Subprocessor Notice
Version: 2026-08-08
Effective date: August 8, 2026
This Notice describes third parties that may process personal data for Infer by Flow7. Infer’s current legal operator is identified in the Legal Operator Notice.
Ordinary marketing pages may describe infrastructure generically. This Notice provides additional transparency for account, payment, email, identity, security, and Customer Personal Data processing.
1. Named providers
| Provider | Role and purpose | Data that may be processed | Typical location/status |
|---|---|---|---|
| Stripe, Inc., Sold through Link, LLC, and applicable Stripe/Link affiliates | Hosted Checkout, payment processing, Managed Payments merchant-of-record services, tax, billing address/name collection, fraud, disputes, refunds, invoices, receipts, and transaction support | Contact, billing, address, payment identifiers, transaction, wallet-funding, tax, risk, refund, and dispute data | United States and documented global Stripe/Link locations; active for paid transactions |
| Google LLC | Optional Google OAuth login | OAuth identifier, email, name/profile fields authorized at login, and authentication metadata | Global; conditional when Google login is used |
| Cloudflare, Inc. | DNS, CDN, edge security, bot/rate protection, Workers infrastructure, and transactional email delivery/lifecycle events | IP/network/security data, email address and transactional message content, delivery diagnostics, and content in transit depending on enabled services | Global network; active for production edge and transactional-email features |
| OpenRouter, Inc. | Gateway for Official API / First-Party Endpoint routes | Customer request and output in transit; model, usage, route, security, and request metadata | United States and selected underlying model-provider locations; active for applicable routes |
| Havenbyte LLC d/b/a ModelFlare | Gateway for Low Cost and Stable routes | Customer request and output in transit; model, usage, route, diagnostics, security, and cost metadata | United States and selected infrastructure/model-provider locations; active for applicable routes |
2. Infrastructure provider categories
Infer uses managed providers in the following categories. The exact provider can change as the production architecture evolves:
- application hosting, compute, deployment, and networking;
- managed database, storage, cache, and backup;
- logging, monitoring, error reporting, and incident alerting;
- DNS, content delivery, web-application firewall, and bot/rate protection;
- identity and authentication; and
- source-code hosting, deployment automation, and secrets management.
These providers may process account, organization, ledger, payment identifiers, security events, operational metadata, and transient Customer Content to the extent technically necessary. Infer configures ordinary logs not to intentionally capture complete prompt or response bodies and limits provider access according to role.
A Business User with a material data-protection need may request the
current production legal-entity inventory at
privacy@flow7.org. Infer may provide
security-sensitive infrastructure detail under confidentiality rather
than on a public marketing page.
3. Underlying model providers
A model developer or host reached through OpenRouter or ModelFlare may be a Subprocessor or further Subprocessor for the request selected by the customer. Depending on the model catalog and route, providers can include entities associated with model families such as OpenAI/GPT, Anthropic/Claude, Google/Gemini, xAI/Grok, DeepSeek, Kimi/Moonshot, and others displayed in the Service.
Before or at route selection, Infer will make reasonably available:
- the model family and resolved model identity;
- whether the route is an Official API / First-Party Endpoint or another qualified host;
- applicable Model Terms or a model-registry reference;
- the route’s no-training, logging, retention, or zero-retention designation where available;
- territorial or account restrictions; and
- the effective pricing/model-registry version.
Customer’s affirmative selection of a specifically presented model or route authorizes the underlying model-processing provider needed for that request.
An Official API / First-Party Endpoint route is locked to the selected model developer’s first-party endpoint through infrastructure intermediaries and does not silently fall back to an unrelated third-party model host. This does not imply a partnership, endorsement, or direct customer agreement with the model developer.
4. Data-processing expectations
Infer requires model-processing and infrastructure suppliers, through contract, account settings, route configuration, or another applicable mechanism, to process data only as needed for the selected service and to maintain appropriate security and confidentiality.
Public supplier documentation is informational and does not replace binding terms where a binding processor agreement is legally required. Route-level technical settings, including zero-retention, no-training, provider allowlists, and data-collection denials, apply only where the selected supplier and model endpoint support them.
5. Notice and objection
Infer will provide at least 30 calendar days’ notice before a new direct Subprocessor begins processing Customer Personal Data when reasonably practicable. For an urgent change required by law, security, supplier failure, model availability, or service continuity, notice may occur later but will be provided as soon as reasonably practicable.
A Business User may object within 15 calendar days
after notice on reasonable data-protection grounds by emailing
privacy@flow7.org. Infer and the customer will seek a
reasonable alternative route, configuration, or provider. If no
reasonable alternative exists, Infer may disable the affected feature or
the customer may terminate the affected processing and request a refund
of eligible unused paid credit.
A customer’s affirmative selection of a newly disclosed model or route after the provider information is presented constitutes authorization for that provider.
6. Supplier disclosure by context
- Marketing pages: supplier names may remain undisclosed unless naming is needed to avoid a misleading claim.
- Terms: supplier categories and Model Terms may be incorporated without naming every provider.
- Privacy Notice: categories and principal named recipients are described, with a link to this Notice.
- DPA and this Notice: payment, gateway, and material direct processing providers are named; underlying model providers are identified through the selected model/route and registry.
- Security-sensitive infrastructure: details may be provided to Business Users under confidentiality.
7. Contact
Subprocessor questions and objections:
privacy@flow7.org
The current operator and postal address are in the Legal Operator Notice.