PROOFCHAIN
● Data Processing Transparency

Subprocessors, Accounted For

ProofChain processes your data through a small, documented set of subprocessors. Every vendor, its purpose, the data it touches, where it sits, and the legal mechanism that governs the transfer — in one place.

Effective date: August 11, 2026 · Version 1.1 · Changes announced 30 days before activation

What This List Covers

A subprocessor is a third-party processor engaged by ProofChain to process personal data on its behalf, under the instructions of ProofChain and its customers. This page lists every subprocessor with a data-processing role in the ProofChain service as of the effective date.

Infrastructure that stores no customer personal data (registrars, certificate authorities, DNS resolvers, monitoring beacons) is not listed. If a vendor's role changes or a new vendor is engaged, this page is updated and all customers are notified no later than 30 days before the change takes effect.

Seven subprocessors, total. ProofChain deliberately keeps the processing chain short. Fewer processors means fewer copies of your data, fewer transfer paths, and a smaller attack surface. Each entry below states its purpose, data scope, location, and transfer mechanism.

Subprocessor Index

#SubprocessorRoleData ClassLocation
1StripePayments & billingBilling details, payment tokensUS / EU regions
2Google CloudInfrastructure & storageEncrypted backups, logs, configsUS multi-region
3Linode / AkamaiHosting & edgeServer logs, request metadata, IPsUS (Linode DCs)
4OpenAIVoice & transcription APIAudio, transcripts, prompt contentUS
5GroqLLM inferencePrompts, outputs, inference metadataUS
6X1 NetworkPublic blockchainEncrypted HXMP envelopes, addressesPublic network (global)
7Nous ResearchAgent runtime (Hermes)Task instructions, tool output, logsUS

Each entry is detailed in the sections below. The X1 network is a special case — it is a public ledger, not a conventional cloud vendor, and its data-flow rules are explained in its own section.

Stripe Active

Payment Processing

Purpose
Payment card processing, subscription billing (KYA shield monthly, vault one-time), one-time scan fix packages, and B2B setup invoices. Stripe handles the full checkout lifecycle and produces the payment records linked to each customer's HXMP trail.
Data Processed
Billing email address, customer name, payment card tokens (Stripe-managed, PCI DSS scope), payment amounts, currency, invoice history, and the ProofChain customer ID used to correlate payments with audit records.
Location
Data stored in US data centers by default; EU customers' payment data may be processed in Stripe's EU region. Stripe's infrastructure spans multiple regions with active-active failover.
Transfer Mechanism
Stripe's Data Processing Addendum with Standard Contractual Clauses (SCCs) for EEA/UK transfers, plus Stripe's global privacy practices. Card data never passes through ProofChain servers — it flows directly to Stripe over TLS.

ProofChain never sees, stores, or logs full card numbers. ProofChain receives only the payment token, the last-four for receipt display, and the payment status. Stripe is contractually prohibited from using customer data for any purpose other than providing payment services to ProofChain.

Google Cloud Active

Cloud Infrastructure & Storage

Purpose
Infrastructure backbone: object storage for encrypted backup snapshots of service configuration, application logging pipeline, and supporting compute for non-customer-facing tooling. Google Cloud is not the primary host for the public site or API — that is Linode — but it carries auxiliary infrastructure data.
Data Processed
Encrypted configuration backups, operational logs, infrastructure telemetry, and deployment artifacts. No customer audit-trail plaintext is stored in Google Cloud; HXMP envelopes on Google-hosted storage are always encrypted.
Location
US multi-region storage (default us-central / us-east), with the option to restrict to specific regions per account configuration. Data is replicated within the chosen region.
Transfer Mechanism
Google Cloud's Data Processing Addendum with Standard Contractual Clauses and Google's supplementary measures for EEA/UK transfers. Google Cloud is certified under SOC 1/2/3, ISO 27001, and ISO 27701.

Backups are encrypted at rest with ProofChain-managed keys before upload. Google Cloud personnel do not have access to the encryption keys, and customer data is never used by Google for advertising or model training.

