Myntriq Subprocessor List
Last Updated: 28 September 2026
Contact: info@myntriq.io
Overview
Myntriq uses the following third-party service providers (subprocessors) to deliver MyntriqOS. Each subprocessor has been selected based on its security standards, data handling practices, and its ability to support Myntriq's obligations to customers under Singapore's Personal Data Protection Act 2012 (PDPA) and, where applicable, the EU General Data Protection Regulation (GDPR).
This list is the authoritative, versioned register of subprocessors. For every AI model provider it records the jurisdiction where inference is processed, whether the provider may use customer data to train its models, and the provider's retention posture as reviewed on the date shown — provider policies change, and the review date is part of the record. The clause-level evidence behind the AI model entries is maintained in the repository (`docs/trust/MODEL_PROVIDER_DATA_POLICY_REVIEW_2026-09.md`).
This list is maintained as a live page and is updated when subprocessors are added, removed, or change their data handling arrangements. Customers subscribed to the Data Processing Addendum (DPA) will be notified of material changes to this list with at least 14 days' notice before the change takes effect.
A note on geography. MyntriqOS's application compute and primary data store are hosted in Singapore. Model inference is processed by the third-party providers named below, in the jurisdictions disclosed below — which include the United States and, for one transitional route, mainland China. Myntriq does not claim that customer data never leaves any particular country; we claim that every provider that touches it is named here, contractually barred from training on it (with one named transitional exception), and accountable to the retention posture recorded here.
Infrastructure Subprocessors
Google Cloud Platform
| Field | Detail |
|---|---|
| Purpose | Cloud compute (Cloud Run), secrets management (Secret Manager), container registry (Artifact Registry), and supporting infrastructure |
| Data categories | Application code and container images; encrypted runtime secrets; application logs; system configuration |
| Processing location | Singapore (`asia-southeast1`) |
| Parent company | Google LLC, United States |
| DPA available | Yes — Google Cloud Data Processing Addendum |
| Security certifications | ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, SOC 1, SOC 2, SOC 3 |
| Notes | Primary compute and infrastructure provider. Google Cloud does not access customer data except as required to deliver contracted services. Distinct from Google's AI inference service, listed separately below. |
Supabase
| Field | Detail |
|---|---|
| Purpose | Database (PostgreSQL), authentication, file storage, and row-level security enforcement |
| Data categories | Customer organisation data; user accounts and profiles; conversation history; agent configurations; knowledge base metadata; uploaded document references; audit logs; AI usage metrics |
| Processing location | Singapore (`ap-southeast-1`) |
| Parent company | Supabase Inc., United States |
| DPA available | Yes — available from Supabase on request |
| Security certifications | SOC 2 Type II |
| Notes | Supabase is the primary data store for MyntriqOS. Row-level security policies enforce strict tenant isolation — one customer's data cannot be accessed by another. Supabase does not use customer data for any purpose other than providing the database service. |
AI Model Subprocessors
Every provider in this section processes customer content (prompts, documents, conversation messages, and where noted, audio) to produce model output. Two facts are recorded per provider: whether it may use that content to train its models, and how long it retains it — reviewed 27 September 2026 against each provider's own current terms.
