Every third party that touches personal data in the Raidu customer relationship, and every one that deliberately does not.
This page is Annex III to the Raidu Data Processing Addendum and is incorporated into it by reference. It lists every sub-processor Raidu engages to process Customer Personal Data, and is maintained as that list changes.
The list is short for a structural reason. Raidu software is installed inside the customer’s own cloud account. Prompts, completions, governance decisions, and the signed audit log are created and stored there, encrypted with the customer’s own keys, and are never transmitted to Raidu. The model providers a customer routes traffic to are chosen and contracted by that customer, inside that customer’s environment, with Raidu no part of the chain.
What remains, and what this list covers, is the business layer around the product: the administrator managing a licence, the support ticket, the contract being signed. That is the only personal data Raidu holds on a customer’s behalf, and these are the vendors involved in holding it.
Each entity below is engaged under written data protection terms no less protective than those in the Data Processing Addendum. None of them receives Customer Content.
A short sub-processor list is only meaningful if you can see what it excludes and why. These are the third parties a reviewer would expect to find here, and the reason each one is absent.
Raidu gives at least 30 days' notice before a new sub-processor begins processing Customer Personal Data. Notice is given by updating this page and emailing subscribed addresses.
Customers may object on reasonable data protection grounds within the notice period, under section 7.4 of the Addendum.
Subscribe or object: privacy@raidu.com
This register is maintained by Ali Sarafzadeh, Privacy Lead and acting Data Protection Officer.