Subprocessors

Firebird Solutions Limited · NZBN 9463794 · Auckland, New Zealand

Draft — pending final legal review. The effective date is set when this document is finalised. Feedback: [email protected].

Atamaia Subprocessors

Last updated: draft — effective date set on publication

This page lists the third parties that may process customer data on our behalf in delivering the hosted Atamaia service. It is referenced by our Privacy Policy and Data Processing Addendum.

DRAFT. Every row below must be confirmed against what is actually deployed before this page is published. A subprocessor list that omits a live provider is a breach of the DPA you are about to offer. Walk the deployment and the codebase — hosting, DNS, CDN, email, error monitoring, analytics, payments — and complete this table honestly.


What "subprocessor" means here

A subprocessor is a third party we engage that may access or store customer data in the course of providing the service to you. Providers that never touch customer data are not listed.

**AI model providers are listed separately, below the table — because they process Customer Content to perform the service you asked for (generating a response), rather than as our business-support subprocessors. You can exclude them entirely by pinning every model to one running on our own hardware. Embeddings for retrieval are generated on hardware we operate.

If we ever change that, the provider we adopt goes on this list and you get 30 days' notice before the change takes effect — the same commitment as any other subprocessor addition.

Where you configure an External Provider with your own credentials, that provider is your subprocessor, not ours — see Privacy Policy section 6.


Current subprocessors

Provider Purpose Data processed Location Notes
Stripe, Inc. Payment processing, subscription billing Name, email, billing address, transaction records, card data (held by Stripe, never by us) United States, global PCI-DSS Level 1. Under Stripe's own DPA and SCCs. Confirmed present — the platform has a Stripe webhook handler.
our own hardware Infrastructure hosting, compute, storage All customer data at rest Auckland, New Zealand ⚠️ Must be completed. If self-hosted on your own hardware, say so explicitly and describe the physical location and security.
our own mail infrastructure (mail.firebird.co.nz) Transactional email — verification, notices, alerts Email address, message content New Zealand ⚠️ Confirm. Something sends verification and alert email.
our own infrastructure (backups are age-encrypted and never leave our hardware) Offsite backup storage Encrypted backups of all customer data New Zealand ⚠️ Confirm. If backups go anywhere other than the primary host, it belongs here.
we use no third-party error-monitoring or performance-monitoring service Error and performance monitoring Request telemetry, stack traces, IP addresses; may incidentally capture content in error payloads New Zealand ⚠️ Confirm. Error monitoring frequently captures more than intended — check what is scrubbed.
Cloudflare, Inc. (DNS and edge proxy) DNS, TLS termination, DDoS protection IP addresses, request metadata Global edge ⚠️ Confirm. A CDN or proxy in front of the app is a subprocessor.
we use no third-party analytics Product analytics Usage events, IP address New Zealand ⚠️ Only if used. If you use none, state "we use no third-party analytics" — it is a genuine selling point.

Changes

We will give at least 30 days' notice before adding a subprocessor that will process Customer Content. Notice will be given by email to account administrators and by updating this page.

Business customers under our Data Processing Addendum may object to a new subprocessor on reasonable data-protection grounds within that notice period. If we cannot resolve the objection, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.

To receive notice of changes, email [email protected] and ask to be added to the subprocessor notification list.


Our commitments for every subprocessor

⚠️ These are present-tense warranties. They cannot be true of a provider not yet chosen, and five of the seven rows above are placeholders. Do not publish this page, or offer the DPA that points at it, until the table is complete and each contract or transfer mechanism actually exists.

  • a written contract imposing data protection obligations no less protective than those we owe you;
  • access limited to what is necessary for their function;
  • an appropriate transfer mechanism where they are outside New Zealand or outside the EEA/UK;
  • we remain liable to you for their performance.