Trust Centre

Subprocessors

The third-party services we use to deliver MyntriqOS — with jurisdictions, training postures, and dated retention snapshots.

Read alongside the full document library →

Myntriq Subprocessor List

Last Updated: 28 September 2026

Contact: info@myntriq.io


Overview

Myntriq uses the following third-party service providers (subprocessors) to deliver MyntriqOS. Each subprocessor has been selected based on its security standards, data handling practices, and its ability to support Myntriq's obligations to customers under Singapore's Personal Data Protection Act 2012 (PDPA) and, where applicable, the EU General Data Protection Regulation (GDPR).

This list is the authoritative, versioned register of subprocessors. For every AI model provider it records the jurisdiction where inference is processed, whether the provider may use customer data to train its models, and the provider's retention posture as reviewed on the date shown — provider policies change, and the review date is part of the record. The clause-level evidence behind the AI model entries is maintained in the repository (`docs/trust/MODEL_PROVIDER_DATA_POLICY_REVIEW_2026-09.md`).

This list is maintained as a live page and is updated when subprocessors are added, removed, or change their data handling arrangements. Customers subscribed to the Data Processing Addendum (DPA) will be notified of material changes to this list with at least 14 days' notice before the change takes effect.

A note on geography. MyntriqOS's application compute and primary data store are hosted in Singapore. Model inference is processed by the third-party providers named below, in the jurisdictions disclosed below — which include the United States and, for one transitional route, mainland China. Myntriq does not claim that customer data never leaves any particular country; we claim that every provider that touches it is named here, contractually barred from training on it (with one named transitional exception), and accountable to the retention posture recorded here.


Infrastructure Subprocessors

Google Cloud Platform

FieldDetail
PurposeCloud compute (Cloud Run), secrets management (Secret Manager), container registry (Artifact Registry), and supporting infrastructure
Data categoriesApplication code and container images; encrypted runtime secrets; application logs; system configuration
Processing locationSingapore (`asia-southeast1`)
Parent companyGoogle LLC, United States
DPA availableYes — Google Cloud Data Processing Addendum
Security certificationsISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, SOC 1, SOC 2, SOC 3
NotesPrimary compute and infrastructure provider. Google Cloud does not access customer data except as required to deliver contracted services. Distinct from Google's AI inference service, listed separately below.

Supabase

FieldDetail
PurposeDatabase (PostgreSQL), authentication, file storage, and row-level security enforcement
Data categoriesCustomer organisation data; user accounts and profiles; conversation history; agent configurations; knowledge base metadata; uploaded document references; audit logs; AI usage metrics
Processing locationSingapore (`ap-southeast-1`)
Parent companySupabase Inc., United States
DPA availableYes — available from Supabase on request
Security certificationsSOC 2 Type II
NotesSupabase is the primary data store for MyntriqOS. Row-level security policies enforce strict tenant isolation — one customer's data cannot be accessed by another. Supabase does not use customer data for any purpose other than providing the database service.

AI Model Subprocessors

Every provider in this section processes customer content (prompts, documents, conversation messages, and where noted, audio) to produce model output. Two facts are recorded per provider: whether it may use that content to train its models, and how long it retains it — reviewed 27 September 2026 against each provider's own current terms.

OpenAI

FieldDetail
PurposeAI model inference (`gpt-4o`, `gpt-4o-mini`, `gpt-5.6-terra`) and audio transcription (`whisper-1`)
Data categoriesPrompts and conversation messages; knowledge base query text; audio recordings submitted for transcription (meetings)
Processing locationGlobal (OpenAI does not commit to a processing location on the standard API; storage-only residency in some regions on request)
Parent companyOpenAI OpCo, LLC, United States
DPA availableYes — OpenAI Data Processing Addendum
TrainingNo. Contractual — OpenAI does not use API customer content to develop or improve its models (Services Agreement §4.2, effective 1 January 2026; policy unchanged since 1 March 2023)
Retention (reviewed 27 Sep 2026)Chat endpoints: prompts and completions retained up to 30 days for abuse monitoring, with possible human review. `whisper-1` transcription: no retention. Zero-data-retention arrangements exist but require OpenAI approval.

Anthropic

FieldDetail
PurposeAI model inference (`claude-opus-4-8`, `claude-sonnet-4-6`, `claude-sonnet-5`, `claude-opus-5`, `claude-fable-5`)
Data categoriesPrompts and conversation messages; knowledge base query text
Processing locationUnited States or global (Anthropic offers "global" or US-only inference; no Singapore/Asia-Pacific option exists)
Parent companyAnthropic, PBC, United States
DPA availableYes — Anthropic Data Processing Addendum, incorporated into its Commercial Terms
TrainingNo. Contractual — Anthropic may not train models on customer content from its commercial services (Commercial Terms §B)
Retention (reviewed 27 Sep 2026)Default: inputs/outputs deleted within 30 days. Content flagged by automated trust-and-safety systems may be retained up to 2 years (this carve-out applies even under zero-retention arrangements). `claude-fable-5` is a designated Covered Model: 30-day retention is mandatory on every platform, effective 9 June 2026.

Google (Gemini API)

FieldDetail
PurposeAI model inference (`gemini-3.7-flash`)
Data categoriesPrompts and conversation messages; knowledge base query text
Processing locationGlobal — Google's terms permit processing in any country where Google or its agents maintain facilities; no residency commitment exists on this API
Parent companyGoogle LLC, United States
DPA availableYes — Google Cloud Data Processing Addendum applies to paid-tier API use
TrainingNo, on the paid tier — Google does not use paid-tier API prompts or responses to improve its products. (Google's free tier does use submitted content; Myntriq's access is via a billed Cloud project.)
Retention (reviewed 27 Sep 2026)Prompts and responses logged for up to 55 days for abuse prevention, with possible human review. Zero-data-retention is not offered on this API (Google directs that requirement to its Vertex AI platform).

