Sub-processors
Every third party that processes customer data on Teleon’s behalf, what each one actually receives, and where it runs. Published because the Data Processing Addendum requires it, and written to be useful to the person doing the assessment.
This document is published for review. Entity registration details and the designated EU and UK representatives are still to be supplied, and appear below as marked placeholders. Until they are filled in, treat this text as a draft rather than as the executed agreement, and ask legal@teleon.ai for the current signed position.
How to read this register
A sub-processor is any third party that processes Customer Personal Data on Teleon’s behalf. Vendors that never touch Customer Personal Data, a code host, a package registry, an office suite, are not sub-processors and are not listed here, because padding the register makes the entries that matter harder to find.
Each entry states what the sub-processor actually receives. That distinction carries the legal weight: a provider that receives only a SHA-256 root hash is in a different position from one that receives prompt text, and a register that flattens both into “processes data” tells a customer’s counsel nothing.
Only one sub-processor in this register receives customer payload content: Amazon Bedrock, in section 3. Everything else receives metadata, hashes, tokens, or contact details. If you are assessing Teleon for a data protection impact assessment, that section is where the analysis is.
Infrastructure
Teleon runs on Amazon Web Services. There is no second cloud provider, no colocation, and no on-premise component in the hosted Service.
| Service | What it holds | Regions |
|---|---|---|
| Amazon EKS | Compute for every Teleon service. Processes data in memory; persists nothing. | us-east-1, eu-west-1 |
| Amazon RDS (PostgreSQL) | Control-plane database: tenants, agents, policies, the audit ledger, DSR records, vault token mappings. | us-east-1, eu-west-1 |
| Amazon DynamoDB | High-write operational state: rate-limit counters, idempotency records, quota accounting. | us-east-1, eu-west-1 |
| Amazon S3 | Compliance bundles, DSR deliverables, cold-storage audit archives. | us-east-1, eu-west-1 |
| Amazon ElastiCache | Ephemeral counters and replay-protection state. No durable personal data. | us-east-1, eu-west-1 |
| AWS KMS | Customer-managed keys for audit signing, vault key-encryption keys, and S3 server-side encryption. Key material never leaves KMS. | us-east-1, eu-west-1 |
| AWS Secrets Manager | Platform and tenant secrets, including customer-supplied provider credentials. | us-east-1, eu-west-1 |
| Amazon CloudFront + AWS WAF | Edge delivery and request filtering for the web properties. | Global edge network |
| Amazon ECR | Container images. No customer data. | us-east-1 |
| Amazon CloudWatch | Platform logs and metrics, scrubbed of payload content. | us-east-1, eu-west-1 |
AWS is certified under the EU–US Data Privacy Framework and offers the EU Standard Contractual Clauses through its Data Processing Addendum, which Teleon has accepted. A tenant configured for EU residency has its database, object storage and keys in eu-west-1; see section 6 of the Data Processing Addendum for what that guarantee does and does not cover.
Model inference and content classification
Teleon evaluates prompts and responses for prompt injection, policy violations and trust scoring. That evaluation is performed by a large language model, and the text being evaluated is sent to that model. It is the only point in the Service where customer payload content leaves Teleon’s own infrastructure.
| Function | What it receives | Region |
|---|---|---|
| Amazon Bedrock Guardrails | Prompt and response text submitted for prompt-injection and content classification. | us-east-1 |
| Anthropic Claude Sonnet 4.5, via Bedrock | Prompt, response and tool-call text submitted for LLM-judge scoring and policy evaluation. | us-east-1 |
What this means in practice
- Content sent to Bedrock is not used to train any model. AWS does not store Bedrock inputs or outputs, and Anthropic does not receive them: inference runs inside the AWS account boundary under the AWS Service Terms.
- Privacy Vault tokenization is applied before evaluation where the tenant has classified a field as sensitive. A tokenized field reaches Bedrock as an opaque token, not as its value.
- Fields that have not been classified reach Bedrock as written. Vault coverage is a tenant configuration, not an automatic property of the platform, if a field is not classified, it is not tokenized.
- Evaluation is currently performed in
us-east-1regardless of a tenant’s configured storage residency, because Bedrock capacity for this model is not yet provisioned ineu-west-1. For an EU tenant this is a transfer to the United States and is covered by the Standard Contractual Clauses referenced in section 6 of the Data Processing Addendum.
If your data protection impact assessment requires that no EU personal data leaves the EEA at any point, the classifier and judge paths do not meet that requirement today. Contact sales before signing: the enforcement path can be configured to fail closed without model-based evaluation, at the cost of the detections that evaluation provides.
