Legal · Subprocessors
Subprocessors
Last updated · 10 August 2026 · v1.3 · Updated whenever the list changes
Palanor relies on the following subprocessors to operate the Enterprise Intelligence Platform. Each is contractually bound to confidentiality, security, and to processing data only as instructed by Palanor. Customers can subscribe to subprocessor updates at privacy@palanor.comand will receive at least 30 days’ notice of any change.
| Subprocessor | Service | Location | Data |
|---|---|---|---|
| Vercel, Inc. | Application hosting (Next.js) | USA · AWS us-east | App logs, request metadata |
| Supabase, Inc. | Postgres database, auth, object storage | USA · AWS us-east | All Customer Data |
| Anthropic, PBC | LLM inference (Claude) — the primary US model, used for all interactive and customer-context workloads (Numen chat + personalization, briefings, onboarding, and — for US-only organizations — news ranking and scenario narratives) | USA | Prompts and contextual data passed to model calls; not retained for training under our subprocessor agreement |
| OpenRouter, Inc. | LLM API gateway — the resilient front door that routes Palanor’s default-key model calls to the selected provider (Anthropic and others). A pass-through router; does not store prompt content. | USA | Prompts and contextual data in transit to the selected model provider; not retained for training. Bypassed entirely for BYOLLM customers (their key routes model-provider-direct). |
| Zhipu AI (GLM / z.ai), via OpenRouter | Cost-efficient LLM inference for high-volume, public-source workloads — news synthesis, earnings-call sentiment (Discourse), and Council research agents. For organizations not configured for US-only processing, also news ranking and scenario narratives. | China (model provider) · routed via OpenRouter | Public source content for synthesis/Discourse/Council. Business-profile / scenario context for ranking + scenarios only when the organization is not on US-only processing — see note below. Not retained for training. |
| Resend | Transactional email | USA | Outbound email content + recipient address |
| Stripe, Inc. | Payments (Stripe Atlas, billing) | USA + EU | Billing identifiers, payment method (tokenized) |
| OpenAI, LLC | Text embeddings; gpt-image-1 for news-image generation when no public-domain match exists | USA | Text passed to the embeddings + image endpoints; not retained for training under our subprocessor agreement |
| ElevenLabs, Inc. | Text-to-speech (Numen voice reader) | USA | Text passed to the synthesis endpoint to generate audio; not retained for training |
| Cloudflare, Inc. | DNS, domain registrar (palanor.com, .ai, .org, .net, .io, .info, .co, .dev, .app) | USA · global edge | DNS queries; no Customer Data passes through Cloudflare |
| Marketaux, s.r.o. | Financial news aggregation across 30+ publishers; entity-tagged, sentiment-scored feed used as a source of raw articles for Palanor synthesis | EU (Czech Republic) | No Customer Personal Data sent; we pull their published article metadata (titles, summaries, source URLs, images, entity tags) and synthesize on our side. Marketaux Standard tier license explicitly permits derivative LLM summaries with source attribution. |
| X Corp. | (1) Public-post outbound: posting Palanor news + Council content to the @palanor X account via OAuth 1.0a. (2) Public-post inbound: recent-search engagement context captured at article-publish time, displayed in the “On X right now” widget per X Developer Agreement display requirements. | USA · global | No Customer Personal Data sent. Outbound posts are Palanor-authored content. Inbound captures only the public-post metadata X already publishes openly — author handle, body, engagement counts, timestamp. Snapshotted per article; not re-fetched live. |
US-only processing. Organizations with data-residency or regulatory requirements can be configured for US-only LLM processing, in which case all inference that touches their contextual data — including news ranking and scenario narratives — runs on a US Anthropic model and never routes to a non-US provider. For full control, BYOLLM lets a customer supply their own model-provider key (Anthropic, Azure OpenAI); all of that organization’s inference then routes provider-direct under the customer’s own account, bypassing Palanor’s default providers and OpenRouter entirely. Contact privacy@palanor.com to enable either.
All subprocessor transfers outside the EEA are covered by EU Standard Contractual Clauses (Module Two, Controller to Processor) and the UK International Data Transfer Addendum. Subprocessor data processing agreements are available on request via privacy@palanor.com.