Security & ComplianceSubprocessors
Third-party subprocessors used by Perceive8 and the data categories they process.
Subprocessors
Version: 1.0
Last Updated: 2026-03-07
Owner: Privacy & Compliance Team
Classification: Internal — Confidential
Related Docs: Data inventory · Data retention · Consent model · Privacy requests
1. Overview
This document lists all third-party subprocessors that process customer data on behalf of Perceive8. Under GDPR Art. 28, data processors must maintain a current list of subprocessors and notify data controllers (customers) of any changes.
Definitions
| Term |
Definition |
| Data Controller |
The Perceive8 customer who uploads audio and determines the purpose of processing |
| Data Processor |
Perceive8, which processes data on behalf of the customer |
| Subprocessor |
A third-party service engaged by Perceive8 to process customer data |
| DPA |
Data Processing Agreement / Addendum |
| SCC |
Standard Contractual Clauses (for international data transfers) |
Change Notification Policy
Perceive8 will notify customers at least 30 days before adding or changing a subprocessor. Customers may object to a new subprocessor within this period.
⚠️ Status: Change notification mechanism is not yet implemented. This is a planned feature.
2. Subprocessor Registry
2.1 AI Processing Providers
OpenAI
| Attribute |
Details |
| Provider |
OpenAI, L.L.C. |
| Purpose |
Speech-to-text transcription (Whisper API), text embeddings, AI chat/RAG query processing |
| Data Shared |
Raw audio files (Whisper), transcript text (embeddings), user chat messages + transcript context (chat/RAG) |
| Data Classification |
L4 — Restricted (audio), L3 — Confidential (text) |
| Processing Location |
United States |
| Data Retention by Provider |
API data: 30 days by default; 0 days with zero-retention opt-out (available for API customers) |
| DPA Status |
❌ Pending — DPA available but not yet executed |
| DPA URL |
https://openai.com/policies/data-processing-addendum |
| Privacy Policy |
https://openai.com/policies/privacy-policy |
| API Data Usage Policy |
https://openai.com/policies/api-data-usage-policies |
| SOC 2 |
✅ Type II |
| Zero-Retention Available |
✅ Yes (must be enabled via API settings) |
| SCC Required |
Yes (for EU data subjects) |
| Notes |
OpenAI does not use API data for model training (as of March 2023). Zero-retention should be enabled for all production use. |
Action Items:
Pyannote.ai
| Attribute |
Details |
| Provider |
Pyannote.ai (operated by CNRS / Hervé Bredin) |
| Purpose |
Speaker diarization, voiceprint analysis, speaker identification |
| Data Shared |
Raw audio files for speaker segmentation and voice embedding extraction |
| Data Classification |
L4 — Restricted (audio + biometric voiceprints) |
| Processing Location |
European Union (France) |
| Data Retention by Provider |
Unknown — must verify with provider |
| DPA Status |
❌ Pending — DPA not yet requested |
| DPA URL |
Not publicly available — must request directly |
| Privacy Policy |
https://www.pyannote.ai/privacy |
| SOC 2 |
❌ Unknown |
| SCC Required |
No (EU-based, if deployment is also EU) |
| Notes |
Pyannote processes biometric data (voiceprints). Enhanced DPA terms required for GDPR Art. 9 data. Must verify their data retention and deletion capabilities. |
Action Items:
Replicate
| Attribute |
Details |
| Provider |
Replicate, Inc. |
| Purpose |
Speaker diarization, transcription (alternative/supplementary provider) |
| Data Shared |
Raw audio files |
| Data Classification |
L4 — Restricted (audio) |
| Processing Location |
United States |
| Data Retention by Provider |
Transient — data deleted after model inference completes (per Replicate docs) |
| DPA Status |
❌ Pending — DPA not yet executed |
| DPA URL |
https://replicate.com/docs/data-processing-addendum |
| Privacy Policy |
https://replicate.com/privacy |
| Terms of Service |
https://replicate.com/terms |
| SOC 2 |
✅ Type II |
| SCC Required |
Yes (for EU data subjects) |
| Notes |
Replicate runs models on ephemeral infrastructure. Input data is typically deleted after prediction completes. Verify this applies to all models used. |
Action Items:
Hume AI
| Attribute |
Details |
| Provider |
Hume AI, Inc. |
| Purpose |
Emotion analysis, prosody analysis, vocal burst detection |
| Data Shared |
Raw audio files for emotional and prosodic analysis |
| Data Classification |
L4 — Restricted (audio + emotional state data) |
| Processing Location |
United States |
| Data Retention by Provider |
Unknown — must verify with provider |
| DPA Status |
❌ Pending — DPA not yet requested |
| DPA URL |
Not publicly available — must request directly |
