Subprocessors
Last updated 9 August 2026
The third parties that may process personal data on our behalf in order to deliver the service, and what each one is used for.
Current subprocessors
| Category | Purpose | Data processed |
|---|---|---|
| Model provider | Generating replies, rewriting queries, classification and validation | The customer's question and the retrieved context for that turn |
| Embedding provider | Turning knowledge chunks and queries into vectors | Your documentation text and query text |
| Reranking provider | Ordering retrieval candidates by relevance (optional) | Query text and candidate chunk text |
| Managed database | Primary data store for all workspace data | All workspace data |
| Cloud hosting | Running the application and API | All data in transit and at rest |
| Error monitoring | Capturing application exceptions | Diagnostic metadata; secrets are redacted |
| Email delivery | Transactional mail — verification, password reset, escalation notices | Recipient address and message content |
| Payment processing | Subscriptions and invoicing | Billing contact and payment details; we never store card numbers |
Notice of changes
We give at least 30 days’ notice before adding or replacing a subprocessor. To receive that notice, email privacy@zealoop.com and ask to be added to the list.
You may object on reasonable data-protection grounds. If we cannot resolve the objection, you may terminate the affected part of the service without penalty, as set out in the DPA, section 6.
Model providers, specifically
Sending a question and its retrieved context to a model provider is inherent to generating an answer and cannot be switched off while the agent is in use. We engage providers under terms that prohibit training on data submitted through their APIs. If your jurisdiction constrains where inference may take place, tell us before you deploy — it determines which providers we can use for your workspace.