Suppliers, subprocessors and data flow
How external dependencies should be governed and why a technical provider catalog is not the same as a legal subprocessor register.
How to interpret this document
This content describes technical and methodological behavior that is implemented or explicitly planned in the product. When a control depends on configuration, a provider, a secret, a contract or legal approval, that dependency must remain visible.
External dependencies
Model providers, OAuth connectors, hosting infrastructure and auxiliary services can participate in the data flow depending on the feature being used.
Minimization
The design should send only the data required for the operation. Integration Hub, for example, prioritizes aggregated metrics in the INT-1.0 baseline.
Assessment
Security, Privacy and Procurement should evaluate contractual terms, location, retention, subcontracting and provider controls according to criticality and the data involved.
Public register
The product does not currently claim a complete formal public subprocessor register. Publishing one requires a validated inventory and an ongoing update process.
Provider change
Changing a dependency can affect security, privacy, methodology and comparability. Material changes should be governed rather than treated as a minor implementation detail.