HostYourAI

Sub-processors

Third parties that may process customer data on our behalf, with purpose and jurisdiction. We notify customers in advance of changes.

Under our Data Processing Agreement (GDPR Art. 28.2), the customer authorises HostYourAI to engage the sub-processors listed below. We will notify customers in writing of any addition or replacement at least 30 days in advance; the customer has the right to object on reasonable grounds.

This list reflects the platform configuration on 2026-06-10. The authoritative version is always this page; we maintain a public changelog.

Active sub-processors

Sub-processorPurposeJurisdictionPersonal data processedNotes
Vast.ai, Inc. GPU compute capacity for LLM inference US (EU regions used by default) Inference traffic in transit, model weights at rest on rented GPU disk Default provider. Excluded when customer enables Sovereignty Mode.
RunPod, Inc. Alternate GPU compute capacity US (EU regions when available) Inference traffic in transit, model weights at rest on rented GPU disk Optional fallback. Excluded when customer enables Sovereignty Mode.
Hugging Face, SAS Source of open-weights model files (download to our GPU during deploy) FR / US None (model weights only — no customer data flows to HF) One-way: we pull, no telemetry.
Stripe Payments Europe, Ltd. Payment processing, invoicing, VAT calculation IE (EU) Name, email, company, billing address, VAT number, payment method (tokenised) Independent controller for payment data per Stripe DPA.
Google Ireland Ltd. (Workspace + SMTP) Transactional email delivery, support inbox IE (EU) Email address, message content of system emails SCC + DPA in place where US transfer applies.
Ploi.io (Hostnet B.V.) Server orchestration & deploy automation for our application servers NL (EU) None directly — SSH access to application servers under our control Operational tooling; no customer data egress.

Conditional sub-processors (only if you enable them)

Sub-processorWhen engagedJurisdictionData flow
OpenAI, L.L.C. Only if you use an OpenAI BYOK instance or pick an OpenAI model via upstream US Your prompts/responses go to OpenAI under your OpenAI agreement, not ours. We pass through, do not log content.
Anthropic, P.B.C. Only if you configure a Claude BYOK upstream US Passthrough under your Anthropic agreement.
Google LLC (Gemini API) Only if you enable Gemini as the conversational backend on an agent US Passthrough; we configure but do not retain content.
Mistral AI Only if upstream routing to Mistral La Plateforme is enabled (off by default; excluded in Sovereignty Mode pending Mistral sub-processor verification) FR (own DCs) Passthrough.

Planned (announced for transparency, not yet active)

Sub-processorPurposeJurisdictionStatus
Scaleway SASEU-sovereign GPU compute (Sovereignty Mode default)FRIntegration in progress.
OVHcloudEU-sovereign GPU compute (alternate)FREvaluation.
Hetzner Online GmbHEU-sovereign GPU compute (DE region)DEEvaluation.

How to be notified of changes

Material changes are emailed to the billing contact on each account and posted in the changelog below. To subscribe an additional address, write to security@hostyourai.com.

Changelog