Linode / Akamai Active

Hosting & Content Delivery

Purpose
Primary hosting for the ProofChain production environment: the public site (proofchain.us), the static compliance pages, the dashboard, and the API server (port 3458 behind nginx) run on Linode compute. Akamai provides the CDN and edge delivery layer for static assets.
Data Processed
Web server access logs (source IP, request path, user agent, timestamps), TLS metadata, and deployment artifacts. Application data persists in Linode-hosted storage only where required for runtime operation.
Location
United States — the production node is hosted in a Linode US data center. Akamai's edge cache may serve static assets from PoPs worldwide, including EU locations.
Transfer Mechanism
For EEA/UK data processed at the US hosting location: Standard Contractual Clauses under the Linode/Akamai DPA. Edge delivery by Akamai is governed by Akamai's data-processing terms and its certification to SOC 2, ISO 27001, and ISO 27018.

Access logs are retained on a rolling window and contain no HXMP plaintext. The server is hardened with fail2ban, CrowdSec, and a default-deny firewall; log retention is documented in the Security Overview.

OpenAI Active

Voice & Transcription API

Purpose
Speech-to-text transcription and voice interaction support for ProofChain's voice-enabled agent tooling. Audio from agent interactions is converted to text for processing and audit logging.
Data Processed
Audio snippets from agent voice interactions, generated transcripts, and the prompt/instruction context sent alongside transcription requests. Transcripts may feed HXMP audit records (encrypted before storage).
Location
United States — API processing occurs in OpenAI's US infrastructure. Data may be processed in additional regions under OpenAI's then-current infrastructure terms.
Transfer Mechanism
OpenAI's Data Processing Addendum with Standard Contractual Clauses for EEA/UK transfers. Zero-data-retention API configuration is used where available so transcripts are not retained by OpenAI for service improvement.

OpenAI does not use ProofChain's API input or output to train OpenAI models by default for API customers. ProofChain limits the data sent to OpenAI to the minimum required for transcription and strips identifiers where possible before transmission.

Groq Active

LLM Inference

Purpose
Large language model inference for agent reasoning, compliance report generation, and automated analysis within the ProofChain service. Groq's LPU infrastructure provides the low-latency inference used by ProofChain's agent tooling.
Data Processed
Prompt text, generated outputs, inference request metadata (timestamps, model identifiers, token counts). Outputs destined for audit trails are hashed and encrypted into HXMP envelopes after generation.
Location
United States — inference runs in Groq's US data centers. No EU-specific regions are currently used.
Transfer Mechanism
Groq's Data Processing Addendum with Standard Contractual Clauses for EEA/UK transfers, plus contractual no-training commitments. Groq does not use customer prompts or outputs to train models.

ProofChain sends only the operational context required for each inference call. Pre-computed hashes of outputs are recorded on-chain, so even if inference traffic were intercepted, the audit trail's integrity claims remain independently verifiable.

X1 Network Active · Public Ledger

Public Blockchain (HXMP Audit Trail)

Purpose
The public blockchain on which ProofChain writes HXMP audit envelopes, AgentID identity records, and compliance evidence. X1 provides the tamper-evident, slot-timestamped ledger that makes ProofChain's audit trails verifiable by third parties.
Data Processed
Transaction memos containing encrypted HXMP envelopes, wallet addresses, transaction signatures, and block timestamps. No plaintext personal data is intentionally written to the chain — payloads are encrypted before submission.
Location
Public network — validator nodes are distributed globally and the ledger is replicated worldwide. Data committed to X1 is public by design and cannot be confined to a jurisdiction.
Transfer Mechanism
Not a conventional transfer. X1 is a public ledger; ProofChain does not "transfer" personal data to a vendor. Records are encrypted to ciphertext before publication, and GDPR erasure is effected by key destruction (see the Compliance page).

Immutability disclosure: data written to X1 cannot be deleted, modified, or redacted by ProofChain or any party. Customers acknowledge this architectural constraint when using ProofChain. The chain carries ciphertext, not plaintext — but the ciphertext is permanent.

Nous Research Active

Hermes Agent Runtime

Purpose
Agent orchestration runtime for ProofChain's own operations and for customer-facing agent tooling. The Hermes agent runtime (Nous Research) executes task workflows, invokes tools, and coordinates agent actions that ProofChain then records to the audit trail.
Data Processed
Task instructions, tool invocation inputs and outputs, runtime configuration, execution logs, and session metadata. Data is processed under ProofChain's instructions; outputs are recorded into HXMP envelopes where they constitute audit evidence.
Location
United States — runtime infrastructure and supporting services are US-hosted. Runtime telemetry is retained per the Security Overview's log-retention policy.
Transfer Mechanism
Processing agreement with Standard Contractual Clauses for EEA/UK transfers and contractual commitments that customer data is used solely to provide the runtime service — never for training or unrelated purposes.

