Trust Center
Subprocessors
A subprocessor is a trusted third-party provider that processes personal data for ASUME while ASUME is processing personal data on behalf of a customer.
ASUME relies on subprocessors to run, secure, support, and improve the product. This page explains how we choose them, the safeguards we put in place, and how customers can raise concerns. The formal, itemised list of providers lives in the Subprocessor List.
Last updated: 8 September 2026
What is a subprocessor?
A subprocessor is a third-party provider that processes personal data for ASUME when ASUME is processing personal data on behalf of a customer.
For example, if ASUME uses a cloud hosting provider to host customer workspace data, that provider may be a subprocessor. If ASUME uses an AI model provider to process prompts or workspace content as part of a customer-requested feature, that provider may also be a subprocessor.
Not every third-party provider is a subprocessor. Some providers act as independent controllers, depending on the context. Payment providers, professional advisers, and public authorities, for example, may process some information for their own legal or operational purposes.
Why ASUME uses subprocessors
ASUME uses subprocessors so it can provide a reliable, secure, and scalable product. They help with the parts of the service that are most efficient to run on specialised infrastructure rather than to build from scratch.
In practice, subprocessors may support:
- hosting and infrastructure;
- database and storage services;
- authentication and access control;
- AI model inference and related infrastructure;
- email delivery and transactional messages;
- logging, monitoring, and error detection;
- security, abuse prevention, and incident response;
- analytics and product performance;
- support, onboarding, and customer communication;
- billing and subscription administration.
ASUME aims to use subprocessors only where they are needed to provide, secure, support, or improve the service.
How we choose subprocessors
Before relying on a material subprocessor, ASUME considers whether the provider is suitable for the role it performs. The review is proportionate to the role, risk, and maturity of the provider.
Depending on the provider and the nature of the processing, that review may look at:
- the type of data processed;
- the purpose of processing;
- the processing location;
- the provider's security practices;
- the provider's privacy and data protection terms;
- confidentiality commitments;
- data retention and deletion practices;
- international transfer safeguards;
- incident notification commitments;
- the ability to support ASUME's obligations to customers.
Contractual safeguards
Where a provider acts as a subprocessor, ASUME aims to have a written agreement in place with data protection obligations appropriate to the services provided.
Those obligations may include commitments relating to confidentiality, security measures, processing only for agreed purposes, assistance with data protection obligations, personal data breach notification, deletion or return of data, the use of further subprocessors, international transfer safeguards, and audit or information rights where appropriate.
Where ASUME acts as a processor for a customer, subprocessor terms are governed by the applicable Data Processing Agreement.
AI and model providers
ASUME may use AI model providers or inference infrastructure providers to generate summaries, classifications, matches, recommendations, assumptions, explanations, and other AI-assisted outputs.
Where these providers process personal data on behalf of ASUME customers, they are treated as subprocessors and listed in the Subprocessor List.
ASUME does not use Customer Data to train third-party foundation models, and does not make Customer Data available to other customers, unless the customer expressly agrees in writing. We aim to limit the data sent to AI and infrastructure providers to what is necessary for the requested functionality.
International transfers
Some subprocessors may process personal data outside the European Economic Area.
Where personal data is transferred outside the European Economic Area to a country that does not provide an adequate level of protection, ASUME uses appropriate safeguards where required, such as Standard Contractual Clauses, transfer impact assessments, and supplementary measures where appropriate.
Subprocessor changes
ASUME may update its subprocessors as the service, infrastructure, providers, and customer needs evolve.
Where required by the Data Processing Agreement, ASUME will notify customers of intended additions or replacements of material subprocessors, and give customers an opportunity to object on reasonable data protection grounds.
Customer objection process
Customers with objection rights under the applicable Data Processing Agreement may object to a new material subprocessor on reasonable data protection grounds.
An objection should be sent to privacy@asume.ai and should include the customer's legal name, the relevant workspace or agreement, the subprocessor concerned, the specific data protection grounds for the objection, and any proposed mitigation.
ASUME will review objections in good faith and may provide additional information, propose mitigation, disable the affected feature, or allow termination of the affected service where required by the Data Processing Agreement.
Where to find the legal list
The current legal list of subprocessors is maintained in the Subprocessor List. It includes each provider's name, service category, purpose, the types of personal data processed, the processing location, and the transfer mechanism where relevant.
Contact
For questions about subprocessors, contact privacy@asume.ai. For security questions, contact security@asume.ai.
Full company details are available in our Legal Notice.