# Nabii.Space — Subprocessors

**Last updated:** {{REVIEW_DATE}}

Nabii.Space engages the following subprocessors to deliver the Service. Each
subprocessor is bound by data-protection obligations no less protective than
Nabii.Space's DPA with Customer. Material changes are announced at least 30
days in advance through this page and, where an email address is on file,
by email to affected customers.

| Subprocessor | Purpose | Data categories | Region |
|---|---|---|---|
| Managed database / auth / storage backend | Application persistence, user authentication, file storage, edge compute | Account data, user-generated content, session tokens | EU / US (per project region) |
| Application hosting (edge network) | Serves the Nabii.Space web application and API routes | Request metadata, IP addresses | Global edge |
| AI model gateway | Routes drafting and evaluation requests to LLM providers | Prompt payloads, generated output (transient) | US |
| Foundation-model providers (via gateway) | Generate AI-assisted drafts and structural output | Prompt payloads (transient; retention per provider policy) | US |
| Web-similarity provider (optional, per IP-shield) | Distinctive-phrase search against the open web | Short text snippets from the draft | US |
| Email delivery | Transactional email (verification, receipts, notifications) | Recipient email, message body | US / EU |
| Payment processing | Subscription billing | Name, billing email, billing address, card token | Global |
| Error and analytics tooling | Runtime error capture and product analytics | Diagnostic events, coarse usage metadata | US / EU |

Customer-facing note: exact vendor names and current contracts are shared
under NDA with contracted Regulated-tier customers and prospective buyers on
request. Contact security@nabii.space.

## Change log

- {{REVIEW_DATE}} — initial published version.