Alibaba Cloud (DashScope / Model Studio, international)

FieldDetail
PurposeAI model inference (`qwen3.8`, `qwen3.8-instant`) via the international endpoint `dashscope-intl.aliyuncs.com`
Data categoriesPrompts and conversation messages; knowledge base query text
Processing locationSingapore region service operated by Alibaba Cloud's international entity; the provider's terms permit processing in countries where Alibaba Cloud, its affiliates, or subcontractors maintain facilities
Contracting entityAlibaba Cloud (Singapore) Private Limited — Singapore law
DPA availableYes — a Data Processing Addendum is incorporated into the Alibaba Cloud Membership Agreement
TrainingNo. Contractual — Alibaba Cloud does not use customer content to develop or improve Model Studio models unless the customer separately consents (Product Terms §4.48.1(e), v3.8.0, 28 August 2026)
Retention (reviewed 27 Sep 2026)Model Studio states that it stores data generated from model calls; no retention period is published. Zero-data-retention is not offered on public terms.
NotesMyntriq has no arrangement with, and sends no traffic to, Alibaba Cloud's mainland-China platform. A planned migration to self-hosted Qwen models on Myntriq infrastructure will remove this route from the data path (see Changes to This List).

Moonshot AI (Kimi)

FieldDetail
PurposeAI model inference (`kimi-k3`)
Data categoriesPrompts and conversation messages; knowledge base query text
Processing locationMainland China — current route uses the `api.moonshot.cn` platform operated by Beijing Moonshot AI Co., Ltd.
Contracting entityBeijing Moonshot AI Co., Ltd. — PRC law (transition to the Singapore entity in progress, below)
DPA availableNone published
Training — transitional qualifier (27 September 2026)Yes — currently permitted. The platform terms under which this route operates today permit customer content to be used for model improvement, with no opt-out. Myntriq is transitioning this route to Moonshot AI's international platform (Moonshot AI PTE. LTD., Singapore) and a written agreement restricting content use. This qualifier will be removed when that written restriction is in force. While it is in effect, Myntriq limits this route to lower-sensitivity workloads.
Retention (reviewed 27 Sep 2026)No retention schedule is published; the provider's terms require certain records to be retained under Chinese cybersecurity law.

OpenRouter

FieldDetail
PurposeAI model inference routing for `qwen3.7-plus`, `glm-5.2` (Zhipu), and `llama3.3` / `llama3.2` (Meta)
Data categoriesPrompts and conversation messages; knowledge base query text
Processing locationUnited States (Google Cloud); no Singapore routing option exists
Parent companyOpenRouter Inc., United States
DPA availableYes — OpenRouter Data Processing Agreement (26 August 2026)
TrainingNo, by OpenRouter — OpenRouter does not use inputs or outputs for model training. Downstream model providers are selected with training-permitted providers excluded and zero-retention endpoints preferred; the effective provider chain is disclosed in the Model Governance Policy.
Retention (reviewed 27 Sep 2026)Prompts and completions are not stored by default; request metadata (token counts, latency, model, cost) is retained.

First-party inference (not a subprocessor)

Myntriq's embedding model (`bge-m3`) runs on Myntriq's own infrastructure inside its own Google Cloud project. No customer data leaves Myntriq's environment for embedding workloads, and no third party processes it. Self-hosted Qwen inference is planned on the same pattern; when it enters service, the corresponding hosted route (Alibaba Cloud, above) will be removed from this list.


Communication Subprocessors

Resend

FieldDetail
PurposeTransactional email delivery (contact form notifications, demo request notifications)
Data categoriesName, email address, company name, and message content submitted through contact and demo request forms on the Myntriq website
Processing locationUnited States
Parent companyResend Inc., United States
DPA availableContact Resend directly for DPA terms
NotesResend is used solely for delivering form submission notifications to Myntriq's internal team. Form data is not stored by Resend beyond standard email delivery logs.

Meta (WhatsApp Cloud API)

FieldDetail
PurposeWhatsApp Business messaging channel — live in production for agent communication
Data categoriesMessage content and sender/recipient identifiers (phone numbers, display names) passed through the WhatsApp channel
Processing locationUnited States and Meta's global infrastructure, per Meta's data terms
Parent companyMeta Platforms, Inc., United States
DPA availableMeta's Data Processing Terms apply to WhatsApp Business Platform use
NotesActive since the WhatsApp Cloud channel launched. Message content transits Meta's platform as the channel operator; Myntriq does not use Twilio or Infobip for WhatsApp.

Changes to This List

Myntriq will update this page when subprocessors are added, removed, or materially change their data handling arrangements.

Customers operating under a signed Data Processing Addendum are entitled to object to the addition of a new subprocessor within 14 days of notice. If a customer objects and Myntriq cannot reasonably accommodate the objection, the customer may terminate the affected services.

Known upcoming changes, recorded here as they complete:

  • Moonshot AI route transition — move from `api.moonshot.cn` to Moonshot AI's international (Singapore-entity) platform with a written restriction on content use; the transitional qualifier above is removed when that restriction is in force.
  • Self-hosted Qwen — Qwen inference moves onto Myntriq's own infrastructure; the hosted Alibaba Cloud route is then removed from this list, after which Qwen workloads leave Myntriq's environment for no third party.

To be notified of changes to this list, or to request a copy of a subprocessor's DPA, contact info@myntriq.io.