Subprocessors, Accounted For
ProofChain processes your data through a small, documented set of subprocessors. Every vendor, its purpose, the data it touches, where it sits, and the legal mechanism that governs the transfer — in one place.
What This List Covers
A subprocessor is a third-party processor engaged by ProofChain to process personal data on its behalf, under the instructions of ProofChain and its customers. This page lists every subprocessor with a data-processing role in the ProofChain service as of the effective date.
Infrastructure that stores no customer personal data (registrars, certificate authorities, DNS resolvers, monitoring beacons) is not listed. If a vendor's role changes or a new vendor is engaged, this page is updated and all customers are notified no later than 30 days before the change takes effect.
Seven subprocessors, total. ProofChain deliberately keeps the processing chain short. Fewer processors means fewer copies of your data, fewer transfer paths, and a smaller attack surface. Each entry below states its purpose, data scope, location, and transfer mechanism.
Subprocessor Index
| # | Subprocessor | Role | Data Class | Location |
|---|---|---|---|---|
| 1 | Stripe | Payments & billing | Billing details, payment tokens | US / EU regions |
| 2 | Google Cloud | Infrastructure & storage | Encrypted backups, logs, configs | US multi-region |
| 3 | Linode / Akamai | Hosting & edge | Server logs, request metadata, IPs | US (Linode DCs) |
| 4 | OpenAI | Voice & transcription API | Audio, transcripts, prompt content | US |
| 5 | Groq | LLM inference | Prompts, outputs, inference metadata | US |
| 6 | X1 Network | Public blockchain | Encrypted HXMP envelopes, addresses | Public network (global) |
| 7 | Nous Research | Agent runtime (Hermes) | Task instructions, tool output, logs | US |
Each entry is detailed in the sections below. The X1 network is a special case — it is a public ledger, not a conventional cloud vendor, and its data-flow rules are explained in its own section.
Payment Processing
ProofChain never sees, stores, or logs full card numbers. ProofChain receives only the payment token, the last-four for receipt display, and the payment status. Stripe is contractually prohibited from using customer data for any purpose other than providing payment services to ProofChain.
Cloud Infrastructure & Storage
Backups are encrypted at rest with ProofChain-managed keys before upload. Google Cloud personnel do not have access to the encryption keys, and customer data is never used by Google for advertising or model training.
Hosting & Content Delivery
Access logs are retained on a rolling window and contain no HXMP plaintext. The server is hardened with fail2ban, CrowdSec, and a default-deny firewall; log retention is documented in the Security Overview.
Voice & Transcription API
OpenAI does not use ProofChain's API input or output to train OpenAI models by default for API customers. ProofChain limits the data sent to OpenAI to the minimum required for transcription and strips identifiers where possible before transmission.
LLM Inference
ProofChain sends only the operational context required for each inference call. Pre-computed hashes of outputs are recorded on-chain, so even if inference traffic were intercepted, the audit trail's integrity claims remain independently verifiable.
Public Blockchain (HXMP Audit Trail)
Immutability disclosure: data written to X1 cannot be deleted, modified, or redacted by ProofChain or any party. Customers acknowledge this architectural constraint when using ProofChain. The chain carries ciphertext, not plaintext — but the ciphertext is permanent.
Hermes Agent Runtime
ProofChain dogfoods this stack: the same agent runtime that powers ProofChain's compliance reports and marketing pipeline is itself audited through the HXMP trail — ProofChain uses ProofChain to prove ProofChain.
Change Notification Policy — 30 Days
ProofChain will notify all customers of any new subprocessor, or any material change to an existing subprocessor's role or data handling, at least 30 days before the change takes effect. This is a contractual commitment, not a courtesy.
Notification channels: (1) this page, (2) email to the billing contact, (3) the HXMP audit trail event. All three are updated simultaneously so the notice is verifiable after the fact.
How to Object to a Subprocessor
- Submit in writing to dpo@proofchain.us with your account identifier and the subprocessor name. State the reason for the objection and the legal basis (e.g., inadequate data protection, unlawful transfer).
- ProofChain assesses the objection within 10 business days and replies with its determination, including any compensating measures.
- If the objection is upheld and ProofChain cannot reasonably avoid the change, the customer may terminate the affected services without penalty, receiving a pro-rata refund for prepaid, unused periods.
- If the objection is rejected, the customer may still terminate under the same no-penalty terms. This is a consumer-protective policy: no customer is ever locked into a subprocessor they do not accept.
Response SLA: acknowledgment within 2 business days, substantive determination within 10 business days. Objections and their resolutions are themselves recorded as HXMP events on the customer's trail — the governance process is auditable too.
Cross-Border Transfer Mechanisms
All transfers of personal data from the EEA, UK, or Switzerland to third countries are governed by the following mechanisms, applied per vendor as noted in each section above:
- Standard Contractual Clauses (SCCs) — the default mechanism for US-based subprocessors, including the EU Commission's 2021 module structure with supplementary measures.
