Legal · GDPR

Sub-processors

Who processes data on behalf of our customers, for what, and where.

Last updated: 25 September 2026

How it works

Situra acts as a processor for its customers. The platform runs on Microsoft Azure, Spain Central region (Madrid).

A model provider only processes data when a project’s residency tier and the chosen model route a request to it. An ES-tier project can only use routes in Spain; an EU-tier project, routes in the EU or Spain; a global project, any route. The gateway enforces this on every request.

Platform, payments and communications

Sub-processorServicesPurposeLocation
Microsoft (Azure)AKS, Azure Database for PostgreSQL, Azure Cache for Redis, Key Vault, Front DoorPlatform hosting, database, secrets, edge (WAF and TLS)Spain (Spain Central). Front Door is Microsoft’s global edge network; its configuration will be detailed in the DPA.
StripeCheckout, Billing, Invoicing, TaxCard payments, invoices and VATTo be detailed in the DPA
[email provider] Transactional email provider Account verification, budget alerts and invoices To be confirmed

Model providers

They are involved only when a route allowed for the project points to them. The routes column shows where processing happens in each tier.

Planned catalogue as of September 2026. Regional availability changes often; the live catalogue per project is shown in the console. DeepSeek is not a sub-processor: we never connect api.deepseek.com and its models are offered only as self-hosted open weights.
ProviderServiceRoutes per tier and location
Microsoft Azure OpenAI, Microsoft Foundry
  • ES Spain Central (per-model availability to verify)
  • EU Azure EU Data Zone; Foundry EU regional endpoints
Google Vertex AI (Gemini, Claude)
  • ES Madrid (europe-southwest1)
  • EU EU multi-region / EU regions
  • Global Global
Amazon Web Services Amazon Bedrock (Claude)
  • EU EU regional endpoints
Anthropic Anthropic API
  • Global Global (api.anthropic.com)
OpenAI OpenAI API
  • EU Europe-region project (eligible customers)
  • Global US by default (api.openai.com)
Mistral AI Mistral API
  • EU EU (EU hosting by default)

Components we run ourselves

These components run inside our own Azure subscription in Spain Central. They are not additional sub-processors: their infrastructure is the Microsoft Azure listed above.

Zitadel (planned)Customer identity provider for SSO, including SAML (self-hosted, unmodified)
ClickHouseUsage metadata and observability
NATS JetStreamConfiguration distribution and usage events
vLLMSelf-hosted open-weight models (DeepSeek, Qwen, Mistral and others)

Changes

The DPA will set out how we inform customers of any intended change to this list, in line with GDPR Article 28(2), so they can object.

Questions about this list: situra@syntheris.com

Privacy policy · Residency & compliance