Sub-processors
Our Privacy Policy says we share data only with processors who need it to run the service. This page names them, says what each one handles, and commits to 30 days notice before we add another.
Key points at a glance
A summary for orientation only — the full policy below is what actually governs.
Named, not just categorised
The table below names each provider, its purpose and where it processes.
All under contract
Every sub-processor is bound by a data-processing agreement before it receives anything.
Transfers are safeguarded
Data leaving the UK or EEA moves under Standard Contractual Clauses or an adequacy decision.
30 days notice of changes
New sub-processors are published here before they start processing.
What a sub-processor is
A sub-processor is a third party that processes personal data on our behalf, under our instructions, to deliver part of the service. Under UK and EU GDPR we are the controller and they are processors engaged by us; under India's DPDP Act they are Data Processors and we remain the Data Fiduciary.
Either way the responsibility stays ours. Engaging a provider does not transfer our obligations to you.
Before any provider is engaged
- A data processing agreement is in place, with confidentiality and security terms at least as protective as those in our own Privacy Policy.
- They receive the minimum data needed for their function, and nothing beyond it.
- They may not use it for their own purposes, and may not sell it.
- Where data leaves the UK or EEA, transfers rely on Standard Contractual Clauses or an adequacy decision.
- We assess their security posture, breach-notification commitments and sub-processing chain first.
Categories we engage
Rather than pin this page to vendor names that change, here is what each category receives. The current vendor in each category is available on request to privacy@aitoolsay.com, and we answer that within five business days.
AI model providers
Processes: the prompt you submit, for the single request that produces your result.
Retention by us: none — prompts are not persisted on our side.
Note: only the provider whose model powers the specific tool you used receives your input. Each operates under its own API terms, and their enterprise API tiers do not train on submitted data.
Hosting and infrastructure
Processes: everything the application stores — account records where you have one, orders, submissions, and server logs.
Retention: logs rotate within 30 days.
Content delivery and DNS
Processes: IP address and request metadata, in transit, for routing, caching and abuse mitigation.
Payment processors
Processes: your payment details, taken directly by them. We never see or store a full card number, CVV or bank credential.
We retain: the transaction record — amount, currency, date, product, last four digits, gateway reference — because tax law requires it.
Email delivery
Processes: your email address and message content, for transactional mail and, if you subscribed, the newsletter.
Analytics
Processes: aggregate page and tool usage, with IP anonymisation enabled.
Note: loaded only after you grant analytics consent. Refuse, and nothing in this category runs at all.
Advertising partners
Processes: impression and click measurement on ad-supported pages.
Note: opt-in only, and named in the consent banner at the time.
Error monitoring
Processes: stack traces, request URL and status. Payloads are scrubbed of personal data before transmission.
What is never shared
- We do not sell, rent or trade personal data with anyone, sub-processor or otherwise.
- We do not share data for a provider's own marketing purposes.
- We do not enrich your data by combining it with third-party datasets.
Changes to this list
New sub-processors are published here at least 30 days before they begin processing. If you have a data processing agreement with us and object to an addition on reasonable data-protection grounds, tell us within that window and we will work with you on an alternative or, failing that, allow you to terminate the affected service without penalty.
To be notified of changes, email privacy@aitoolsay.com and ask to be added to the sub-processor notification list.
Requesting a DPA
If you are a business customer needing a signed data processing agreement, or a completed security questionnaire, write to privacy@aitoolsay.com. We respond within five business days.
Contact
Data-protection questions: privacy@aitoolsay.com. Our wider practices are in the Privacy Policy.
Everything you wanted to ask
Still stuck? Our team answers every message.
Still have a question? We usually reply within one working day.
Why are vendors listed by category, not by name?
Vendor names change more often than a policy page gets updated, and a stale name is worse than an honest category. The current vendor in any category is available on request to privacy@aitoolsay.com, answered within five business days.
Do AI providers train on my prompts?
Not on the enterprise API tiers we use. Your prompt is sent for the single request that produces your result and is not persisted by us.
Do payment processors give you my card number?
No. Card details go directly to the processor. We hold only the transaction record — amount, date, product, last four digits and a gateway reference — because tax law requires it.
How do I get notice of new sub-processors?
Email privacy@aitoolsay.com and ask to join the notification list. New sub-processors are published here at least 30 days before they start processing.
Can I object to a new sub-processor?
If you hold a DPA with us, yes — on reasonable data-protection grounds, within the 30-day window. We will work on an alternative or let you terminate the affected service without penalty.
Can I get a signed DPA?
Yes. Write to privacy@aitoolsay.com and we will respond within five business days, including completed security questionnaires.
Do any of these transfer data outside the UK or EEA?
Some do. Those transfers rely on Standard Contractual Clauses or an adequacy decision, and we satisfy ourselves the safeguards are adequate before anything is sent.
Something here unclear?
Legal writing is easy to get wrong. If any part of this page is ambiguous — or you think it is mistaken — tell us and we will fix the wording.