Candli Subprocessors
Enlightware GmbH uses the following direct and downstream subprocessors where necessary to provide, secure and support Candli. The exact data processed depends on the Candli features used by the Customer.
Enlightware requires subprocessors to provide appropriate data-protection and security safeguards. AI inference is restricted to approved providers and configurations with zero retention of submitted inference data and appropriate safeguards for international transfers. For organisations configured for EEA AI data processing, AI API payloads are restricted to processing within the European Union or European Economic Area.
The provider documentation links below point to provider-maintained subprocessor, DPA, privacy or trust documentation. These sources describe further downstream processing where available. Where a provider does not publish a complete downstream list, its available processing documentation is linked instead. Enlightware does not duplicate changing downstream lists maintained by those providers on this page.
AI inference subprocessors process Customer data only when optional AI-powered features are enabled and used.
| Provider | Relationship | Purpose | Data potentially processed | Processing region | Provider processing documentation |
|---|---|---|---|---|---|
| Hetzner Online GmbH | Direct | Hosting infrastructure | Account, project, asset, application and technical data | EEA | Subcontractors |
| Cloudflare, Inc. | Direct | Network security, reverse proxy, content delivery and bot protection | IP addresses, request metadata and cacheable content | Global | Subprocessors |
| Sand Dune Mail Ltd (SMTP2GO) | Direct | Transactional email delivery | Recipient addresses and message information | EEA (EU-hosted account) | Subprocessors |
| OpenRouter, Inc. | Direct | AI inference routing | Input data, relevant context, model outputs and technical metadata | Global, or EU/EEA-only for organisations configured for EEA AI data processing | Authorized subprocessors, DPA |
| DeepInfra | Downstream via OpenRouter | AI inference | Input data, relevant context, model outputs and technical metadata | United States | Subprocessors |
| NextBit | Downstream via OpenRouter | AI inference | Input data, relevant context, model outputs and technical metadata | Spain (EEA) | DPA |
| Google Vertex | Downstream via OpenRouter | AI inference | Input data, relevant context, model outputs and technical metadata | United States / EEA | Google Cloud subprocessors |
| Together AI | Downstream via OpenRouter | AI inference | Input data, relevant context, model outputs and technical metadata | United States | Trust Center |
| Fireworks AI | Downstream via OpenRouter | AI inference | Input data, relevant context, model outputs and technical metadata | United States | Trust Center |
| CoreWeave | Downstream via OpenRouter | AI inference | Input data, relevant context, model outputs and technical metadata | United States | Subprocessors |
| DigitalOcean | Downstream via OpenRouter | AI inference | Input data, relevant context, model outputs and technical metadata | Multiple regions worldwide; model-dependent | Subprocessors |
| Modal | Downstream via OpenRouter | AI inference | Input data, relevant context, model outputs and technical metadata | United States | Subprocessors |
| Nebius Token Factory | Downstream via OpenRouter | AI inference | Input data, relevant context, model outputs and technical metadata | EU / United States / Israel, model-dependent | Subprocessors |
| Inceptron AB | Downstream via OpenRouter | AI inference | Input data, relevant context, model outputs and technical metadata | Finland / France (EEA) | Data & privacy policy (DPA available from provider) |
External identity providers
External identity providers selected or configured by a Customer or user, such as Google, Microsoft or Edulog, may exchange the information required to authenticate the user with Candli. They are not listed above unless Enlightware engages them to process Personal Data on its behalf.
Changes
Enlightware maintains this page to reflect its current approved processing chain. The set of approved AI inference providers may change as models, providers, regional requirements and processing arrangements evolve. Provider-maintained documentation linked above should be consulted for further downstream processing. Changes are handled in accordance with the Candli Data Processing Agreement and applicable data-protection law.