Subprocessor Registry

Third-party service providers that process data on behalf of Quintech LLC

Last updated: April 2026

How We Govern Subprocessors

Quintech applies the following standards to every subprocessor relationship before and during engagement:

Due diligence: All subprocessors are assessed before onboarding for their data protection practices, security certifications, and compliance posture. We do not engage subprocessors who cannot demonstrate adequate protections. Contractual obligations: Every subprocessor is bound by a Data Processing Agreement (DPA) that imposes obligations equivalent to those Quintech holds under GDPR, UK GDPR, and applicable Indian data protection law. Data minimisation: Subprocessors receive only the minimum data necessary to perform their contracted function. They are contractually prohibited from using personal data for any purpose beyond delivering their service to Quintech. Transfer safeguards: Where subprocessors are located outside the EU, EEA, or UK, we ensure appropriate transfer mechanisms are in place -- including Standard Contractual Clauses (SCCs), UK IDTA, or adequacy decisions. Ongoing monitoring: We review subprocessor security postures and compliance annually, and conduct ad-hoc reviews following any significant incident or material change to their service. Client notification: We will notify active clients at least 14 days before adding or materially changing a subprocessor. Clients may object to new subprocessors in accordance with their Data Processing Agreement.

AI and LLM Providers

These providers power the AI features within the Quintech Software Factory.

All personal data passed to LLM providers is subject to PII obfuscation at Quintech's LLM gateway layer before transmission -- meaning identifiable personal data is redacted or anonymised prior to reaching any model provider. PII obfuscation is a structural control that applies to all LLM API calls regardless of which provider is used.

ProviderPurposeLocationTransfer BasisData Shared
AnthropicClaude model API for AI feature inference, agent orchestration, and content processingUnited StatesSCCs (EU) / IDTA (UK)Obfuscated prompts & outputs
OpenAIGPT model API -- optional routing for specific agent tasks where client-configuredUnited StatesSCCs (EU) / IDTA (UK)Obfuscated prompts & outputs
Google (Vertex AI / Gemini)Gemini model API and Vertex AI infrastructure for multi-model routingUnited States / EUSCCs (EU) / IDTA (UK) / Adequacy (EU region)Obfuscated prompts & outputs

Cloud Infrastructure and Hosting

These providers host the Quintech platform infrastructure, databases, and application services. They process personal data as part of storing and transmitting platform data on our behalf.

ProviderPurposeLocationTransfer BasisData Shared
DigitalOceanPrimary cloud hosting for platform application servers, databases, and storageUnited States / EU / UKSCCs (EU) / IDTA (UK)All platform data
Google Cloud PlatformSupplementary compute, managed Kubernetes (GKE), and cloud storage for specific workloadsUnited States / EUSCCs (EU) / IDTA (UK)Application & pipeline data
Bunny CDNContent delivery network for static assets, media, and platform performance optimisationGlobal (EU primary)SCCs (EU) / IDTA (UK)Static assets only -- no personal data
CloudflareDDoS protection, WAF, and DNS managementGlobal (EU primary)SCCs (EU) / IDTA (UK)IP addresses, request metadata

Data Storage and Database Services

These providers supply the database and data storage infrastructure that underpins the Quintech platform and client workloads.

ProviderPurposeLocationTransfer BasisData Shared
MongoDB AtlasPrimary document database for platform application data, client workspaces, and agent stateUnited States / EUSCCs (EU) / IDTA (UK)Application & user data

Observability, Monitoring, and Security

These providers supply the monitoring, alerting, and security tooling used by Quintech's Product & Engineering team to meet its managed services SLA commitments.

ProviderPurposeLocationTransfer BasisData Shared
DatadogFull-stack monitoring, APM, real user monitoring (RUM), log management, and alertingUnited StatesSCCs (EU) / IDTA (UK)Logs, metrics, traces -- no end-user PII
ZabbixNetwork and server infrastructure monitoring and threshold alertingSelf-hosted / On-premiseN/A -- self-hostedInfrastructure metrics only
PRTG / PaesslerNetwork performance monitoring and bandwidth telemetryGermany / EUAdequacy (EU)Network metadata only
SentryApplication error tracking and crash reporting for platform stability managementUnited StatesSCCs (EU) / IDTA (UK)Error logs, stack traces -- PII scrubbed

Payment Processing

These providers handle billing, subscription management, and payment processing on behalf of Quintech. Quintech does not store payment card data -- all card processing is handled directly by our payment processors.

