1About This List
This list is actively maintained. Every time we add or replace a subprocessor we update this page and the "Last updated" date. Business customers can subscribe to change notifications — see "Notice and Objection" below — and we email subscribers before a change takes effect.
A subprocessor is a third party engaged by Neox that has access to personal data while we process it on behalf of a customer. For the purposes of GDPR Article 28 these are our sub-processors, and this page is the list we disclose to customers under Article 28(2).
The list excludes vendors that supply tooling without touching personal data, and model providers you choose and connect to yourself in BYOK mode — in that mode requests never pass through our servers and your relationship with the provider is direct.
2Current Subprocessors
| Category | Purpose | Data categories |
|---|---|---|
| Cloud hosting and compute | Runs the website, APIs, gateway, database, and background jobs | Account identifiers, IP addresses, request metadata, technical logs, account and subscription records |
| Edge network and distribution | DNS, CDN and protection; human verification on sign-up and password reset; client release distribution | IP addresses, request metadata, access logs |
| Transactional email delivery | Verification, billing, and service notices | Email address, name/display name, message content, delivery status |
| Payment processing | Subscription and balance charges, receipts, and refunds | Name, email, billing address, payment credential tokens, transaction records |
| Upstream AI model providers | Perform inference via our gateway for subscriptions and the Neox Platform API, including model providers and their authorized resellers and aggregators, some located outside the United States (including in China) (in BYOK mode your device connects directly, bypassing us) | Prompt and file content (processed in transit), model output, request metadata |
| Speech and search services | Text-to-speech included in subscriptions; web search performed by the agent | Text to be spoken; search queries |
| Mobile push | Sending notifications to your phone | Push token, notification title and summary |
The "Data categories" column describes the widest scope a provider may encounter in performing its function, not what it necessarily retains. We limit what is passed to each subprocessor on a need-to-know basis.
We disclose by category rather than naming each provider on a public page. Business customers who need the specific list - for a DPA or a vendor assessment - can request it at support@neox-dev.com, and we will add you to the change-notice list at the same time. On model providers: in subscription mode our gateway forwards requests to the upstream model provider. When you bring your own key, requests go from your device straight to the provider you chose - they do not pass through our servers, and your contract is directly with them.
3How We Vet Subprocessors
Before engaging a subprocessor we assess its level of data protection. The assessment considers:
- security posture — independent audit evidence (such as SOC 2 Type II or ISO/IEC 27001) and encryption at rest and in transit;
- data protection commitments — willingness to sign a data processing agreement meeting GDPR Article 28(3), and availability of Standard Contractual Clauses;
- data residency and transfers — processing locations, region selection, and the lawful basis for any cross-border transfer;
- retention and deletion — default retention periods, deletion on instruction, and return or destruction of data on termination;
- incident response — notification timelines for security events and obligations to cooperate with investigations;
- onward subcontracting — transparency and control over the provider's own subprocessors;
- business continuity — availability record, backup strategy, and portability.
Our relationship with each subprocessor is governed by its terms of service and data processing terms. We prefer providers that offer data processing terms; some providers — including most upstream model providers — work only on their published standard terms, and for those providers the applicable data protection commitments are the ones in their published terms.
We periodically re-review existing subprocessors' terms and security posture, and promptly following any material security incident or change to their terms.
4Notice and Objection
Under the Data Processing Addendum you give us general authorization to use subprocessors. In exchange we commit to notice and an opportunity to object before any change:
- 30 days' notice
- At least 30 calendar days before adding or replacing a subprocessor, we update this page and email customers subscribed to notifications, identifying the provider, its purpose, and its processing location.
- Right to object
- You may object in writing within 30 days of the notice on reasonable data protection grounds, setting out your specific concern.
- Our response
- On receiving an objection we will discuss it with you in good faith and make reasonable efforts to offer an alternative — for example adjusting the data flow, limiting what the provider can access, or using a different provider.
- If it cannot be resolved
- If we cannot offer an arrangement acceptable to you within a reasonable period, you may terminate the affected subscription and we will refund fees paid for the unused portion of the term. This is the sole remedy in that situation.
- Emergency replacement
- Where a subprocessor fails, discontinues service, or presents a security risk requiring urgent replacement, we may make the change first to maintain service and notify you as soon as practicable afterwards. Your right to object is not lost.
To subscribe to change notifications, email support@neox-dev.com with "Subscribe to subprocessor notifications" in the subject line and the address you want notices sent to. You can unsubscribe the same way at any time.
5International Transfers
Some subprocessors may process data outside your country or region. Where personal data is transferred out of the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on one or more of the following safeguards:
- Standard Contractual Clauses adopted by the European Commission, together with the UK International Data Transfer Addendum (IDTA / UK Addendum);
- an adequacy decision of the European Commission, or its UK or Swiss equivalent;
- transfer impact assessments where required, and the supplementary technical and organizational measures they identify (such as transport encryption and minimized access).
Copies of the applicable transfer mechanisms are available to business customers on request.
6Questions
For questions about this list, or to request further compliance documentation about a particular subprocessor, contact support@neox-dev.com.
Read this list alongside the Privacy Policy and the Data Processing Addendum. If this list conflicts with the Data Processing Addendum on subprocessor matters, the Data Processing Addendum prevails.