Billing and payments
| Sub-processor | What it receives | Location |
|---|---|---|
| Stripe, Inc. / Stripe Payments Europe, Ltd. | Billing contact name and email, company name, billing address, VAT identifier, subscription and invoice records. | United States, Ireland |
Stripe is the merchant of record for self-serve plans and processes card payments directly. Card numbers, expiry dates and security codes are entered into Stripe-hosted fields and never reach Teleon’s systems; Teleon stores only Stripe’s customer and subscription identifiers.
Stripe is certified under the EU–US Data Privacy Framework and PCI DSS Level 1.
Transactional email
| Sub-processor | What it receives | Location |
|---|---|---|
| Resend (Plus Five Five, Inc.) | Recipient email address and message content for account, DSR, approval and alert emails. Primary provider. | United States |
| Amazon Web Services, Inc., Amazon SES | The same, when Resend is unavailable. Failover only. | us-east-1 |
Teleon sends transactional email only: verification, password and invitation flows, data-subject request receipts and deliverable links, approval requests, and platform alerts. There is no marketing email list and no newsletter, so there is no email-marketing sub-processor.
A data-subject request receipt necessarily contains the requester’s email address and enough context to identify the request. That email transits Resend. A data subject who objects to that transit can be served through the DSR portal without email notification; ask the controller operating the agent to select portal-only delivery.
Error monitoring
| Sub-processor | What it receives | Location |
|---|---|---|
| Functional Software, Inc. (Sentry) | Stack traces, service name, release version, request route and correlation identifiers from unhandled errors. | United States |
Sentry receives errors, not traffic. Every event passes a scrubbing function before it leaves the process: user email addresses and usernames are never attached, and payload content is stripped from breadcrumbs and exception context. Sampling is set to 10% of performance traces in production.
A stack trace can still incidentally carry a fragment of the data that caused the error. That residual risk is the reason Sentry is listed here rather than treated as ordinary telemetry.
Earlier versions of Teleon’s published summaries stated that observability was “internal only” and that customer telemetry was “never forwarded to third-party analytics”. Product and platform analytics are indeed self-hosted, but Sentry is a third party and this sentence was wrong as written. It has been corrected here and in the summaries shown on teleon.ai.
Metrics, dashboards and log aggregation are self-hosted on Prometheus, Grafana and Loki inside Teleon’s own cluster. No hosted observability vendor receives them.
Tamper-evidence anchoring
| Operator | What it receives | Location |
|---|---|---|
| OpenTimestamps calendars (alice, bob) | A single SHA-256 digest per day, per region. Nothing else. | Global |
| Eternity Wall (finney calendar) | The same digest, submitted redundantly. | Global |
| Catallaxy (btc calendar) | The same digest, submitted redundantly. | Global |
Once a day, the Merkle root of each region’s audit ledger is submitted to these calendar servers, which aggregate submissions from many parties and commit the aggregate to the Bitcoin blockchain. What is published is a hash of a hash: the root cannot be reversed, and it reveals neither the number of entries nor anything about their content.
These operators are listed for completeness. In the strict sense they are not sub-processors, because a SHA-256 digest of a Merkle root is not personal data by any workable definition. They are named because a customer reading about Bitcoin anchoring is entitled to know exactly what is being anchored.
Earlier published summaries described anchoring as “Bitcoin & Ethereum witnessing”. Teleon anchors to Bitcoin only, through the four OpenTimestamps calendars above. There is no Ethereum anchoring and there never has been.
Intra-group sub-processor
| Entity | What it receives | Location |
|---|---|---|
| Teleon SARL | Break-glass production access for engineering, platform operations and technical support. Access is role-scoped, time-boxed, approved per session and written to the audit ledger. | Tunisia |
Teleon SARL is a wholly-owned subsidiary of Teleon, Inc. and supplies the engineering and operations function. Its personnel do not have standing access to production data; access is granted per incident, expires automatically, and is logged in the same hash-chained ledger customers audit.
Tunisia is not the subject of a European Commission adequacy decision under Article 45 GDPR. Any access to EU personal data from Tunisia is a restricted transfer and is made under the EU Standard Contractual Clauses executed between the group entities, together with the supplementary measures and transfer impact assessment described in section 6 of the Data Processing Addendum.
Tunisia is a party to Council of Europe Convention 108 and has a supervisory authority, the Instance Nationale de Protection des Données Personnelles, operating under Loi organique n° 2004-63. Those facts support the transfer impact assessment. They are not adequacy, and Teleon does not present them as adequacy.
