Sub-processors
Draft — verify each entry against live contracts/config before publication. See
README.md. Entity facts:COMPANY.md.
- Owner: byRazLabs Ltd (trading as "Dena")
- Version: 1.0 (draft) — drafted 2026-06-05
- Referenced by: the DPA §5 and the
This page lists the third parties Dena engages to process personal data in providing the Service ("sub-processors"). We require each to meet data-protection obligations no less protective than our DPA, and we remain responsible for their performance.
How we notify changes
We give customers prior notice of new or replacement sub-processors (at least 30 days where practicable) via this page and/or email, with an opportunity to object on reasonable data-protection grounds. To receive notifications, email privacy@denainfra.com.
Current sub-processors
| Sub-processor | Service provided | Data processed | Processing location | Transfer safeguard |
|---|---|---|---|---|
| Google Cloud (Google Cloud EMEA Ltd / Google Ireland) | Cloud hosting, database (Cloud SQL / Postgres), object storage, networking, logging, monitoring | All Customer Data hosted on the platform; account & telemetry data | UK — europe-west2 (London) (logging/monitoring metadata may use Google's global infra) | UK/EEA hosting; Google's SCCs/IDTA for any out-of-region support |
| Clerk (Clerk, Inc.) | Identity & authentication (accounts, login, MFA, sessions) | Account identity data: name, email, auth credentials, session/IP/device metadata | [TODO: confirm Clerk data region — US by default unless EU data residency is enabled] | EU SCCs + UK IDTA (Clerk's DPA) [TODO: enable EU data residency if available] |
| Anthropic (Anthropic PBC) | AI model inference (Claude) for inspection analysis | Inspection content submitted for analysis (largely asset/defect imagery + structured engineering data); may incidentally include personal data in media | [TODO: confirm — US; check whether EU/UK inference region or zero-retention endpoint is available] | EU SCCs + UK IDTA (Anthropic Commercial Terms / DPA); API data not used for model training; [TODO: confirm zero-retention / no-training terms in writing] |
[TODO: email/notification provider] | Transactional email (invites, alerts) | Recipient email + message content | [TODO] | [TODO] |
[TODO: error/telemetry tooling, if any beyond GCP] | [TODO] | [TODO] | [TODO] | [TODO] |
Verification owed before publication. Confirm each provider's current legal entity, data region, sub-processor terms, and transfer mechanism from its DPA, and complete the
[TODO]s. Add any provider that processes personal data on our behalf (analytics, support desk, payment processor when billing is added, etc.). Removing a provider from the platform should also remove it here.
Infrastructure vs. sub-processor
Providers that supply infrastructure we control but that do not access Customer personal data in identifiable form (e.g. a CDN passing encrypted traffic, a CI runner building images) are not listed as sub-processors. If their role changes such that they process personal data, they are added here.
Revision history
| Version | Date | Change | Author |
|---|---|---|---|
| 1.0 (draft) | 2026-06-05 | Initial draft — GCP, Clerk, Anthropic identified from ADRs | AI session — pending verification |