DEEPXL AS
SUB-PROCESSORS AND OTHER PROCESSORS
Version 1.0 | Effective from 14 September 2026 Published in the legal section of our website at deepxl.ai — superseded versions remain available in the same place
This page is the list referred to in clause 5.1 of the Data Processing Addendum (Schedule 2 to the DeepXL API Terms), in section 5 of the DeepXL Privacy Policy, and in the Azure Subscription and Data Processing Agreement between DeepXL AS and DeepXL Corp. For each provider it states what is processed, where, and on what transfer basis.
It is in two parts, because they answer two different questions. Part A is the parties that process our customers’ files — the list required by Article 28 of the GDPR and, where the Standard Contractual Clauses apply, Annex III to them. Part B is the parties that process DeepXL’s own account and business data, for which DeepXL AS is the controller. No party outside Part A has access to Customer Content.
PART A — SUB-PROCESSORS OF CUSTOMER CONTENT
These are the only parties, other than DeepXL AS itself, in the processing chain for the files, images and data our customers submit to the Services (“Customer Content”). One of them holds the infrastructure; the other operates it. No other party has access to Customer Content.
1. DeepXL Corp
| Entity | DeepXL Corp, 1007 N Orange St, Wilmington, DE 19801, United States. A separate company from DeepXL AS. |
|---|---|
| What it does | Holds the Microsoft Azure subscription in which the Services run. DeepXL Corp does not access Customer Content; all administration of the subscription is performed by DeepXL AS personnel in Norway, under a data processing agreement with DeepXL AS. |
| Location of processing | United States — within the Microsoft Azure environment described in entry 2. |
| Transfer basis | None required — DeepXL Corp receives no Customer Content. Standard Contractual Clauses, Module Three (processor to processor), are nonetheless in place between DeepXL AS and DeepXL Corp because the subscription stands in its name. |
| Its own sub-processor | Microsoft Corporation (entry 2). No other. |
2. Microsoft Corporation
| Entity | Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, United States. |
|---|---|
| What it does | Cloud compute, storage, database and Azure OpenAI inference for the Services. |
| Location of processing | Azure region East US 2 (Virginia) for all Customer Content — compute, storage of submitted files, database, derived signals, the fraud-prevention layer, logs and backups. Backups are held within the region only; nothing is replicated to Azure’s paired region. West US 3 (Arizona) is maintained as a disaster-recovery region and holds no Customer Content in normal operation; Customer Content would be present there only during and after |
| a declared failover. | |
| Azure OpenAI configuration | Regional (Standard) deployments only, so inference runs in East US 2. Global deployments, which could route inference outside the United States, are not used. Microsoft has approved DeepXL’s exemption from abuse monitoring, so prompts and responses are not retained by Microsoft for that purpose and there is no Microsoft human-review path. Microsoft commits contractually that Azure OpenAI customer data is not used to train Microsoft or third-party models and is not shared with OpenAI. |
|---|---|
| Transfer basis | Microsoft Corporation is certified under the EU–U.S. Data Privacy Framework, verifiable on the public Data Privacy Framework list, and DeepXL relies on the European Commission’s adequacy decision for the Framework for this transfer. If that decision or the certification ceases to cover the transfer, DeepXL will suspend the affected processing or move it to a mechanism that validly covers it within sixty days. |
| Its own sub-processors | Microsoft’s authorised sub-processors, as published in the Microsoft Online Services Subprocessor List on the Microsoft Trust Center, apply as an onward layer. |
That is the whole of Part A. DeepXL uses no third-party document parsing, no model API outside Azure, no external tracing or observability service and no third-party error logging. No consultant or developer outside DeepXL AS holds production access. Customer Content does not appear in e-mail, chat, support tooling or any CRM.
PART B — PROCESSORS OF DEEPXL’S OWN DATA
These providers process personal data for which DeepXL AS is itself the controller — account, user, billing, correspondence and notice data, as described in section 2 of the Privacy Policy. They do not process Customer Content and are not sub-processors under the Data Processing Addendum. They are listed here so that this page and the Privacy Policy give the same account of who processes what.
3. Google
| What it does | DeepXL’s own e-mail, calendar and office tools (Google Workspace). Business contact details and correspondence with customers and users pass through it. |
|---|---|
| Location of processing | Google’s global infrastructure. |
| Transfer basis | Google’s Cloud Data Processing Addendum, which incorporates the Standard Contractual Clauses. |
4. Resend
| Entity | Resend, Inc., United States. |
|---|---|
| What it does | Sending transactional e-mail to customers and users: registration and Order Form confirmations, notices under the API Terms, and invoices. |
| Location of processing | United States. |
| Transfer basis | Resend’s Data Processing Addendum, which incorporates the Standard Contractual Clauses. |
|---|
Not listed, and why. Our bank, and the bank of a payer, act as controllers in their own right when we invoice and receive payment, not as our processors. Professional advisers, auditors and insurers act under a duty of confidence and are not processors of a category belonging on this list.
CHANGES TO THIS LIST
DeepXL gives notice of an intended addition to, or replacement in, Part A at least fifteen (15) days in advance during the Evaluation Period and at least thirty (30) days in advance where an Order Form is in force, by e-mail to the customer’s notice address or by a notice displayed to the Administrator in the account, and updates this page at the same time. A customer may object on reasonable data-protection grounds and, where the objection cannot be resolved, terminate under clause 5.2 of the Data Processing Addendum. Changes to Part B are made by updating this page and, where material, through the change notice in section 10 of the Privacy Policy.
| Version | Effective | Change |
|---|---|---|
| 1.0 | 14 September 2026 | First published version. |