Subprocessors and data location
The categories of third party that process data on our behalf, the diligence before one is added, how you are notified of a change, and where data sits
On this page — 5 sections
No serious platform is built without third parties, and pretending otherwise is a worse answer than naming them. This article explains what a subprocessor is in our arrangement, the categories we rely on, the diligence applied before one is added, how you hear about a change, and how data location and cross-border transfer actually work rather than how a marketing page usually describes them.
What a subprocessor is, and what it is not
You are the controller of the data in your workspace. Theos Quantum Technologies Private Limited is the processor: we handle it on your instructions and for the purposes in your contract. A subprocessor is a third party we engage to process some of that data on our behalf — a hosting provider, a log store, a mail relay. Each one is bound by terms no weaker than our own commitments to you, and we remain accountable to you for what they do.
Three things are commonly mistaken for subprocessing and are not. A tool that never touches customer data is a vendor, not a subprocessor. An integration you configure, where data flows from your workspace to a system you control, is your processing rather than ours; Integrations, and where we fit covers that boundary. An identity provider you connect for single sign-on holds your directory, not our copy of it.
The categories we rely on
We keep the list short on purpose. Every addition widens the surface a customer has to assess, so a new subprocessor has to earn its place against the alternative of building or doing without. The provider column is filled from the live register rather than from this page, so that a documentation update can never lag the register.
| Category | Purpose | Data reached | Provider |
|---|---|---|---|
| Cloud infrastructure | Compute, storage, managed database and key management for the platform | All categories held in the control plane, encrypted at rest and in transit | [PLACEHOLDER: cloud infrastructure provider and region] |
| Observability and logging | Application logs, metrics and error traces for reliability and incident response | Service telemetry, request metadata, stack traces; inventory content excluded by log policy | [PLACEHOLDER: observability provider and data region] |
| Transactional email | Sign-in verification, alerts and report notifications | Work email, display name, message subject and body of the notification | [PLACEHOLDER: transactional email provider] |
| Support tooling | Ticketing and correspondence with your team | Contact details and whatever you choose to include in a ticket | [PLACEHOLDER: support and ticketing provider] |
| Payment processing | Invoicing, payment collection and tax calculation | Billing entity, billing contact, plan and invoice history; we never receive primary card numbers | [PLACEHOLDER: payment processor] |
| Content delivery and edge protection | Distribution of the application and defence against volumetric attack | Connection metadata and request paths at the edge | [PLACEHOLDER: CDN and edge protection provider] |
Categories we deliberately do not use
There is no advertising or marketing analytics platform with access to product data, no data broker or enrichment service, and no third-party model provider receiving customer inventory content. There is no AI chatbot on this site or in the product, so no conversational data leaves the platform. Contractors are not given standing access to customer data; where specialist work is required it happens under the same time-boxed, logged access path our own engineers use, described in Encryption and key handling.
Diligence before one is added
Adding a subprocessor is a decision with a written record, not a procurement convenience. The same sequence runs whether the candidate is a large platform or a small tool.
- 1
Justify the category
State which data would reach the provider and why the function cannot be delivered without it. A request that cannot name the minimum necessary data stops here.
- 2
Assess the security posture
Review of independent audit reports, penetration test summaries, breach history, subprocessor chain and incident notification terms. Findings are recorded against [PLACEHOLDER: vendor security assessment standard used].
- 3
Check the legal basis and location
Confirm processing locations, the transfer mechanism for each, retention terms, deletion commitments and audit rights before a contract is signed.
- 4
Sign data protection terms
A data processing agreement with confidentiality, security, subprocessing and deletion obligations no weaker than ours to you, plus breach notification within a defined window. Reference [PLACEHOLDER: our DPA version and effective date].
- 5
Constrain the integration
Least-privileged credentials, scoped API access, field-level filtering so only the named data reaches the provider, and log redaction verified by test rather than assumed.
- 6
Notify, then enable
The register is updated, notice runs, and only then does data begin to flow. Reassessment happens on the cadence in the Assurance Center.
How you hear about a change
A change to the register should never be something you discover. Notice is given before a new subprocessor begins processing customer data, not after.
- Advance notice. [PLACEHOLDER: subprocessor change notice period] before a new subprocessor begins processing, sent to the technical and legal contacts on your account.
- The dated register. Every addition, removal and change of purpose is recorded with its effective date in the Assurance Center, so a procurement review can see the history rather than the current snapshot.
- Announcement channel. Changes are also published in the Signal Log, which is subscribable; alert routing for your workspace is covered in Where alerts land.
- A right to object. If a proposed subprocessor is unacceptable to you, raise it within the notice period. We will look for an alternative, and where none exists the escalation and termination path is the one in Terms.
- Emergency substitution. If a subprocessor fails or is compromised, we may substitute at short notice to keep the service running, and will notify you within [PLACEHOLDER: emergency substitution notification window] with the reason.
Where data sits, and how it crosses a border
Data location is two questions that get merged into one. The first is where data is stored, which is a region choice. The second is where it can be accessed from, which is a support and engineering question and usually the one an assessor is actually asking. We answer both separately.
- Primary storage region
- [PLACEHOLDER: default storage region]. Workspace data, backups and generated reports are stored there.
- Alternative regions
- [PLACEHOLDER: additional regions available and the tier required]. Region is fixed at workspace creation; moving an existing workspace is a migration, not a setting.
- Access locations
- Engineering and support access originates from [PLACEHOLDER: countries from which support and engineering access occurs], under the time-boxed, logged access path.
- Transfer mechanism
- [PLACEHOLDER: transfer mechanism relied on for each corridor] — an adequacy finding where one applies, standard contractual clauses with a documented transfer assessment otherwise.
- Data localisation requirements
- Where a sector regulator requires in-country storage or processing, the position is [PLACEHOLDER: localisation commitments by jurisdiction]. See The Indian regulatory picture.
Two principles sit behind those entries. Data is stored in the region you choose and is not replicated outside it for convenience, performance or analytics. Access from another country is treated as a transfer with a named mechanism and a documented assessment, rather than as an internal matter because the same company is on both ends of it.
Regulated customers usually need this in a specific form. Financial entities in scope of DORA, which applies from 17 January 2025, maintain a register of information covering ICT third-party arrangements, including subcontracting chains and the locations of data storage and processing. The register in the Assurance Center is structured to populate those fields directly; DORA and financial-sector obligations maps the columns.
What to send a procurement team
The dated subprocessor register, the transfer assessment and the current control status are in the Assurance Center. The binding terms, including the subprocessing clause and the notice period, are in Privacy and Terms. If a questionnaire asks something none of those answer, send it to /contact rather than assuming the answer from this page.
More in Data & privacy