Every third party that may process personal data on our behalf, what they handle, and where. We give notice before adding one.
Security reviewers ask for it, and a vendor that will not name its supply chain is asking you to accept unmeasured risk. The register below is current and maintained.
We notify account administrators in-product and by email at least thirty days before a new sub-processor begins processing customer personal data.
During that period a customer may object in writing on reasonable data-protection grounds, and we will work in good faith towards an alternative or, failing that, allow termination of the affected service without penalty.
Each sub-processor is engaged under a written contract requiring security measures no less protective than our own, restricting processing to our documented instructions, prohibiting onward transfer without authorisation, and requiring assistance with data-principal requests and breach notification.
Model providers are additionally bound by terms prohibiting training on any content submitted through our services.
Sub-processors handling Indian customer client data operate within India. This is the same commitment made on the data protection notice and the security page — no client data is transferred outside India, to any sub-processor.
A detailed register including contract dates, sub-processor certifications and data-flow diagrams per product is available under NDA. Write to [email protected]; we return it within five working days.
Questions about this document: [email protected]. Data protection and privacy requests: [email protected]. Grievances: grievance redressal.
EnterFirst Private Limited, 10th Floor, Plot No 1015, Arunachal Building, Barakhamba Road, New Delhi 110001, India · CIN U64990DL2023PTC411277. EnterFirst Pte Ltd, 6001 Beach Road, #12-04, Golden Mile Tower, Singapore 199589.
Every sub-processor with access to client tax, trademark or regulatory data operates within India. Functions that never touch that data are marked accordingly.