{
  "version": 1,
  "effective_date": "2026-06-03",
  "operator": {
    "legal_name": "Navego AB",
    "contact_security": "security@quantlix.ai"
  },
  "subprocessors": [
    {
      "id": "github",
      "name": "GitHub, Inc. (Microsoft)",
      "role": "Source code hosting and CI",
      "regions": [
        "US",
        "EU"
      ],
      "data_categories": [
        "source_code",
        "ci_metadata"
      ],
      "website": "https://github.com",
      "tier": 2,
      "customer_configured": false
    },
    {
      "id": "hetzner",
      "name": "Hetzner Online GmbH",
      "role": "Cloud infrastructure (managed Quantlix hosting)",
      "regions": [
        "EU"
      ],
      "data_categories": [
        "customer_payloads",
        "operational_logs",
        "account_metadata"
      ],
      "website": "https://www.hetzner.com",
      "tier": 1,
      "customer_configured": false
    },
    {
      "id": "model_providers",
      "name": "Model providers you configure",
      "role": "Inference (OpenAI, Anthropic, Azure OpenAI, Bedrock, etc.)",
      "regions": [
        "varies"
      ],
      "data_categories": [
        "prompts",
        "completions",
        "embeddings"
      ],
      "website": null,
      "tier": 2,
      "customer_configured": true,
      "note": "Customer-selected; data flows per deployment provider binding and DPA."
    },
    {
      "id": "opentimestamps",
      "name": "OpenTimestamps calendar servers",
      "role": "Secondary blockchain timestamp for trace chain Merkle roots",
      "regions": [
        "global"
      ],
      "data_categories": [
        "sha256_merkle_root_digests"
      ],
      "website": "https://opentimestamps.org",
      "tier": 2,
      "customer_configured": false,
      "note": "Optional redundancy alongside Rekor; digest-only submissions."
    },
    {
      "id": "sigstore_rekor",
      "name": "Sigstore Rekor (Linux Foundation)",
      "role": "Transparency log for trace chain Merkle roots (hashedrekord; digest only)",
      "regions": [
        "US",
        "EU"
      ],
      "data_categories": [
        "sha256_merkle_root_digests"
      ],
      "website": "https://www.sigstore.dev",
      "tier": 2,
      "customer_configured": false,
      "note": "Enterprise trace chain anchoring when TRACE_CHAIN_ANCHOR_ENABLED is on. No tenant identifiers in public log entries."
    },
    {
      "id": "stripe",
      "name": "Stripe, Inc.",
      "role": "Payment processing and billing",
      "regions": [
        "EU",
        "US"
      ],
      "data_categories": [
        "billing_pii",
        "payment_metadata"
      ],
      "website": "https://stripe.com",
      "tier": 1,
      "customer_configured": false
    },
    {
      "id": "voyage",
      "name": "Voyage AI (when enabled)",
      "role": "Embeddings and semantic retrieval",
      "regions": [
        "US"
      ],
      "data_categories": [
        "text_for_embedding"
      ],
      "website": "https://www.voyageai.com",
      "tier": 2,
      "customer_configured": true,
      "note": "Only when used for RAG or semantic cache."
    }
  ],
  "content_hash": "6f70c0b26f45114bec427249e41bb1c61fe1ea5c9a6fd7e8d19bd547df6d7c9a",
  "published_at": "2026-06-08"
}