OpenAI
| Field | Detail |
|---|---|
| Purpose | AI model inference (`gpt-4o`, `gpt-4o-mini`, `gpt-5.6-terra`) and audio transcription (`whisper-1`) |
| Data categories | Prompts and conversation messages; knowledge base query text; audio recordings submitted for transcription (meetings) |
| Processing location | Global (OpenAI does not commit to a processing location on the standard API; storage-only residency in some regions on request) |
| Parent company | OpenAI OpCo, LLC, United States |
| DPA available | Yes — OpenAI Data Processing Addendum |
| Training | No. Contractual — OpenAI does not use API customer content to develop or improve its models (Services Agreement §4.2, effective 1 January 2026; policy unchanged since 1 March 2023) |
| Retention (reviewed 27 Sep 2026) | Chat endpoints: prompts and completions retained up to 30 days for abuse monitoring, with possible human review. `whisper-1` transcription: no retention. Zero-data-retention arrangements exist but require OpenAI approval. |
Anthropic
| Field | Detail |
|---|---|
| Purpose | AI model inference (`claude-opus-4-8`, `claude-sonnet-4-6`, `claude-sonnet-5`, `claude-opus-5`, `claude-fable-5`) |
| Data categories | Prompts and conversation messages; knowledge base query text |
| Processing location | United States or global (Anthropic offers "global" or US-only inference; no Singapore/Asia-Pacific option exists) |
| Parent company | Anthropic, PBC, United States |
| DPA available | Yes — Anthropic Data Processing Addendum, incorporated into its Commercial Terms |
| Training | No. Contractual — Anthropic may not train models on customer content from its commercial services (Commercial Terms §B) |
| Retention (reviewed 27 Sep 2026) | Default: inputs/outputs deleted within 30 days. Content flagged by automated trust-and-safety systems may be retained up to 2 years (this carve-out applies even under zero-retention arrangements). `claude-fable-5` is a designated Covered Model: 30-day retention is mandatory on every platform, effective 9 June 2026. |
Google (Gemini API)
| Field | Detail |
|---|---|
| Purpose | AI model inference (`gemini-3.7-flash`) |
| Data categories | Prompts and conversation messages; knowledge base query text |
| Processing location | Global — Google's terms permit processing in any country where Google or its agents maintain facilities; no residency commitment exists on this API |
| Parent company | Google LLC, United States |
| DPA available | Yes — Google Cloud Data Processing Addendum applies to paid-tier API use |
| Training | No, on the paid tier — Google does not use paid-tier API prompts or responses to improve its products. (Google's free tier does use submitted content; Myntriq's access is via a billed Cloud project.) |
| Retention (reviewed 27 Sep 2026) | Prompts and responses logged for up to 55 days for abuse prevention, with possible human review. Zero-data-retention is not offered on this API (Google directs that requirement to its Vertex AI platform). |
Alibaba Cloud (DashScope / Model Studio, international)
| Field | Detail |
|---|---|
| Purpose | AI model inference (`qwen3.8`, `qwen3.8-instant`) via the international endpoint `dashscope-intl.aliyuncs.com` |
| Data categories | Prompts and conversation messages; knowledge base query text |
| Processing location | Singapore region service operated by Alibaba Cloud's international entity; the provider's terms permit processing in countries where Alibaba Cloud, its affiliates, or subcontractors maintain facilities |
| Contracting entity | Alibaba Cloud (Singapore) Private Limited — Singapore law |
| DPA available | Yes — a Data Processing Addendum is incorporated into the Alibaba Cloud Membership Agreement |
| Training | No. Contractual — Alibaba Cloud does not use customer content to develop or improve Model Studio models unless the customer separately consents (Product Terms §4.48.1(e), v3.8.0, 28 August 2026) |
| Retention (reviewed 27 Sep 2026) | Model Studio states that it stores data generated from model calls; no retention period is published. Zero-data-retention is not offered on public terms. |
| Notes | Myntriq has no arrangement with, and sends no traffic to, Alibaba Cloud's mainland-China platform. A planned migration to self-hosted Qwen models on Myntriq infrastructure will remove this route from the data path (see Changes to This List). |
Moonshot AI (Kimi)
| Field | Detail |
|---|---|
| Purpose | AI model inference (`kimi-k3`) |
| Data categories | Prompts and conversation messages; knowledge base query text |
| Processing location | Mainland China — current route uses the `api.moonshot.cn` platform operated by Beijing Moonshot AI Co., Ltd. |
