Legal · Subprocessors
Subprocessors
Last updated · 23 September 2026 · v1.5 · Updated whenever the list changes
Palanor relies on the following subprocessors to operate the Enterprise Intelligence Platform. Each is contractually bound to confidentiality, security, and to processing data only as instructed by Palanor. Customers can subscribe to subprocessor updates at privacy@palanor.com and will receive at least 30 days’ notice of any change.
| Subprocessor | Service | Location | Data |
|---|---|---|---|
| Vercel, Inc. | Application hosting (Next.js) | USA · AWS us-east | App logs, request metadata |
| Supabase, Inc. | Postgres database, auth, object storage | USA · AWS us-east | All Customer Data |
| Anthropic, PBC | LLM inference (Claude) — the primary US model, used for all interactive and customer-context workloads (Numen chat + personalization, briefings, onboarding, and — for US-only organizations — news ranking and scenario narratives) | USA | Prompts and contextual data passed to model calls; not retained for training under our subprocessor agreement |
| OpenRouter, Inc. | LLM API gateway — the resilient front door that routes Palanor’s default-key model calls to the selected provider (Anthropic and others). A pass-through router; does not store prompt content. | USA | Prompts and contextual data in transit to the selected model provider; not retained for training. Bypassed entirely for BYOLLM customers (their key routes model-provider-direct). |
| Zhipu AI (GLM / z.ai), via OpenRouter | Cost-efficient LLM inference for high-volume, public-source workloads — news synthesis, earnings-call sentiment (Discourse), and Council research agents. For organizations not configured for US-only processing, also news ranking and scenario narratives. | China (model provider) · routed via OpenRouter | Public source content for synthesis/Discourse/Council. Business-profile / scenario context for ranking + scenarios only when the organization is not on US-only processing — see note below. Not retained for training. |
| Resend | Transactional email | USA | Outbound email content + recipient address |
| Stripe, Inc. | Payments (Stripe Atlas, billing) | USA + EU | Billing identifiers, payment method (tokenized) |
| OpenAI, LLC | Text embeddings; gpt-image-1 for news-image generation when no public-domain match exists | USA | Text passed to the embeddings + image endpoints; not retained for training under our subprocessor agreement |
| ElevenLabs, Inc. | Text-to-speech (Numen voice reader) | USA | Text passed to the synthesis endpoint to generate audio; not retained for training |
| Cloudflare, Inc. | DNS, domain registrar (palanor.com, .ai, .org, .net, .io, .info, .co, .dev, .app), WAF and CDN at the edge, and R2 object storage holding the archived platform log drain | USA · global edge | DNS queries and edge request metadata. R2 stores gzipped platform logs (edge, database, authentication and function logs) on a rolling retention window; these logs can contain user identifiers and email addresses. No customer scenario, signal or briefing content is stored in R2. |
| Marketaux, s.r.o. | Financial news aggregation across 30+ publishers; entity-tagged, sentiment-scored feed used as a source of raw articles for Palanor synthesis | EU (Czech Republic) | No Customer Personal Data sent; we pull their published article metadata (titles, summaries, source URLs, images, entity tags) and synthesize on our side. Marketaux Standard tier license explicitly permits derivative LLM summaries with source attribution. |
| X Corp. | (1) Public-post outbound: posting Palanor news + Council content to the @palanor X account via OAuth 1.0a. (2) Public-post inbound: recent-search engagement context captured at article-publish time, displayed in the “On X right now” widget per X Developer Agreement display requirements. | USA · global | No Customer Personal Data sent. Outbound posts are Palanor-authored content. Inbound captures only the public-post metadata X already publishes openly — author handle, body, engagement counts, timestamp. Snapshotted per article; not re-fetched live. |
| Google LLC (Google Cloud / Vertex AI) | Failover LLM inference for Anthropic models, and the Gemini model used by Council research agents | USA | Prompts and contextual data passed to model calls; not retained for training |
| Voyage AI | Text embeddings powering platform search and signal retrieval | USA | Customer content submitted to the embeddings endpoint; not retained for training |
| Twilio Inc. | Outbound SMS for operational alerting | USA | Phone numbers of Palanor operations personnel. No customer personal data. |
| Apollo.io | Enrichment of business-contact records held in Palanor’s internal CRM | USA | Business-contact personal data — name, work email address, LinkedIn URL — sent outbound for matching. Applies to Palanor’s own prospect records, not to platform Customer Data. |
| People Data Labs | Alternate provider for the same CRM enrichment function | USA | Same fields as above. Only one enrichment provider is active at a time. |
| Calendly LLC | Embedded scheduling on designated Palanor web pages | USA | Name and email address entered by a visitor into the scheduling widget |
| Svix, Inc. | Cryptographic signature verification for inbound email webhooks | USA | Verifies the integrity of payloads that may contain sender email addresses; does not retain content |
| NewsAPI.ai (Event Registry) | News article ingestion for the editorial wire | EU (Slovenia) | No customer personal data. Published article metadata only. |
| Quiver Quantitative | Legislative trading-disclosure and patent signal data | USA | No customer personal data. Public disclosure filings only. |
| SerpAPI | Google Trends search-interest retrieval for signal construction | USA | No customer personal data. Public search-interest indices only. |
| Artificial Analysis | Independent model capability and pricing benchmarks used to compute a published index | Australia | No customer personal data. Public benchmark data only. |
| GitHub, Inc. (Microsoft) | Source-code hosting, CI, static analysis, and public repository signal data | USA | Palanor source code and change history. No Customer Data. |
| Slack Technologies (Salesforce) | Internal operational alerting and editorial coordination | USA | Internal operational messages. No Customer Data. |
| Meta Platforms · LinkedIn · Bluesky · Threads · Reddit | Publication of Palanor-authored content to its own social accounts, and ingestion of public posts | USA | No customer personal data. Outbound posts are Palanor-authored; inbound is public post metadata. |
Public data sources. Palanor additionally reads from public, credential-free government and open-data endpoints to construct signals — among them SEC EDGAR, the Bureau of Labor Statistics, the U.S. Treasury, the Federal Register, the Federal Reserve, USAspending, the World Bank, the OECD, openFDA, ClinicalTrials.gov, arXiv and Wikimedia. These are read-only retrievals of published data. No Palanor customer data is transmitted to them, and they are not subprocessors of customer personal data.
US-only processing. Organizations with data-residency or regulatory requirements can be configured for US-only LLM processing, in which case all inference that touches their contextual data — including news ranking and scenario narratives — runs on a US Anthropic model and never routes to a non-US provider. For full control, BYOLLM lets a customer supply their own model-provider key (Anthropic, Azure OpenAI); all of that organization’s inference then routes provider-direct under the customer’s own account, bypassing Palanor’s default providers and OpenRouter entirely. Contact privacy@palanor.com to enable either.
All subprocessor transfers outside the EEA are covered by EU Standard Contractual Clauses (Module Two, Controller to Processor) and the UK International Data Transfer Addendum. Subprocessor data processing agreements are available on request via privacy@palanor.com.