Tunisian law places its own restrictions on transfers of personal data out of Tunisia. Teleon’s architecture keeps customer data in AWS rather than on Tunisian infrastructure, so the SARL reaches data rather than holding it, which keeps the outbound-transfer question from arising in the first place.
What is deliberately not on this list
Several functions that most platforms outsource are run by Teleon itself. Listing them here is the only way a reader can tell the difference between “absent because we forgot” and “absent because there is no vendor”.
| Function | How it runs |
|---|---|
| Identity and SSO | Zitadel, self-hosted in Teleon’s own cluster. No hosted identity vendor receives customer credentials or session data. |
| Metrics, dashboards, logs | Prometheus, Grafana and Loki, self-hosted. No hosted observability vendor. |
| Product analytics | None. Teleon runs no product-analytics vendor and no session recording. |
| Website analytics | None. teleon.ai loads no analytics script and sets no advertising or measurement cookie. |
| Support helpdesk | Email to the addresses in section 13, handled in Teleon’s own mailbox. No helpdesk SaaS holds a ticket history. |
| Audit ledger and Privacy Vault | Teleon-operated, on the AWS infrastructure in section 2. No third-party ledger, notary or tokenization vendor. |
Development tooling, source hosting, CI, package registries, processes Teleon’s source code, not Customer Personal Data, and is therefore outside the scope of this register.
Optional and prospective sub-processors
None are engaged today. This section exists so that the list of what could be added is as visible as the list of what is in use.
Teleon does not currently offer a sovereign-EU secondary region, a Germany-resident deployment, or a hosted status page. Any of these would add a sub-processor and would be published here under the notice process in section 11 before it was activated.
Earlier versions of this register named Paddle, Postmark, Datadog, Plain, Statuspage, Cloudflare, OVHcloud and Microsoft Azure. None of them process Teleon customer data. They were drafted against a planned architecture that was not the one built, and have been removed.
Change notice and your right to object
Teleon gives at least 30 days’ written notice to the account administrator before a new sub-processor begins processing Customer Personal Data, and publishes the change on this page on the same day the notice is sent.
How to receive notices
- Notices are sent to the billing and administrative contacts on the account. Keep them current in
Settings → Organisation. - Anyone may subscribe independently by emailing compliance@teleon.ai with the subject “sub-processor notices”.
How to object
A customer may object to a new sub-processor in writing to dpo@teleon.ai within the 30-day notice period, stating the data protection grounds for the objection. Teleon will work in good faith to offer a configuration that avoids the sub-processor for that customer. Where no such configuration exists, the customer may terminate the affected part of the subscription without penalty and receive a pro-rata refund of prepaid fees, as set out in section 11 of the Terms of Service.
Emergency replacement
If a sub-processor becomes unavailable or unsafe, an outage, a breach, a termination, Teleon may engage a replacement with shorter notice, and will publish the change here and notify administrators within one business day, together with the reason. The right to object survives; it is exercised after the fact rather than before it.
Change log
Entries are append-only. A correction is made by adding an entry that references the earlier one, never by editing it away.
| Date | Change | Notice |
|---|---|---|
| 2026-08-30 | Register rewritten against the deployed architecture. Added: Amazon Bedrock (model inference and classification), Stripe (billing), Resend and Amazon SES (transactional email), Sentry (error monitoring), Teleon SARL (intra-group). Removed as never engaged: Paddle, Postmark, Datadog, Plain, Statuspage, Cloudflare, OVHcloud, Microsoft Azure. Corrected: anchoring is Bitcoin only; compute is EKS, not ECS Fargate. | Published; administrators notified. See the note below. |
| 2026-05-13 | Initial register published alongside the DPA and SOC 2 evidence index. Superseded by the 2026-08-30 entry. | Published |
The sub-processors added on 2026-08-30 were already in use. This entry is a correction of an incomplete register, not notice of a new engagement, and Teleon is not presenting it as one. The previous register was drafted against an intended architecture and was not updated as the platform was built.
Because the 30-day notice period in section 11 could not run before processing began, every customer with a Data Processing Addendum in force on 2026-08-30 may object to any sub-processor listed here on the same terms as a new addition, for 30 days from that date, with the same right to terminate the affected part of the subscription without penalty. Objections go to dpo@teleon.ai.
Contact
- Data protection and objections
- dpo@teleon.ai
- Compliance evidence and notices
- compliance@teleon.ai
- Security
- security@teleon.ai
- Contracting entity
- Teleon, Inc., a Delaware corporation. Registered office: «TODO: Delaware registered office address».
This page is the register referred to in section 5 of the Data Processing Addendum and section 8 of the Terms of Service. It is also served at /sub-processors for the benefit of documents that cite that path.