| Contracting entity | Beijing Moonshot AI Co., Ltd. — PRC law (transition to the Singapore entity in progress, below) |
| DPA available | None published |
| Training — transitional qualifier (27 September 2026) | Yes — currently permitted. The platform terms under which this route operates today permit customer content to be used for model improvement, with no opt-out. Myntriq is transitioning this route to Moonshot AI's international platform (Moonshot AI PTE. LTD., Singapore) and a written agreement restricting content use. This qualifier will be removed when that written restriction is in force. While it is in effect, Myntriq limits this route to lower-sensitivity workloads. |
| Retention (reviewed 27 Sep 2026) | No retention schedule is published; the provider's terms require certain records to be retained under Chinese cybersecurity law. |
OpenRouter
| Field | Detail |
|---|---|
| Purpose | AI model inference routing for `qwen3.7-plus`, `glm-5.2` (Zhipu), and `llama3.3` / `llama3.2` (Meta) |
| Data categories | Prompts and conversation messages; knowledge base query text |
| Processing location | United States (Google Cloud); no Singapore routing option exists |
| Parent company | OpenRouter Inc., United States |
| DPA available | Yes — OpenRouter Data Processing Agreement (26 August 2026) |
| Training | No, by OpenRouter — OpenRouter does not use inputs or outputs for model training. Downstream model providers are selected with training-permitted providers excluded and zero-retention endpoints preferred; the effective provider chain is disclosed in the Model Governance Policy. |
| Retention (reviewed 27 Sep 2026) | Prompts and completions are not stored by default; request metadata (token counts, latency, model, cost) is retained. |
First-party inference (not a subprocessor)
Myntriq's embedding model (`bge-m3`) runs on Myntriq's own infrastructure inside its own Google Cloud project. No customer data leaves Myntriq's environment for embedding workloads, and no third party processes it. Self-hosted Qwen inference is planned on the same pattern; when it enters service, the corresponding hosted route (Alibaba Cloud, above) will be removed from this list.
Communication Subprocessors
Resend
| Field | Detail |
|---|---|
| Purpose | Transactional email delivery (contact form notifications, demo request notifications) |
| Data categories | Name, email address, company name, and message content submitted through contact and demo request forms on the Myntriq website |
| Processing location | United States |
| Parent company | Resend Inc., United States |
| DPA available | Contact Resend directly for DPA terms |
| Notes | Resend is used solely for delivering form submission notifications to Myntriq's internal team. Form data is not stored by Resend beyond standard email delivery logs. |
Meta (WhatsApp Cloud API)
| Field | Detail |
|---|---|
| Purpose | WhatsApp Business messaging channel — live in production for agent communication |
| Data categories | Message content and sender/recipient identifiers (phone numbers, display names) passed through the WhatsApp channel |
| Processing location | United States and Meta's global infrastructure, per Meta's data terms |
| Parent company | Meta Platforms, Inc., United States |
| DPA available | Meta's Data Processing Terms apply to WhatsApp Business Platform use |
| Notes | Active since the WhatsApp Cloud channel launched. Message content transits Meta's platform as the channel operator; Myntriq does not use Twilio or Infobip for WhatsApp. |
Changes to This List
Myntriq will update this page when subprocessors are added, removed, or materially change their data handling arrangements.
Customers operating under a signed Data Processing Addendum are entitled to object to the addition of a new subprocessor within 14 days of notice. If a customer objects and Myntriq cannot reasonably accommodate the objection, the customer may terminate the affected services.
Known upcoming changes, recorded here as they complete:
- Moonshot AI route transition — move from `api.moonshot.cn` to Moonshot AI's international (Singapore-entity) platform with a written restriction on content use; the transitional qualifier above is removed when that restriction is in force.
- Self-hosted Qwen — Qwen inference moves onto Myntriq's own infrastructure; the hosted Alibaba Cloud route is then removed from this list, after which Qwen workloads leave Myntriq's environment for no third party.
To be notified of changes to this list, or to request a copy of a subprocessor's DPA, contact info@myntriq.io.