| Privacy Policy |
https://www.hume.ai/privacy-policy |
| SOC 2 |
❌ Unknown |
| SCC Required |
Yes (for EU data subjects) |
| Notes |
Hume AI processes sensitive emotional data. Their Ethical AI guidelines should be reviewed. Emotion analysis may constitute profiling under GDPR Art. 22. Must verify data handling practices. |
Action Items:
AssemblyAI
| Attribute |
Details |
| Provider |
AssemblyAI, Inc. |
| Purpose |
Sentiment analysis, named entity recognition, topic detection, content moderation |
| Data Shared |
Raw audio files for multi-modal content intelligence |
| Data Classification |
L4 — Restricted (audio), L3 — Confidential (derived analysis) |
| Processing Location |
United States |
| Data Retention by Provider |
Audio deleted after processing by default; transcripts available for retrieval |
| DPA Status |
❌ Pending — DPA available but not yet executed |
| DPA URL |
https://www.assemblyai.com/legal/dpa |
| Privacy Policy |
https://www.assemblyai.com/legal/privacy-policy |
| Security |
https://www.assemblyai.com/security |
| SOC 2 |
✅ Type II |
| SCC Required |
Yes (for EU data subjects) |
| Notes |
AssemblyAI offers data deletion API. Should enable redact_pii feature for sensitive recordings. Verify that content moderation results don't include raw audio retention. |
Action Items:
2.2 Infrastructure Providers
Supabase
| Attribute |
Details |
| Provider |
Supabase, Inc. |
| Purpose |
PostgreSQL database hosting, user authentication (Supabase Auth), real-time subscriptions |
| Data Shared |
All application data stored in PostgreSQL — user records, analyses, transcripts, billing references, audit logs, etc. |
| Data Classification |
L2–L4 (varies by table — see Data Inventory) |
| Processing Location |
United States (default region) — configurable per project |
| Data Retention by Provider |
Duration of service agreement; data deleted on project termination |
| DPA Status |
⚠️ Review Needed — Supabase includes DPA in standard terms |
| DPA URL |
https://supabase.com/legal/dpa |
| Privacy Policy |
https://supabase.com/privacy |
| Security |
https://supabase.com/security |
| SOC 2 |
✅ Type II |
| HIPAA |
✅ Available (enterprise plan) |
| SCC Required |
Yes (for EU data subjects, unless EU region selected) |
| Notes |
Supabase is the primary data store. All PII passes through Supabase. Consider EU region deployment for EU customers. Review standard DPA terms for adequacy. |
Action Items:
MinIO / S3-Compatible Storage
| Attribute |
Details |
| Provider |
MinIO, Inc. (self-hosted) or cloud S3-compatible provider |
| Purpose |
Object storage for audio files (raw and enhanced) |
| Data Shared |
Audio files (raw uploads and enhanced versions) |
| Data Classification |
L4 — Restricted (audio recordings) |
| Processing Location |
Self-hosted (same region as application deployment) |
| Data Retention by Provider |
N/A — self-managed; data persists until explicitly deleted |
| DPA Status |
✅ N/A — self-hosted infrastructure |
| Privacy Policy |
https://min.io/privacy |
| Notes |
When self-hosted, MinIO does not process data as a third party. If using a managed S3 service (AWS S3, etc.), that provider becomes a subprocessor and requires a DPA. |
Action Items:
Railway (Application Hosting)
| Attribute |
Details |
| Provider |
Railway Corp. |
| Purpose |
Application hosting, container orchestration |
| Data Shared |
Application runtime data, environment variables (API keys, database credentials), application logs |
| Data Classification |
L3 — Confidential (credentials in env vars), L2 — Internal (logs) |
| Processing Location |
United States |
| Data Retention by Provider |
Logs retained per Railway's retention policy; application data transient |
| DPA Status |
⚠️ Review Needed — check Railway's standard terms |
| DPA URL |
https://railway.app/legal/dpa |
| Privacy Policy |
https://railway.app/legal/privacy |
| SOC 2 |
⚠️ Unknown — verify |
| SCC Required |
Yes (for EU data subjects) |
| Notes |
Railway hosts the application containers. While it doesn't directly process customer audio/transcripts, it has access to the runtime environment including database credentials and API keys. Log data may contain PII if not properly filtered. |
Action Items:
2.3 Payment Processing
Stripe
| Attribute |
Details |
| Provider |
Stripe, Inc. |
| Purpose |
Payment processing, subscription management, billing |
| Data Shared |
Customer email, subscription plan, payment amounts, Stripe customer/subscription IDs |
| Data Classification |
L3 — Confidential (billing data), L4 — Restricted (payment card data — handled by Stripe only) |
| Processing Location |
