Sub-processors
Reference document
This is niil's default sub-processor list, reflecting the EU-first reference deployment. The operator maintains the authoritative list for your instance (the actual hosting provider, AI processors, and payment/email providers in use); for the hosted niil service (niil.ai / app.niil.ai) the operator is Gradient Zero Deutschland GmbH (gzero.ai), and for a self-hosted deployment it is the organisation running the instance. It is the binding Annex 2 to the DPA.
Version 1.0
niil engages the following sub-processors to deliver the Services. Under the default Strict EU policy all inference is region-pinned to the EU, and hosting and primary data storage are EU-resident.
| Sub-processor | Purpose | Processing location | Transfer safeguard |
|---|---|---|---|
| EU IaaS provider | Platform hosting + primary data storage | EU (e.g. Germany) | EU/EEA — none required |
| EU object storage (e.g. Hetzner Object Storage) | Encrypted knowledge-base document content (only when enabled) | EU (e.g. Germany/Finland) | EU/EEA — ciphertext only |
| Microsoft (Azure OpenAI) | OpenAI model inference | Sweden (EU) | EU/EEA; ZDR contracted |
| Google Cloud (Vertex AI) | Anthropic / Google model inference | EU (e.g. Belgium) | EU/EEA; ZDR where supported |
| Mistral AI SAS | Mistral model inference | France (EU) | EU/EEA |
| Self-hosted model endpoint | Open-source model inference | Operator-controlled (EU) | EU/EEA |
| OpenRouter, Inc. | Model-routing broker to EU-pinned upstreams — engaged only when the operator enables it and the org selects the EU models or All models policy (see data protection & model routing) | US company; upstreams restricted to EU endpoints under EU models | SCCs (US); off by default |
| Stripe Payments Europe | Subscription billing (only if enabled) | EU | EU/EEA |
| Email provider | Transactional / verification email | EU | EU/EEA |
OpenRouter is off by default
OpenRouter is not engaged under the default Strict EU policy. It is only used if the operator enables it and an org admin chooses the EU models policy (OpenRouter restricted to EU-only upstreams) or the All models policy, which may route to non-EU providers. See No external vendors.
Zero Data Retention
ZDR is contracted with AI sub-processors and disclosed per model in the model picker. Where a provider offers a retention-opt-out signal, niil is designed to use it, so prompts and outputs are not retained beyond generation and are not used for model training. See Zero Data Retention for the precise wording.
Changes
Material additions or replacements are notified to customers at least 15 days in advance, with a right to reasoned objection (see DPA §5).