Subprocessors List

Authorized third parties for data processing

What is a subprocessor?

Under the General Data Protection Regulation (GDPR), a subprocessor is any third party engaged by us to process personal data on behalf of our customers.

At Solneko, we are committed to full transparency about who has access to the data we process. This page lists all currently authorized subprocessors and will be updated whenever changes occur.

Active Subprocessors

OpenAI Inc.

🌍 United States Since: April 4, 2026
Service provided: Natural language processing via API (GPT models)
Type of data processed: Chatbot conversation content, end-user messages
Purpose: Generation of intelligent chatbot responses using artificial intelligence
Processing location: United States (servers in multiple regions depending on availability)
Data retention: OpenAI retains API data for 30 days for abuse/misuse monitoring, then automatically deletes it
Use for training: No. OpenAI confirms that data submitted via the API is not used to train its models
Data protection safeguards:
International transfer risk assessment:

We have assessed that United States law does not prevent OpenAI from complying with the SCC safeguards. OpenAI implements sufficient technical (encryption, access control) and organizational measures (privacy policies, audits) to protect the personal data transferred.

OVHcloud

🇪🇺 European Union Since: April 4, 2026
Service provided: Hosting infrastructure, servers and database
Type of data processed: All data stored on the platform (conversations, customer data, logs)
Purpose: Secure storage and availability of the service infrastructure
Processing location: European Union, at the OVHcloud data centers used to provide the service
Data retention: Data retention in accordance with the service's operational configuration and the applicable internal retention and deletion policy
Data protection safeguards:

Change Process

Adding new subprocessors

When we need to add a new subprocessor or replace an existing one, we follow this process:

  1. Prior assessment: We verify that the subprocessor meets security and data protection standards equivalent to our own
  2. Advance notice: We inform all affected customers with at least 30 days' advance notice via email and by updating this page
  3. Right to object: Customers may object on grounds related to data protection within the notice period
  4. Contract with the subprocessor: We sign a DPA imposing the same data protection obligations that we undertake with our customers
  5. Record update: We update this public page and our internal records

Additional Information

Audit and transparency

Our customers have the right to:

Sub-subprocessors

Some of our subprocessors (particularly infrastructure providers) may in turn use sub-subprocessors. We ensure that these also comply with the same data protection standards through appropriate contractual clauses. Lists of sub-subprocessors are available on the transparency pages of each main provider.

International transfers

When data is transferred outside the European Economic Area (EEA), we ensure that adequate safeguards are in place through:

Contact

For inquiries about subprocessors or data protection:

Email: solneko@solneko.es

Data controller: Eloy Garrido Castro

Trade name: Solneko

Address: c/ de la Danza, 25, Mairena del Aljarafe, Spain

Version 1.0 | Last updated: April 4, 2026