Legal
Sub-processor list
Every third-party service that processes customer data on Praxara's behalf is listed here. Customers are notified at least 14 days before we onboard a new one.
Last updated: 29 April 2026Notice period for new sub-processors: 14 daysAuthoritative version: app.praxara.io/legal/subprocessors
| Sub-processor | Purpose | Data category | Region | Last audited |
|---|---|---|---|---|
Microsoft Azure Customer chooses UK or EU residency at tenant creation. Geo-paired backups stay within the chosen jurisdiction. | Hosting, storage, compute, queue, search index | All Controller content (encrypted at rest) | UK South + EU West (Netherlands) | Annual (vendor SOC 2 Type II + ISO 27001 reviewed) |
Anthropic Inputs not retained beyond the call. SCCs + TIA on file. | LLM inference for narrative generation + drafting skills | Prompt content (input only — no training) | US with EU data path | Annual (Anthropic enterprise no-training terms reviewed) |
Google Cloud (Gemini) Inputs not retained. SCCs + TIA on file. | LLM inference for extraction + classification skills | Prompt content (input only — no training) | EU region (europe-west4) where supported | Annual (Google Cloud enterprise no-training terms reviewed) |
OpenAI Zero-data-retention API used where available. SCCs + TIA on file. | LLM inference for fallback skills + embeddings | Prompt content (input only — no training) | US with EU residency option | Annual (OpenAI enterprise no-training + zero-retention terms reviewed) |
Azure Document Intelligence | OCR, table extraction, and structure detection on uploaded files | Content of uploaded documents | UK region (matched to tenant residency) | Annual (covered by parent Microsoft Azure attestation) |
SendGrid | Transactional email delivery (invitations, password resets, alerts) | Email metadata only — no Controller PII in body beyond user name | US (with EU IP egress option) | Annual (SendGrid SOC 2 Type II reviewed) |
Stripe | Payment processing, subscription billing, invoicing | Billing data only — no clinical / PV data | UK + EU (Ireland) | Annual (Stripe PCI-DSS Level 1 attestation reviewed) |
How to object to a new sub-processor
Customers can object on reasonable grounds within the 14-day notice window by emailing [email protected]. If we can't accommodate the objection by reconfiguring or substituting the sub-processor, the customer may terminate the affected service for cause without penalty under the DPA.
Older versions of this list, change history, and audit attestations are available on request via the trust portal — /trust.