BriefVox
Startseite

BriefVox AI

Subprocessors Registry

Zuletzt aktualisiert: 2026-07-14

Für die gewählte Sprache gibt es noch keine eigene Rechtsübersetzung. Es wird die verfügbare Sprachversion angezeigt.

BriefVox AI Subprocessors and Vendors Registry

1. Purpose of this registry

This registry tracks who BriefVox AI entrusts or shares data with in the course of providing the service. The document must be updated whenever a vendor changes.

2. Registry

Vendor

Service

Data

Role

Location

DPA/SCC

Status

Google LLC

login and registration via Google (OAuth 2.0)

Google account identifier, email address, name from Google account

identity provider / independent controller

USA (transfer under standard contractual clauses, Art. 46 GDPR)

https://policies.google.com/privacy

active

Stripe

payments, invoices, subscriptions

payment data, email, transaction identifiers

processor / independent controller for certain services

Ireland (Stripe Payments Europe, Ltd.) and the United States (Stripe, Inc.); international transfers use the safeguards described in Stripe's DPA

https://stripe.com/legal/dpa

active

Backblaze B2 (Backblaze Inc.)

storage and infrastructure

source audio and video files, linked media imports, generated export files and related object metadata; transcript records remain in the Operator's PostgreSQL database

processor

European Union (Backblaze B2 EU Central, Amsterdam, Netherlands)

https://www.backblaze.com/company/dpa.html

active

Amazon Web Services (AWS Bedrock)

AI Notes generation (summaries, notes, translations) from transcript text; does not perform audio transcription — that runs locally at the Operator

transcript text sent as a prompt, AI Notes output, metadata (audio/video files are not shared with this provider)

processor / subprocessor

European Union (Stockholm, AWS eu-north-1)

https://aws.amazon.com/compliance/gdpr-center/

active

Resend (Resend, Inc.)

system notifications

email address, system message content

processor

United States; international transfers use the safeguards described in the provider's DPA

https://resend.com/legal/dpa

active

Vercel Inc.

hosting and delivery of the web application (frontend), CDN, request routing and — only after analytics consent — aggregate analytics and performance measurement; the backend (API, database, queues, transcription) runs on the Operator's own infrastructure, not on Vercel

technical connection data (IP address, request metadata), session cookies, and data entered in the browser in transit; after consent, visit and performance metrics; audio/video files and transcriptions are not stored on Vercel

processor

USA (transfer under standard contractual clauses, Art. 46 GDPR)

https://vercel.com/legal/dpa

active

Cloudflare, Inc.

secure API exposure through Cloudflare Tunnel, network routing, and traffic protection

IP address, connection and request metadata, and data transmitted through the tunnel in transit; Cloudflare is not used to store source media or transcripts

processor

global, including the United States (transfer safeguards are described in Cloudflare's DPA)

https://www.cloudflare.com/cloudflare-customer-dpa/

active

3. Vendor selection criteria

availability of a Data Processing Agreement (DPA),

whether data is processed within the EU/EEA,

whether encryption is applied,

data retention terms,

whether data is used for model training,

whether model training on client data can be disabled,

how data is deleted after processing,

whether the vendor holds security certifications or documentation.