To provide the Service, Kinara engages the third-party sub-processors below to process personal data on our behalf, under contract and only as needed to deliver the Service. How we handle personal data is described in our Privacy Policy.
Where a row states that data is not used to train models, that reflects each provider's applicable API or enterprise terms as we have configured them; these terms vary by provider and may change. Providers that route requests to downstream model providers are noted below, and those downstream providers' terms also apply.
| Sub-processor | Purpose | Data processed | Region |
|---|---|---|---|
| Supabase | Authentication and primary application database | Account and workspace data (name, work email, company, role, tenant/user records) | United States |
| PostHog | Product analytics | Pseudonymous usage events (no name or email) | European Union |
| Mailgun | Transactional email (sign-in links, account notifications) | Email address and message content | United States |
| Modal | Application hosting and compute | Service data in transit and during processing | United States |
| Render | Application hosting and compute | Service data in transit and during processing | United States |
| Vercel | Application/frontend hosting and compute | Service data in transit and during processing | United States |
| Cloudflare | Bot and abuse protection (Turnstile) on public forms | Visitor IP address and challenge-interaction signals | United States / global (Cloudflare network) |
| OpenAI | AI inference for analysis and recommendations | Analysis inputs (may include Customer Data and connected-system data); not used to train their models | United States |
| Anthropic | AI inference for analysis and recommendations | Analysis inputs (may include Customer Data and connected-system data); not used to train their models | United States |
| Nebius | AI inference for analysis and recommendations | Analysis inputs (may include Customer Data and connected-system data); not used to train models | United States |
| OpenRouter | AI inference routing for analysis and recommendations | Analysis inputs (may include Customer Data and connected-system data); routed to downstream model providers whose terms apply; configured not to train on our data where supported | United States |
| Baseten | AI inference for analysis and recommendations | Analysis inputs (may include Customer Data and connected-system data); not used to train models | United States |
| Qdrant | Knowledge vector storage and retrieval | Knowledge documents and embeddings | United States |
Changes to this list
We may add, remove, or replace sub-processors as the Service evolves. We will update this page and, where required by contract or law, provide notice before a new sub-processor begins processing personal data, so customers who require it have an opportunity to object. Where a customer's written agreement requires it, we will give at least 30 days' notice of a new sub-processor; if the customer reasonably objects on data-protection grounds and we cannot address the concern, the customer may terminate the affected subscription.
Some connected data sources (for example your own telemetry, logs, or topology systems) are operated by you, not by Kinara, and are not sub-processors. They are governed by the Terms of Service.
Questions
Questions about our sub-processors, or requests for a Data Processing Addendum, may be directed to Kinara Systems Inc. via our contact page.