ProofChain dogfoods this stack: the same agent runtime that powers ProofChain's compliance reports and marketing pipeline is itself audited through the HXMP trail — ProofChain uses ProofChain to prove ProofChain.

Change Notification Policy — 30 Days

ProofChain will notify all customers of any new subprocessor, or any material change to an existing subprocessor's role or data handling, at least 30 days before the change takes effect. This is a contractual commitment, not a courtesy.

T-30 DAYS
Notification issued
Notice posted to this page, emailed to the billing contact on file, and logged as an event in the customer's HXMP audit trail (ProofChain records its own transparency, too).
DAYS 1–29
Review & objection window
Customers may object to the change in writing to dpo@proofchain.us. ProofChain will respond with the assessment and, where required, make reasonable efforts to avoid the change or terminate the affected processing without penalty.
T-0
Activation
The change takes effect only after the notice period has elapsed. This page is updated with the new effective date and version number.

Notification channels: (1) this page, (2) email to the billing contact, (3) the HXMP audit trail event. All three are updated simultaneously so the notice is verifiable after the fact.

How to Object to a Subprocessor

Response SLA: acknowledgment within 2 business days, substantive determination within 10 business days. Objections and their resolutions are themselves recorded as HXMP events on the customer's trail — the governance process is auditable too.

Cross-Border Transfer Mechanisms

All transfers of personal data from the EEA, UK, or Switzerland to third countries are governed by the following mechanisms, applied per vendor as noted in each section above:

ProofChain conducts transfer impact assessments when SCCs are relied upon, and updates them on regulatory guidance changes. The current assessment status is documented in the Data Processing Agreement.

Data Retention

Data ClassWhereRetention
HXMP audit envelopesX1 blockchainPermanent (immutable ledger; erasure via key destruction)
Payment recordsStripePer Stripe's retention terms + ProofChain's accounting obligations
Server access logsLinode + Google Cloud logsRolling window, ≤ 30 days
Transcription / inference contentOpenAI / GroqZero-retention API mode where available; otherwise per vendor DPA
Account & billing dataProofChain app DBFor the duration of the account + required legal periods

On account termination, ProofChain ceases processing through all subprocessors, requests deletion of retained data where contractually available, and destroys ProofChain-managed keys for on-chain records — completing the erasure story per the Compliance page.

Security Requirements for Subprocessors

Every subprocessor must meet a baseline that ProofChain enforces contractually and reviews on a scheduled cycle:

Vendor security posture is reviewed at onboarding and annually thereafter. Findings are recorded in ProofChain's risk register, which feeds the SOC 2 Type II evidence trail currently in progress.

Audit & Verification Rights

ProofChain's subprocessor agreements grant audit and inspection rights, and ProofChain exercises them:

Verification is not limited to paper: the HXMP trail lets customers verify where records were actually written — on-chain evidence complements, rather than replaces, vendor attestations.

Contractual Flow-Down & Your DPA

The obligations ProofChain owes you flow down to every subprocessor by contract. The Data Processing Agreement incorporates this subprocessor list by reference and includes:

Customers accept this list by using the service; the DPA and this page together constitute the subprocessor notice required under Article 28 of the GDPR. If your organization needs a custom DPA addendum, contact dpo@proofchain.us.

Changelog

VersionEffectiveChange
1.1Aug 11, 2026Initial public subprocessor register published (7 subprocessors). Full per-vendor disclosure of purpose, data, location, and transfer mechanisms.
1.0Aug 2026Internal register compiled; vendor contracts and DPAs aligned to this list.

Future changes to this list are governed by the 30-day notification policy in section 10. Historical versions are retained in the HXMP audit trail for verifiability.

Questions, Objections, Report Requests

All subprocessor-related correspondence goes to the Data Protection Officer:

Every correspondence thread affecting your account is recorded in your HXMP trail, so the record of your questions and our answers is itself tamper-evident.

See the Trail These Vendors Feed Into

Subprocessors are one half of the transparency story. The other half is the audit trail that records what your agents actually do.