Subprocessors List
Authorized third parties for data processing
What is a subprocessor?
Under the General Data Protection Regulation (GDPR), a subprocessor is any
third party engaged by us to process personal data on behalf of our customers.
At Solneko, we are committed to full transparency about who has access
to the data we process. This page lists all currently authorized subprocessors and will be
updated whenever changes occur.
🔔 Notice of changes: In accordance with our DPA, we will notify all customers with
30 days' advance notice before adding new subprocessors or making substantial changes.
Customers may object on grounds related to data protection.
Active Subprocessors
OpenAI Inc.
🌍 United States
Since: April 4, 2026
Service provided:
Natural language processing via API (GPT models)
Type of data processed:
Chatbot conversation content, end-user messages
Purpose:
Generation of intelligent chatbot responses using artificial intelligence
Processing location:
United States (servers in multiple regions depending on availability)
Data retention:
OpenAI retains API data for 30 days for abuse/misuse monitoring, then automatically deletes it
Use for training:
No. OpenAI confirms that data submitted via the API is not used to train its models
Data protection safeguards:
International transfer risk assessment:
We have assessed that United States law does not prevent OpenAI from complying with the SCC safeguards.
OpenAI implements sufficient technical (encryption, access control) and organizational measures (privacy
policies, audits) to protect the personal data transferred.
OVHcloud
🇪🇺 European Union
Since: April 4, 2026
Service provided:
Hosting infrastructure, servers and database
Type of data processed:
All data stored on the platform (conversations, customer data, logs)
Purpose:
Secure storage and availability of the service infrastructure
Processing location:
European Union, at the OVHcloud data centers used to provide the service
Data retention:
Data retention in accordance with the service's operational configuration and the applicable internal retention and deletion policy
Data protection safeguards:
Change Process
Adding new subprocessors
When we need to add a new subprocessor or replace an existing one, we follow this process:
- Prior assessment: We verify that the subprocessor meets security and data protection standards equivalent to our own
- Advance notice: We inform all affected customers with at least 30 days' advance notice via email and by updating this page
- Right to object: Customers may object on grounds related to data protection within the notice period
- Contract with the subprocessor: We sign a DPA imposing the same data protection obligations that we undertake with our customers
- Record update: We update this public page and our internal records
💡 How to object? If a customer wishes to object to the addition of a new subprocessor,
they must contact us at solneko@solneko.es within the 30-day period, stating the grounds related
to data protection. We will jointly seek an alternative solution or, if this is not possible,
the customer may terminate the contract without penalty.
Additional Information
Audit and transparency
Our customers have the right to:
- Request additional information about the security measures implemented by our subprocessors
- Receive a copy of the DPAs signed with subprocessors (subject to confidentiality obligations)
- Carry out compliance audits as set out in our DPA
Sub-subprocessors
Some of our subprocessors (particularly infrastructure providers) may in turn use
sub-subprocessors. We ensure that these also comply with the same data protection standards
through appropriate contractual clauses. Lists of sub-subprocessors are available on the
transparency pages of each main provider.
International transfers
When data is transferred outside the European Economic Area (EEA), we ensure that adequate
safeguards are in place through:
- Standard Contractual Clauses (SCC): Approved by the European Commission
- Adequacy decisions: For countries recognized by the EU as offering an adequate level of protection
- Supplementary measures: Encryption, data minimization, impact assessments
Version 1.0 | Last updated: April 4, 2026