YAKKL Subprocessor and Service-Provider Register
Current YAKKL service providers, managed AI providers, roles, and data paths.
This register distinguishes the roles vendors may have across YAKKL data paths. The same vendor may have different roles for different paths.
1. Roles and data paths
- Subprocessors: vendors processing Customer Personal Data for YAKKL-managed business Services;
- Controller-side service providers: vendors supporting YAKKL's own website, accounts, sales, billing, analytics, security, and communications;
- Customer-selected recipients: direct BYOK providers, custom endpoints, repositories, tools, and integrations selected by the customer; and
- Local-only components: software that does not receive data from the customer environment.
Customer-selected recipients are not automatically YAKKL subprocessors. The same vendor may have different roles for different data paths.
3. Website and service providers
| Vendor/product | Role | Purpose | Typical data | Consent/trigger |
|---|---|---|---|---|
| Cloudflare, Inc. | Controller-side provider and Subprocessor (see also §4 for Workers AI) | CDN, DNS/proxy, security, traffic management, hosting | IP, request/device/security logs; hosted data if applicable | Essential or Service activation |
| Cloudflare Turnstile | Controller-side provider | Bot and abuse prevention | IP, device/browser, interaction/security signals | User accesses protected form/flow |
| Google Analytics | Controller-side provider | Website analytics | Consent-based website/device/event data | Analytics consent |
| PostHog | Controller-side provider and possible Subprocessor depending deployment | Website/product analytics | Consent-based events limited to allow-listed fields that exclude Customer Content; autocapture and session recording are disabled | Analytics consent or contracted product setting |
| Brevo | Controller-side provider | Newsletter, transactional or requested email | Email, name, consent, campaign/transaction events | User signs up or email is required for Service |
| Stripe, Inc. | Controller-side provider (partly independent controller for payments/fraud) | Checkout, card payment, fraud screening, billing | Identity, billing, payment and transaction data | User initiates purchase/account billing |
| PayPal, Inc. | Controller-side provider (partly independent controller for payments/disputes) | Alternate payment rail, wallet checkout | Identity, billing, payment and transaction data | User selects PayPal at checkout |
| LambdaStack, LLC (payment gateway) | Controller-side provider (affiliated); non-custodial on-chain settlement contract | Crypto payment acceptance and swap-to-stablecoin settlement | Wallet addresses, transaction identifiers, amounts (note: on-chain data is inherently public) | User selects crypto at checkout |
4. AI and infrastructure providers
| Provider | YAKKL-managed role | Regions | Content retention | Abuse exception | Training status | Transfer mechanism | Effective date |
|---|---|---|---|---|---|---|---|
| Anthropic, PBC (EEA/CH/UK customers contract with Anthropic Ireland, Limited) | Subprocessor — managed model execution. Receives Customer Content (may contain personal data) on managed routes only | Global | API inputs and outputs deleted within 30 days of receipt or generation (Anthropic Privacy Center retention article, Jul 1, 2026) | Content flagged by automated trust-and-safety systems retained up to 2 years; classification scores up to 7 years | No training on Customer Content (Commercial Terms of Service, Jun 17, 2025, §B) | DPA (Feb 24, 2025): EU SCCs Modules 2 and 3, UK Addendum, Swiss Addendum. Not DPF-certified | Aug 12, 2026 |
| OpenAI OpCo, LLC (EEA/CH customers contract with OpenAI Ireland Ltd) | Subprocessor — managed model execution, same scope | Global | API inputs and outputs retained up to 30 days for abuse monitoring, then removed; stored-state endpoints (e.g., Assistants/Threads) retain until deleted ("How we use your data," platform docs) | 30-day abuse-monitoring logs; flagged content may be retained and human-reviewed; ZDR available by approval and revocable per model | Not used to train, develop, or improve the services absent explicit opt-in (OpenAI Services Agreement §4.2, effective Jan 1, 2026) | DPA executed (in-account): EU SCCs Modules 2 and 3, UK Addendum; EEA/Swiss data processed via OpenAI Ireland Ltd. Not DPF-certified | Aug 12, 2026 |
| Google LLC | Subprocessor — managed model execution, same scope | Global | Optional API logging, default maximum 55 days (configurable 7–55); paid-tier logs not used for product improvement (Gemini API data-logging policy, Jul 9, 2026) | Prompts and outputs retained 55 days for Prohibited Use Policy enforcement, with human review by authorized personnel (Gemini API usage policies, Jun 9, 2026) | Paid services: prompts and responses not used to improve products (Gemini API Additional Terms, Mar 23, 2026; all YAKKL usage is on paid services) | Processor DPA v10 (May 7, 2026) at business.safety.google/processorterms (not the Cloud DPA): SCCs; Google LLC is DPF-certified (EU, Swiss, UK extension) | Aug 12, 2026 |
| X.AI LLC | Subprocessor — managed model execution, same scope | Global | User Content automatically deleted no later than 30 days after end of session (Enterprise ToS §3.4) | Retention beyond 30 days permitted for safety, security, abuse prevention, or legal compliance — no fixed outer window stated; ZDR mode deletes within 1 hour | No training on User Content (Enterprise ToS §3.3); de-identified usage data may be used for service improvement | DPA (Jun 9, 2025): EU SCCs Modules 2 and 3, UK Addendum, Swiss modifications. Not DPF-certified | Aug 12, 2026 |
| Cloudflare, Inc. (Workers AI — open-source models on Cloudflare infrastructure) | Subprocessor — managed execution of open-source models. Model authors receive no data; inference runs on Cloudflare's GPU subprocessors (CoreWeave, Inc. (US); Nebius BV (England)) | Global | No Workers AI-specific fixed retention window is stated; processing lasts only until the DPA ends or is no longer necessary, with deletion or return at termination | No separate Workers AI abuse-retention exception is stated in the applicable service-specific terms | No use of Customer Content to train generative AI tools unless otherwise agreed (Developer Platform Service-Specific Terms, Jun 2, 2026) | DPA v6.4 (Apr 3, 2026): EU SCCs Modules 2 and 3, UK Addendum, Swiss; Cloudflare is DPF-certified (all three frameworks) | Aug 12, 2026 |
Customer-selected recipients (not YAKKL subprocessors — shown for transparency): any provider or endpoint the customer connects via direct BYOK or custom endpoint, including the vendors above when reached with the customer's own credentials. Those paths run under the provider's own terms and the customer's settings; YAKKL does not receive the payloads and has not negotiated retention or training terms for them.
7. Change notices
YAKKL publishes this current register at a stable legal URL. Business customers may request email-based change notices by contacting privacy@yakkl.com.