Sub-processor Disclosure
Last updated: 24 July 2025
Kromatic uses a small number of carefully selected sub-processors to deliver the Krobar.ai service. Each sub-processor is bound by written agreement to meet or exceed the data-protection and security obligations in our Data-Processing Agreement (DPA) with customers.
We notify customers at least 30 days in advance of any new sub-processor so they may object on reasonable data-protection grounds. To receive change notifications, e-mail [email protected] with the subject line "Subscribe – sub-processor updates".
If your workspace is deleted, we instruct all subprocessors to erase Customer Data within 30 days; encrypted backups are retained 7 days; system logs ≤ 90 days, then anonymised.
⸻
Current authorised sub-processors
| Sub-processor | Purpose | Primary Processing Location(s) | Categories of Data | Transfer Mechanism | Security Highlights | DPA / Certifications | Date Added |
|---|---|---|---|---|---|---|---|
Heroku (Salesforce Inc.) | application platform and managed Postgres database hosting | United States (AWS us-east-1) | model structures, simulation parameters, user names & e-mail addresses, operational logs, encrypted backups (7-day retention) | EU–US Data Privacy Framework (DPF) & 2021 Standard Contractual Clauses (SCCs) incorporated in our DPA | AES-256 encryption at rest; TLS 1.2+ in transit; MFA-protected console access | View DPA | 01 Jun 2025 |
OpenAI OpCo, LLC (OpenAI Enterprise API) | large-language-model inference for natural-language features | United States | model prompts and parameters (no special-category data) retained ≤ 30 days for abuse monitoring | EU–US DPF & 2021 SCCs | AES-256 encryption at rest; TLS 1.2+ in transit; no model training on customer data | View DPA | 01 Jun 2025 |
Functional Software Inc. d/b/a Sentry | error monitoring and performance logging (PII automatically removed) | United States and EU data centres | anonymised stack traces, application metrics | 2021 SCCs | encryption at rest and in transit; role-based access; data purged after 90 days | View DPA | 01 Jun 2025 |
Mailchimp (Intuit Inc.) | onboarding & service e-mail delivery | United States | user names and e-mail addresses | EU–US Data Privacy Framework & SCCs | ISO 27001, SOC 2; TLS 1.2+ | View DPA | 07 Jun 2025 |
⸻
Questions or objections?
To object, contact our Data Protection Officer at [email protected] within 30 days of any change citing reasonable data-protection grounds. We will work with you in good faith to address concerns or propose an alternative arrangement.