United States, European Union (Stripe has global infrastructure) |
| Data Retention by Provider |
Per Stripe's retention policy; financial records retained for legal/regulatory compliance |
| DPA Status |
✅ Standard — Stripe DPA included in standard service agreement |
| DPA URL |
https://stripe.com/legal/dpa |
| Privacy Policy |
https://stripe.com/privacy |
| Security |
https://stripe.com/docs/security |
| PCI DSS |
✅ Level 1 Service Provider |
| SOC 2 |
✅ Type II |
| SCC Required |
Included in Stripe DPA |
| Notes |
No payment card data (PAN, CVV) is stored in Perceive8 systems. All payment processing is handled by Stripe. Only Stripe reference IDs are stored locally. |
Action Items:
3. Summary Table
| Provider |
Purpose |
Data Shared |
Location |
DPA Status |
Privacy Policy |
| OpenAI |
Transcription, embeddings, chat/RAG |
Audio, text, chat messages |
US |
❌ Pending |
Link |
| Pyannote.ai |
Speaker diarization, voiceprints |
Audio |
EU (France) |
❌ Pending |
Link |
| Replicate |
Diarization, transcription |
Audio |
US |
❌ Pending |
Link |
| Hume AI |
Emotion/prosody analysis |
Audio |
US |
❌ Pending |
Link |
| AssemblyAI |
Sentiment, entities, topics, moderation |
Audio |
US |
❌ Pending |
Link |
| Stripe |
Payment processing |
Billing data |
US/EU |
✅ Standard |
Link |
| Supabase |
Database, authentication |
All DB records |
US (configurable) |
⚠️ Review |
Link |
| Railway |
Application hosting |
Runtime/logs |
US |
⚠️ Review |
Link |
| MinIO |
Object storage (self-hosted) |
Audio files |
Self-hosted |
✅ N/A |
Link |
4. DPA Execution Tracker
| Provider |
DPA Available |
DPA Executed |
SCC Included |
Zero-Retention |
Owner |
Target Date |
| OpenAI |
✅ Yes |
❌ No |
❌ No |
✅ Available |
Engineering |
TBD |
| Pyannote.ai |
❌ Unknown |
❌ No |
N/A (EU) |
❌ Unknown |
Engineering |
TBD |
| Replicate |
✅ Yes |
❌ No |
❌ No |
✅ Default (ephemeral) |
Engineering |
TBD |
| Hume AI |
❌ Unknown |
❌ No |
❌ No |
❌ Unknown |
Engineering |
TBD |
| AssemblyAI |
✅ Yes |
❌ No |
❌ No |
⚠️ Partial |
Engineering |
TBD |
| Stripe |
✅ Yes |
✅ Yes |
✅ Yes |
N/A |
Finance |
✅ Complete |
| Supabase |
✅ Yes |
⚠️ Standard terms |
⚠️ Review |
N/A |
Engineering |
TBD |
| Railway |
⚠️ Unknown |
❌ No |
❌ No |
N/A |
Engineering |
TBD |
5. Data Deletion Capabilities by Provider
For DSAR (Data Subject Access Request) compliance, we must be able to request data deletion from each provider. See Deletion & Export Workflow for the full process.
| Provider |
Deletion API |
Manual Request |
Deletion Timeline |
Verified |
| OpenAI |
❌ No public API |
✅ Via support/DPA |
Unknown |
❌ Not tested |
| Pyannote.ai |
❌ Unknown |
❌ Unknown |
Unknown |
❌ Not tested |
| Replicate |
✅ Prediction deletion API |
✅ Via support |
Immediate (ephemeral) |
❌ Not tested |
| Hume AI |
❌ Unknown |
❌ Unknown |
Unknown |
❌ Not tested |
| AssemblyAI |
✅ Transcript deletion API |
✅ Via support |
Immediate |
❌ Not tested |
| Stripe |
✅ Customer deletion API |
✅ Via dashboard |
Per retention policy |
❌ Not tested |
| Supabase |
✅ Full database control |
✅ Via dashboard |
Immediate |
✅ Verified |
| MinIO |
✅ S3 API (self-hosted) |
✅ Direct access |
Immediate |
✅ Verified |
6. Subprocessor Change Log
| Date |
Change Type |
Provider |
Description |
Customer Notification |
| 2026-03-07 |
Initial |
All |
Initial subprocessor registry created |
N/A (first version) |
7. Implementation Status
| Component |
Status |
Notes |
| Subprocessor registry documentation |
✅ Complete |
This document |
| DPA execution with AI providers |
❌ Not Started |
All 5 AI providers need DPAs |
| DPA review for infrastructure |
⚠️ Partial |
Stripe complete; Supabase/Railway need review |
| Customer notification mechanism |
❌ Not Implemented |
No system to notify customers of subprocessor changes |
| Subprocessor change approval process |
❌ Not Implemented |
No internal review process defined |
| Provider security assessment |
❌ Not Started |
No vendor security questionnaires completed |
| Zero-retention configuration |
❌ Not Configured |
OpenAI zero-retention not enabled |
| Provider deletion testing |
❌ Not Tested |
Deletion capabilities not verified |
Priority Actions
- 🔴 Execute DPAs with OpenAI, Replicate, and AssemblyAI (DPAs available)
- 🔴 Contact Pyannote.ai and Hume AI to request DPAs
- 🔴 Enable zero-retention on OpenAI API
- 🟡 Review Supabase and Railway standard DPA terms
- 🟡 Test provider deletion APIs for DSAR readiness
- 🟡 Complete vendor security assessments
- 🟢 Build customer notification system for subprocessor changes
8. Revision History
| Version |
Date |
Author |
Changes |
| 1.0 |
2026-03-07 |
Privacy & Compliance Team |
Initial subprocessor registry |