Skip to content
Theos Quantum Θ mark
Data & privacy

Subprocessors and data location

The categories of third party that process data on our behalf, the diligence before one is added, how you are notified of a change, and where data sits

Reviewed 24 Jul 2026 6 min read
On this page — 5 sections

No serious platform is built without third parties, and pretending otherwise is a worse answer than naming them. This article explains what a subprocessor is in our arrangement, the categories we rely on, the diligence applied before one is added, how you hear about a change, and how data location and cross-border transfer actually work rather than how a marketing page usually describes them.

What a subprocessor is, and what it is not

You are the controller of the data in your workspace. Theos Quantum Technologies Private Limited is the processor: we handle it on your instructions and for the purposes in your contract. A subprocessor is a third party we engage to process some of that data on our behalf — a hosting provider, a log store, a mail relay. Each one is bound by terms no weaker than our own commitments to you, and we remain accountable to you for what they do.

Three things are commonly mistaken for subprocessing and are not. A tool that never touches customer data is a vendor, not a subprocessor. An integration you configure, where data flows from your workspace to a system you control, is your processing rather than ours; Integrations, and where we fit covers that boundary. An identity provider you connect for single sign-on holds your directory, not our copy of it.

The categories we rely on

We keep the list short on purpose. Every addition widens the surface a customer has to assess, so a new subprocessor has to earn its place against the alternative of building or doing without. The provider column is filled from the live register rather than from this page, so that a documentation update can never lag the register.

CategoryPurposeData reachedProvider
Cloud infrastructureCompute, storage, managed database and key management for the platformAll categories held in the control plane, encrypted at rest and in transit[PLACEHOLDER: cloud infrastructure provider and region]
Observability and loggingApplication logs, metrics and error traces for reliability and incident responseService telemetry, request metadata, stack traces; inventory content excluded by log policy[PLACEHOLDER: observability provider and data region]
Transactional emailSign-in verification, alerts and report notificationsWork email, display name, message subject and body of the notification[PLACEHOLDER: transactional email provider]
Support toolingTicketing and correspondence with your teamContact details and whatever you choose to include in a ticket[PLACEHOLDER: support and ticketing provider]
Payment processingInvoicing, payment collection and tax calculationBilling entity, billing contact, plan and invoice history; we never receive primary card numbers[PLACEHOLDER: payment processor]
Content delivery and edge protectionDistribution of the application and defence against volumetric attackConnection metadata and request paths at the edge[PLACEHOLDER: CDN and edge protection provider]
The authoritative, dated register lives in the [Assurance Center](/assurance). Contractual terms governing subprocessing are in [Privacy](/legal/privacy).

Categories we deliberately do not use

There is no advertising or marketing analytics platform with access to product data, no data broker or enrichment service, and no third-party model provider receiving customer inventory content. There is no AI chatbot on this site or in the product, so no conversational data leaves the platform. Contractors are not given standing access to customer data; where specialist work is required it happens under the same time-boxed, logged access path our own engineers use, described in Encryption and key handling.

Diligence before one is added

Adding a subprocessor is a decision with a written record, not a procurement convenience. The same sequence runs whether the candidate is a large platform or a small tool.

  1. 1

    Justify the category

    State which data would reach the provider and why the function cannot be delivered without it. A request that cannot name the minimum necessary data stops here.

  2. 2

    Assess the security posture

    Review of independent audit reports, penetration test summaries, breach history, subprocessor chain and incident notification terms. Findings are recorded against [PLACEHOLDER: vendor security assessment standard used].

  3. 3

    Check the legal basis and location

    Confirm processing locations, the transfer mechanism for each, retention terms, deletion commitments and audit rights before a contract is signed.

  4. 4

    Sign data protection terms

    A data processing agreement with confidentiality, security, subprocessing and deletion obligations no weaker than ours to you, plus breach notification within a defined window. Reference [PLACEHOLDER: our DPA version and effective date].

  5. 5

    Constrain the integration

    Least-privileged credentials, scoped API access, field-level filtering so only the named data reaches the provider, and log redaction verified by test rather than assumed.

  6. 6

    Notify, then enable

    The register is updated, notice runs, and only then does data begin to flow. Reassessment happens on the cadence in the Assurance Center.

How you hear about a change

A change to the register should never be something you discover. Notice is given before a new subprocessor begins processing customer data, not after.

  • Advance notice. [PLACEHOLDER: subprocessor change notice period] before a new subprocessor begins processing, sent to the technical and legal contacts on your account.
  • The dated register. Every addition, removal and change of purpose is recorded with its effective date in the Assurance Center, so a procurement review can see the history rather than the current snapshot.
  • Announcement channel. Changes are also published in the Signal Log, which is subscribable; alert routing for your workspace is covered in Where alerts land.
  • A right to object. If a proposed subprocessor is unacceptable to you, raise it within the notice period. We will look for an alternative, and where none exists the escalation and termination path is the one in Terms.
  • Emergency substitution. If a subprocessor fails or is compromised, we may substitute at short notice to keep the service running, and will notify you within [PLACEHOLDER: emergency substitution notification window] with the reason.

Where data sits, and how it crosses a border

Data location is two questions that get merged into one. The first is where data is stored, which is a region choice. The second is where it can be accessed from, which is a support and engineering question and usually the one an assessor is actually asking. We answer both separately.

Primary storage region
[PLACEHOLDER: default storage region]. Workspace data, backups and generated reports are stored there.
Alternative regions
[PLACEHOLDER: additional regions available and the tier required]. Region is fixed at workspace creation; moving an existing workspace is a migration, not a setting.
Access locations
Engineering and support access originates from [PLACEHOLDER: countries from which support and engineering access occurs], under the time-boxed, logged access path.
Transfer mechanism
[PLACEHOLDER: transfer mechanism relied on for each corridor] — an adequacy finding where one applies, standard contractual clauses with a documented transfer assessment otherwise.
Data localisation requirements
Where a sector regulator requires in-country storage or processing, the position is [PLACEHOLDER: localisation commitments by jurisdiction]. See The Indian regulatory picture.

Two principles sit behind those entries. Data is stored in the region you choose and is not replicated outside it for convenience, performance or analytics. Access from another country is treated as a transfer with a named mechanism and a documented assessment, rather than as an internal matter because the same company is on both ends of it.

Regulated customers usually need this in a specific form. Financial entities in scope of DORA, which applies from 17 January 2025, maintain a register of information covering ICT third-party arrangements, including subcontracting chains and the locations of data storage and processing. The register in the Assurance Center is structured to populate those fields directly; DORA and financial-sector obligations maps the columns.

What to send a procurement team

The dated subprocessor register, the transfer assessment and the current control status are in the Assurance Center. The binding terms, including the subprocessing clause and the notice period, are in Privacy and Terms. If a questionnaire asks something none of those answer, send it to /contact rather than assuming the answer from this page.

The live, dated list of subprocessors, their regions and their purposes is maintained in the Assurance Center alongside our control and audit status.See the current register