ProviderPurposeLocationTransfer BasisData Shared
StripeSubscription billing, invoice generation, payment card processing, and revenue managementUnited States / EUSCCs (EU) / IDTA (UK)Billing contact, payment metadata

Communications and Notifications

These providers support Quintech's email, notification, and client communication infrastructure.

ProviderPurposeLocationTransfer BasisData Shared
ResendTransactional email delivery for platform notifications, incident alerts, and account communicationsUnited StatesSCCs (EU) / IDTA (UK)Email address, message content

Analytics and Marketing

These providers support Quintech's website analytics and marketing operations. They are used on the public-facing quin-tech.ai website only and are subject to cookie consent requirements. They do not process personal data within the platform itself.

ProviderPurposeLocationTransfer BasisData Shared
Google Analytics GA4Website traffic analytics and user behaviour measurement on quin-tech.aiUnited StatesSCCs (EU) / IDTA (UK)Pseudonymous usage data
HubSpotCRM, lead management, email marketing, and prospect engagement for opted-in contactsUnited StatesSCCs (EU) / IDTA (UK)Name, email, engagement data
LinkedIn Insight TagB2B campaign attribution and conversion tracking on quin-tech.aiUnited StatesSCCs (EU) / IDTA (UK)Pseudonymous ad interaction data
Google AdsCampaign conversion tracking and remarketing audience managementUnited StatesSCCs (EU) / IDTA (UK)Pseudonymous ad conversion data

Development Tools and Productivity

These providers support Quintech's engineering and delivery operations. They may process limited personal data (such as names and email addresses of platform users or Quintech team members) in the course of software development and project delivery.

ProviderPurposeLocationTransfer BasisData Shared
GitHub / MicrosoftCode repository, version control, and CI/CD pipeline managementUnited StatesSCCs (EU) / IDTA (UK)Developer identifiers, code metadata
LinearSprint planning, issue tracking, and engineering backlog managementUnited StatesSCCs (EU) / IDTA (UK)Team member names, task data
NotionInternal knowledge base, documentation, and SOW/SLA reference libraryUnited StatesSCCs (EU) / IDTA (UK)Team member names, doc content
VercelFrontend application hosting and edge deployment for platform UI componentsUnited States / EUSCCs (EU) / IDTA (UK)Request metadata, edge logs
FigmaUI/UX design tooling for platform and client product developmentUnited StatesSCCs (EU) / IDTA (UK)Design files, team identifiers

Subprocessor Change Process

Quintech reviews and updates its subprocessor list as our services evolve. The following process governs subprocessor changes:

New subprocessor: Quintech will notify active clients at least 14 days before a new subprocessor begins processing personal data. Notification will be sent by email to the designated data protection contact for the engagement.

Material change: Where an existing subprocessor materially changes its role, data location, or transfer mechanism, Quintech will notify clients within 14 days of Quintech becoming aware of the change.

Client objection: Clients who have signed a Data Processing Agreement with Quintech may object to a new or changed subprocessor within 14 days of notification. Quintech will work in good faith to accommodate valid objections; if no alternative can be agreed, the client may terminate the relevant services in accordance with the DPA.

Subprocessor removal: Where a subprocessor is removed or replaced, this registry will be updated within 30 days. Clients will be notified where the removal affects services they actively use.

Emergency changes: Where a subprocessor change is required urgently for security or legal compliance reasons, Quintech will notify clients as soon as practicable and provide a retrospective explanation.

To subscribe to subprocessor change notifications, email quin@quin-tech.ai with the subject line 'Subprocessor Updates'. You can also check the current version of this registry at quin-tech.ai/legal/subprocessors.

Contact Us

For questions about our subprocessors or data processing practices, please contact us at quin@quin-tech.ai.

FieldDetails
CompanyQuintech LLC
Emailquin@quin-tech.ai
Websitequin-tech.ai