Sub-processors

Who CloudQuell uses to operate the Service.

CloudQuell engages a small number of third-party service providers ("sub-processors") to operate the Service. This page lists the current sub-processors, what they do, and where they process data.

Effective: 2026-07-03

A sub-processor is any third party engaged by CloudQuell that may process Customer Data. We vet each sub-processor against our security and privacy standards before engaging them and continue to monitor their controls over time. We pass our obligations under your agreement with us down to each sub-processor.

Current sub-processors

Amazon Web Services (AWS)

Vendor page ↗
Purpose
Cloud infrastructure — hosting, compute, storage, database, authentication, email delivery, and all production processing.
Data category
Customer Data, account information, AWS CUR data, telemetry, backups.
Location
United States (us-east-1, us-east-2, us-west-2).

Stripe

Vendor page ↗
Purpose
Payment processing for paid subscriptions. Applies once paid billing is enabled.
Data category
Billing contact details, payment method, and transaction data. Payment-card numbers are processed and stored by Stripe, not by CloudQuell.
Location
United States.

Sentry

Vendor page ↗
Purpose
Application error monitoring for the CloudQuell web applications.
Data category
Error reports and diagnostic metadata, which may include user identifiers (email, organization ID) and device/browser information. No CUR data.
Location
United States.

Zoho

Vendor page ↗
Purpose
Business email hosting for support and operational mailboxes (for example, support@cloudquell.com).
Data category
The contents of email you send to CloudQuell addresses, including support requests.
Location
United States.

OpenAI

Vendor page ↗
Purpose
AI-powered explanations and the website chat assistant (one of several model providers, routed per request — see note below). Invoked only when a user explicitly clicks an "Explain with AI" button or sends a chat message.
Data category
Contextual prompt data necessary to produce the requested explanation (for example, the name of a service and a recent cost trend). We do not send raw CUR data or personally identifiable information beyond what is required to answer the question.
Location
United States.

Google (Gemini API)

Vendor page ↗
Purpose
AI-powered explanations and the website chat assistant (one of several model providers, routed per request — see note below). Invoked only when a user explicitly clicks an "Explain with AI" button or sends a chat message.
Data category
Contextual prompt data necessary to produce the requested explanation (for example, the name of a service and a recent cost trend). We do not send raw CUR data or personally identifiable information beyond what is required to answer the question.
Location
United States.

Anthropic

Vendor page ↗
Purpose
AI-powered explanations and the website chat assistant (one of several model providers, routed per request — see note below). Invoked only when a user explicitly clicks an "Explain with AI" button or sends a chat message.
Data category
Contextual prompt data necessary to produce the requested explanation (for example, the name of a service and a recent cost trend). We do not send raw CUR data or personally identifiable information beyond what is required to answer the question.
Location
United States.

Notification of changes

When we add or remove a sub-processor, we update this page and update the Effective Date above. To receive an email notification when this list changes, email privacy@cloudquell.com with the subject "Subscribe".

Questions

Concerns about a specific sub-processor or our sub-processor management practices can be sent to privacy@cloudquell.com.

Customers may have additional rights regarding sub-processors under a signed Data Processing Agreement, which takes precedence over this page in case of conflict.