Service Providers & Subprocessors
Effective date: 1 November 2026. Published: 8 October 2026.
This list accompanies the consolidated terms, Privacy Policy and DPA. Before the effective date, refer to the previous SquadraOne provider list. Contact: contact@squadra.ai.
Core platform and website providers
| Provider | Purpose | Data involved | Location, retention and role |
|---|---|---|---|
| Google Cloud Platform — Cloud Run, Cloud SQL, virtual machines, Cloud Storage | Platform hosting, computation, database and file storage | Customer content, configuration, conversations, files, credentials and technical data as required by the component |
Core architecture uses Paris
(europe-west9); confirmed database
backups are in EU multiregion. SQL retains seven
automatic backups and seven days of recovery logs;
file soft delete is seven days. Other
processing/support may involve transfers. Processor
for relevant hosted Customer Data.
|
| Firebase Hosting / Google | Public website hosting | Visitor request and technical data | Managed hosting/CDN; do not assume EU-only processing. Website provider; separate from the app infrastructure. |
| OpenAI API | AI inference | Prompts, relevant conversation/context, knowledge-base excerpts and file content as supplied |
Responses API with store: false. No
model training by default unless the account holder
opts in; abuse-monitoring retention ordinarily up to
30 days, subject to exceptions, plus applicable
caching/feature processing. Transfers outside the
EEA possible.
|
| Google Gemini API | AI inference | Prompts, relevant conversation/context and supplied content | Applicable paid-service data terms exclude product-improvement use, including for EEA service users. Gemini API abuse-monitoring policy specifies 55 days; caching and feature-specific rules are separate. Policy-enforcement model use is disclosed in the Privacy Policy. Transfers outside the EEA possible. |
| Brevo | Transactional email | Email addresses, message content and delivery metadata | Recipient/service data needed to deliver messages. Processing locations and transfers depend on the contracted service. |
| Google Analytics | Website and relevant app usage analytics | Online identifiers, device and usage events | Non-essential tracking subject to consent where required. Analytics provider; not a recipient of customer content for model training. Processing outside the EEA possible. |
| Stripe | Payments and subscriptions | Billing details, payment information, subscription and transaction references | Payment provider; acts as an independent controller for relevant payment/compliance activities, rather than necessarily as our subprocessor. Transfers outside the EEA possible. |
Provider legal entities and transfer safeguards are determined by the applicable vendor agreements. This list does not assert that a brand has the same GDPR role for every activity. Customer-configured third-party tools and customer-supplied API accounts are additionally governed by the Customer’s arrangements with those providers.
Additional services associated with SquadraOne
These services are relevant where the associated workflow or optional feature is used. They are not all involved in every request or used by every User.
| Provider | Purpose | Data involved | Notes |
|---|---|---|---|
| Notion | Connected workspace operations and documentation/support workflows | Authorized workspace content, notes, documents, support requests or feedback | Agent access follows connection permissions. A customer-connected Notion account is also governed by that customer’s agreement with Notion. Transfers possible. |
| Firecrawl | Public web crawling in relevant workflows | Requested URLs and retrieved public content, which may contain personal data | Public availability does not remove data-protection obligations. Transfers possible. |
| Discord | Optional community and support interactions | User handles, messages and voluntarily shared content | Optional external service, with its own privacy terms. Transfers possible. |
Webflow is no longer listed as the current website host. Anthropic and Mistral are not listed as active providers solely because older documents described them as planned. Additional providers will be disclosed when actually engaged, following applicable notice requirements.
Retention, safeguards and changes
Inference use does not mean zero retention. See the Privacy Policy and the providers’ published policies: OpenAI data controls, Gemini terms and Gemini abuse monitoring. Account settings and enabled features can affect these rules.
Where required, international transfers must use an applicable lawful mechanism, such as adequacy or Standard Contractual Clauses with necessary supplementary measures. Contact us for information on the safeguards applicable to your service. Intended additions or replacements of our subprocessors will be notified by email to affected Customers under the DPA, with an opportunity to object on reasonable data-protection grounds.