The short version
- Four sub-processors. An edge network for ingress, a mail relay for staff sign-in codes, an in-Kingdom cloud region in Riyadh for encrypted backup storage, and Google Analytics on this website only.
- No AI sub-processor at all. The model, speech and OCR run on our own hardware.
- None of them can read conversation content at rest — the backup host holds ciphertext without the key.
- 30 days' notice before we add one, with a right to object.
- The in-Kingdom cloud provider agreement is still being formalised — section 5 says so plainly rather than waiting for the paperwork.
1. The register
This is the complete list of third parties that process personal data on Elbetron's behalf in connection with Elbi. There are four. None of them can read conversation content at rest.
| Sub-processor | What it does | What it can see | Where | Agreement |
|---|---|---|---|---|
| Edge network provider | Ingress, TLS termination at the edge, protection against attack | Traffic while in transit, which can include message content before it is re-encrypted to our origin | Global edge network (US-headquartered) | On file |
| Transactional mail relay | Sends transactional email — staff sign-in codes and invitations | A staff email address and a one-time code or invite link. Never conversation content. | United States | On file |
| In-Kingdom cloud provider | Hosts the encrypted off-site backup replica | Ciphertext only. The backup routine ships nothing but AES-encrypted artefacts, and aborts before replication if encryption fails | Riyadh, Kingdom of Saudi Arabia | Being formalised |
| Google (Analytics 4) | Counts visits to this marketing website | Page views and IP address from a-i.sa only. It is not present in the Elbi product and never sees a conversation | United States | Google Ads Data Processing Terms |
There is no AI sub-processor. No OpenAI, Anthropic, Google, Azure or any other model, speech or OCR provider processes personal data — all of it runs on hardware we control inside the Kingdom. This is the single biggest difference between this register and those of comparable vendors.
2. What each one actually touches
It is worth being precise, because “sub-processor” covers very different levels of exposure:
- the edge network sits in front of the service. TLS terminates at its edge, so in principle it handles request bodies in transit — this is why it is listed, even though it stores nothing for us. Traffic is re-encrypted to our origin.
- The mail relay only ever sees an email address belonging to an Elbetron staff member and a short-lived code. No customer, visitor or conversation data reaches it.
- in-Kingdom cloud holds files it cannot read. The encryption key lives on our own server and is never transmitted, so the replica is useless without it.
Anything not on this list is not a sub-processor. Our own staff are not sub-processors; their access is covered under Access control.
3. Adding or changing a sub-processor
- We give customers at least 30 days' written notice before a new sub-processor begins processing, or before an existing one's role materially changes.
- A customer may object on reasonable data-protection grounds within that period. We will work to resolve it, and if we cannot, the customer may terminate the affected service without penalty.
- This page is the authoritative register. Its version and date change whenever the list does.
- Every sub-processor is bound by written terms no less protective than those we owe our customers, as required by the Data Processing Agreement.
4. Transfers outside the Kingdom
Conversation content is processed and stored inside Saudi Arabia and destroyed there. Two of the four entries above nonetheless involve a party outside the Kingdom, and we would rather list them than hide them:
| Leaves the Kingdom? | What | |
|---|---|---|
| the edge network | In transit only | Routing may traverse edge infrastructure abroad. Encrypted throughout; nothing is stored there. |
| Mail relay | Yes | A staff email address and a one-time code. No customer data. |
| in-Kingdom cloud | No | The region is inside Saudi Arabia, chosen specifically so backups never leave. |
These transfers are handled under PDPL Article 29 and the transfer conditions in the Implementing Regulations.
5. What this register does not yet show
Two things a careful reviewer should know, stated here rather than discovered later:
- The in-Kingdom cloud agreement is being formalised. The off-site backup replica went live after our Records of Processing Activities were last issued, so it appears here before it appears there. It is listed as a sub-processor from the moment it began processing, not from the moment the paperwork catches up. The exposure is limited — it holds ciphertext it has no key for — but the register should be honest about the status.
- Our RoPA is being updated to match. Version 1.1 lists two processors; this page lists four. The register on this page is the current one.
6. Questions
| global.business@elbetron.com | |
| Related | Data Processing Agreement · Privacy Policy · Security & Compliance |
Register verified.