Legal
Sub-processors
Last updated: 2 August 2026
Version 1.1
Code Tigris PLT (LLP0038657-LGN, Malaysia) follows the ISO/IEC 27001 information security management framework when selecting and overseeing sub-processors. Code Tigris PLT is not currently certified to ISO/IEC 27001. Each sub-processor listed below is bound by a written agreement that imposes data-protection obligations no less protective than our Privacy Policy and any applicable Data Processing Addendum.
1. What is a sub-processor?
A sub-processor is a third party we engage to process personal data on our behalf in connection with the Services. We commit to: (a) entering into a written agreement with each sub-processor that imposes data-protection obligations no less protective than this Privacy Policy and the applicable Data Processing Addendum; (b) remaining liable for our sub-processors' performance; and (c) providing customers with at least thirty (30) days' prior notice before adding a new sub-processor by updating this page and (for customers with active subscriptions) sending an email notification. Material objections from customers will be considered in good faith.
2. Infrastructure sub-processors (used for all customers)
| Sub-processor | Purpose | Location | Privacy Policy |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure (compute, storage, networking, CDN, identity) | ap-southeast-1 (and other AWS regions as required) | aws.amazon.com/privacy |
| Amazon Web Services — Bedrock | Default LLM inference, embeddings, and reranking | ap-southeast-1 | aws.amazon.com/privacy |
| MongoDB, Inc. (MongoDB Atlas) | Primary application data store | ap-southeast-1 | mongodb.com/legal/privacy-policy |
| Stripe Payments Malaysia Sdn Bhd | Payment processing and subscription billing | Malaysia (with Stripe global processing) | stripe.com/privacy |
| Google Asia Pacific Pte Ltd | Corporate email (Google Workspace) and Gemini API (where Gemini is selected as the LLM) | Singapore (primary), global | policies.google.com/privacy |
3. LLM provider sub-processors (used where you select them, including BYOM)
When you use BYOM (Bring Your Own Model) or where Code Tigris PLT's curated model fallback routes to a non-Bedrock provider, the following LLM providers may act as sub-processors. Each operates under their own terms of service and privacy policy; you are responsible for reviewing them.
| Provider | Endpoint | Privacy Policy |
|---|---|---|
| Anthropic, PBC | api.anthropic.com | anthropic.com/legal/privacy |
| OpenAI, L.L.C. | api.openai.com | openai.com/privacy |
| Google LLC (Gemini) | Google GenAI SDK | policies.google.com/privacy |
| DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.) | api.deepseek.com | Provider site |
| Alibaba Cloud (Qwen) | dashscope-intl.aliyuncs.com | alibabacloud.com/help/en/legal |
| Mistral AI SAS | api.mistral.ai | mistral.ai/terms |
| Moonshot AI | api.moonshot.ai | Provider site |
| OpenRouter, Inc. | openrouter.ai | openrouter.ai/privacy |
| Groq, Inc. | api.groq.com | groq.com/privacy-policy |
| Requesty | router.requesty.ai | Provider site |
4. Integration sub-processors (used where you enable an integration)
Where a customer enables an Integration Partner, end-user chat content and identifiers may flow to that partner for the duration of the enabled scenario (for example, human handoff, CRM sync, or channel delivery). Integration sub-processors are listed below; enabling an integration constitutes your consent to data flow to that sub-processor under this Privacy Policy and any applicable Data Processing Addendum.
| Integration Partner | Purpose | Status |
|---|---|---|
| Zanroo Malaysia Sdn Bhd | Human-agent handoff desk — chat-transcript forwarding when a customer escalates to a live agent | Active |
5. Customer-configured destinations (MCP tools)
Customers may configure chatbot tools that read from or write to third-party services using credentials the customer provides — including Google Sheets, REST API endpoints under the customer's own control, and any other endpoints reachable from the Services. These destinations are not sub-processors of Code Tigris PLT; the customer remains the data controller for all flows to such destinations and is responsible for any required notices, contracts, and consents with those services.
6. Change log
- v1.0 — 28 May 2026 — Initial publication.
- v1.1 — 2 August 2026 — Added Requesty (LLM gateway).