Subprocessors
Last updated: July 12, 2026
Klarefi engages the following subprocessors to deliver the service. Each is bound by data protection obligations materially no less protective than our data processing agreement. Customer case content and the primary application, parsing, and AI processing paths are EU-hosted by default. Identity, billing, email, status, and encrypted-backup providers may process the limited categories shown below outside the EEA; those transfers are covered by standard contractual clauses or another recognized transfer mechanism.
| Subprocessor | Purpose | Data categories | Location |
|---|---|---|---|
| Railway | Infrastructure hosting for the web application, document processing workers, database, and object storage for uploaded files. | All customer data handled by the service: account data, intake responses, case documents, and workflow records. | EU |
| TensorX | AI model inference for extraction and verification. Common high-sensitivity patterns are minimized before supported text calls. Applicant documents and case content are processed only for inference and are not used to train shared models. | Document text, intake responses, and document page images submitted for inference. Names, addresses, and other context may remain when needed to perform the workflow. | EU; zero data retention |
| LlamaIndex (LlamaParse)Fallback parser | Document parsing for complex layouts, engaged when built-in parsing cannot read a document. Processed through the EU endpoint. | Customer documents submitted for parsing. | EU |
| WorkOS | Authentication, single sign-on, and organization membership. | User account and contact data, such as names, email addresses, and organization membership. No case data. | EU and US |
| Stripe | Payments, billing, and subscription administration. | Billing contact and payment data only. No case data. | EU and US |
| Resend | Transactional and lifecycle email delivery. | Recipient names, email addresses, and the content of service emails. | EU and US |
| Cloudflare | Serving the public status page and storing off-platform backup copies. Backups are encrypted before they leave Klarefi's infrastructure. | Encrypted backup copies of customer data. The status page serves no customer data. | EU and US |
| DataFastConsent-gated | Consent-gated public-site and product analytics, limited to acquisition and activation measurement. | Usage and device data, a pseudonymous browser visitor identifier, and low-cardinality activation events. No account identity, organization identity, applicant, or case data. | EU and US |
| AxiomPrivacy-minimized allowlist | EU-hosted service observability, error monitoring, and reliability diagnostics. | Allowlisted operational metadata such as service, route, status, duration, job type, processing counts, and random request or job identifiers. No applicant identifiers, raw errors, request bodies, document names, case content, extracted values, or evidence text. | EU |
Locations describe where the provider processes personal data for Klarefi's default deployment. Deployment-specific residency commitments are set out in the applicable customer agreement.
Providers receiving applicant documents or case content may process that data only to deliver the contracted service. Klarefi does not authorize subprocessors to use it to train shared models. Public-site analytics and privacy-minimized service telemetry do not include raw applicant documents, extracted values, or evidence text.
Changes to this list are posted here first. To receive notice of subprocessor changes by email, write to [email protected] with the subject "Subprocessor notifications" and the organization you represent.