe Payments Europe, Ltd. (Ireland)
- What it does: subscription billing, checkout and the customer billing portal.
- What it receives: the billing contact, the subscription record, and payment details entered directly into Stripe's own hosted forms. Card details never reach Cedreon's servers.
- Processing location: European Union, with onward transfer to Stripe, Inc. under Standard Contractual Clauses.
Transactional email relay
- What it does: delivers account email, meaning address-verification links, seat invitations and replies to contact enquiries.
- What it receives: the recipient address and the message Cedreon sends. It never receives Customer Content.
Umami, self-hosted
- What it does: website analytics, on the public marketing pages only.
- Where it runs: on Cedreon's own infrastructure, in the same Frankfurt region, in a container we operate. No third party receives it.
- Where it does not run: it is never loaded inside the signed-in workspace. The console makes no third-party requests at all.
3. Not sub-processors
These run inside Cedreon and send nothing outward. They are listed because customers ask, and because "no third party is involved" is a stronger statement than silence.
- Sensitive-value recognition. The recognition model runs locally, on our own infrastructure, as part of the application process. No content is sent anywhere to be screened.
- Document text extraction. Word, PDF and spreadsheet text is extracted in-process.
- Optical character recognition for scanned documents runs locally as a subprocess at ingest time.
- Search indexing and embeddings for the document library are computed locally, over the already-pseudonymised copy.
- PDF generation is rendered in-process and offline.
- GitHub, Inc. holds the source code repository and runs the deployment pipeline. It holds no Customer Content and has no access to the production database.
4. Changes to this list
A change is published here at least 30 days before it takes effect, and the account contact of each organisation is notified.
If you reasonably object on data-protection grounds within that period, we will work with you in good faith to find a solution. If none is found, you may terminate the affected part of the service without penalty and receive a pro-rata refund for the unused remainder of the paid period. This mirrors DPA clause 7, which is the operative text.
Where we engage a sub-processor, we impose on it data protection obligations equivalent to those in the DPA, by contract or another legally binding instrument. Cedreon remains fully liable to you for a sub-processor's performance of those obligations.
Questions about anything on this page: [email protected].
Version 1.2, in force from 2026-08-28