- Data Protection Frameworks — where a US subprocessor is certified, transfers rely on the EU-US Data Privacy Framework (or UK Extension) for certified entities, reducing SCC burden.
- Public ledger carve-out — the X1 network is a public, permissionless ledger. Data is encrypted to ciphertext prior to publication, so no personal-data "transfer" occurs in the GDPR sense; erasure is by key destruction.
- Contractual flow-down — every subprocessor agreement binds the vendor to (a) process only on documented instructions, (b) confidentiality obligations, (c) appropriate technical and organizational measures, and (d) deletion or return of data on termination.
ProofChain conducts transfer impact assessments when SCCs are relied upon, and updates them on regulatory guidance changes. The current assessment status is documented in the Data Processing Agreement.
Data Retention
| Data Class | Where | Retention |
|---|---|---|
| HXMP audit envelopes | X1 blockchain | Permanent (immutable ledger; erasure via key destruction) |
| Payment records | Stripe | Per Stripe's retention terms + ProofChain's accounting obligations |
| Server access logs | Linode + Google Cloud logs | Rolling window, ≤ 30 days |
| Transcription / inference content | OpenAI / Groq | Zero-retention API mode where available; otherwise per vendor DPA |
| Account & billing data | ProofChain app DB | For the duration of the account + required legal periods |
On account termination, ProofChain ceases processing through all subprocessors, requests deletion of retained data where contractually available, and destroys ProofChain-managed keys for on-chain records — completing the erasure story per the Compliance page.
Security Requirements for Subprocessors
Every subprocessor must meet a baseline that ProofChain enforces contractually and reviews on a scheduled cycle:
- Encryption in transit and at rest — TLS 1.2+ for all data in transit; AES-256 or equivalent at rest.
- Certification — SOC 2 (Type I or II) or ISO 27001, or an equivalent independently audited framework, held and current.
- Access control — least-privilege access, multi-factor authentication for administrative access, and documented access reviews.
- Breach notification — notification to ProofChain within 72 hours of any confirmed incident affecting ProofChain customer data.
- No data use — no use of customer data for the vendor's own purposes, no training on customer data without explicit opt-in, no advertising use.
- Sub-processing — vendors may not engage further subprocessors without ProofChain's written consent, mirroring the transparency ProofChain owes its own customers.
Vendor security posture is reviewed at onboarding and annually thereafter. Findings are recorded in ProofChain's risk register, which feeds the SOC 2 Type II evidence trail currently in progress.
Audit & Verification Rights
ProofChain's subprocessor agreements grant audit and inspection rights, and ProofChain exercises them:
- Independent reports — ProofChain reviews each vendor's SOC 2 / ISO reports on an annual cycle, and on any material incident.
- On-site audits — where contractually available, ProofChain (or a mutually agreed third party) may conduct audits with reasonable notice, not more than once per year absent cause.
- Customer access — customers may request copies of the relevant vendor reports in redacted form via dpo@proofchain.us, subject to confidentiality and the vendors' distribution terms.
Verification is not limited to paper: the HXMP trail lets customers verify where records were actually written — on-chain evidence complements, rather than replaces, vendor attestations.
Contractual Flow-Down & Your DPA
The obligations ProofChain owes you flow down to every subprocessor by contract. The Data Processing Agreement incorporates this subprocessor list by reference and includes:
- Documented instructions — vendors process only on ProofChain's written instructions, which mirror the customer's instructions to ProofChain.
- Confidentiality — vendor personnel bound by confidentiality obligations, statutory or contractual.
- Security — the technical and organizational measures in section 14, contractually binding.
- Data subject rights — vendors must assist with the fulfilment of data subject requests within agreed timeframes.
- Deletion — on termination, vendors delete or return all customer data at ProofChain's election, unless law requires retention.
Customers accept this list by using the service; the DPA and this page together constitute the subprocessor notice required under Article 28 of the GDPR. If your organization needs a custom DPA addendum, contact dpo@proofchain.us.
Changelog
| Version | Effective | Change |
|---|---|---|
| 1.1 | Aug 11, 2026 | Initial public subprocessor register published (7 subprocessors). Full per-vendor disclosure of purpose, data, location, and transfer mechanisms. |
| 1.0 | Aug 2026 | Internal register compiled; vendor contracts and DPAs aligned to this list. |
Future changes to this list are governed by the 30-day notification policy in section 10. Historical versions are retained in the HXMP audit trail for verifiability.
Questions, Objections, Report Requests
All subprocessor-related correspondence goes to the Data Protection Officer:
- Email: dpo@proofchain.us (also compliance@proofchain.us)
- Response SLA: acknowledgment within 2 business days; substantive response within 10 business days for objections.
- Verification requests: vendor attestation summaries (SOC 2, ISO) available in redacted form under NDA.
Every correspondence thread affecting your account is recorded in your HXMP trail, so the record of your questions and our answers is itself tamper-evident.