NorthStar AINorthStar AI

Sub-processors

Effective date:
2026-06-19
Last updated:
2026-06-18
Version:
2
ControllerData Protection ContactAddress
NORTH STAR AI S.R.L., a company registered in Romania, VAT RO54842326, with registered office at Sat Ghionea, Comuna Ulmi, Jud. Giurgiu, cf 747 N, acting as data controller for the NorthStar Platform (ns-ai.io, app.ns-ai.io).privacy@ns-ai.ioSat Ghionea, Comuna Ulmi, Jud. Giurgiu, cf 747 N

Overview

This page lists the third-party service providers ("sub-processors") engaged by NorthStar AI S.R.L. to process personal data on our behalf in connection with the Platform.

We engage sub-processors only where:

  • They are bound by written contracts that include the safeguards required by Article 28 GDPR
  • They provide sufficient guarantees of appropriate technical and organizational measures
  • Their processing is necessary for the operation and improvement of the Platform

This list is authoritative and updated as sub-processors are added, removed, or changed. For information about how we use sub-processors, see our Privacy Policy and Data Processing Agreement (DPA).

Current Sub-Processors

ProviderPurposeLocationTransferRole
SupabaseManaged PostgreSQL database, authentication, and file storage for all Platform dataEuropean Union (Frankfurt, Germany)Intra-EU transferSub-processor
OblioInvoice generation and integration with the Romanian ANAF e-Factura systemRomania (intra-EU)Intra-EU transferSub-processor
Termene.roRomanian company verification data from ONRC, including administrator and shareholder informationRomaniaIntra-EU transferData source
VIESEU VAT number validation; company name and VAT-registered statusEuropean UnionIntra-EU transferData source
BNRCurrency exchange rates (no personal data)RomaniaN/A — no personal dataData source
OpenRouterAI model pricing metadata (no user data)United StatesN/A — no personal dataData source
Google (YouTube Transcript API)Public video transcript content when customers ingest YouTube URLs into their Knowledge BaseUnited StatesN/A — public contentData source
Cohere Inc.AI re-ranking model used in Knowledge Base retrieval (semantic relevance scoring on text chunks)United StatesStandard Contractual Clauses (SCC)Sub-processor
VercelWeb application hosting and edge content deliveryUnited States (with EU edge locations)Standard Contractual Clauses (SCC)Sub-processor
InngestWorkflow orchestration and background job processingUnited StatesStandard Contractual Clauses (SCC)Sub-processor
SentryError tracking and application performance monitoringUnited StatesStandard Contractual Clauses (SCC)Sub-processor
ResendTransactional email delivery (account notifications, password resets, billing alerts)United StatesStandard Contractual Clauses (SCC)Sub-processor
FirecrawlWeb content extraction service used when customers ingest web pages into their Knowledge BaseUnited StatesStandard Contractual Clauses (SCC)Sub-processor
Anthropic, PBCLarge language model API (Claude) for AI processing of user-submitted prompts and contentUnited StatesEU-US Data Privacy Framework (DPF)Sub-processor
OpenAI OpCo, LLCLarge language model API (GPT family) for AI processing of user-submitted prompts and contentUnited StatesEU-US Data Privacy Framework (DPF)Sub-processor
Microsoft Azure ADOAuth authentication for users signing in via Microsoft accountsCustomer tenant region (varies) with US backboneEU-US Data Privacy Framework (DPF)Sub-processor
Google OAuthOAuth authentication for users signing in via Google accountsUnited StatesEU-US Data Privacy Framework (DPF)Sub-processor
StripeSubscription billing and payment processing. NorthStar does not store payment instrument data — Stripe handles this in PCI-DSS scope.European Union and United StatesEU-US Data Privacy Framework (DPF)Sub-processor

Third-Party Data Sources (NOT Sub-Processors)

The following third parties provide data to NorthStar from public registries or open APIs. They are not sub-processors because they do not process personal data on our behalf — instead, they are independent sources from which we retrieve information. For data we receive from these sources containing personal data of third parties (e.g., company administrator names from Termene.ro), NorthStar acts as Controller of the received data.

  • Termene.ro (RO) — Romanian company verification data from ONRC, including administrator and shareholder information
  • VIES (European Commission) — EU VAT number validation; company name and VAT-registered status
  • BNR (National Bank of Romania) — Currency exchange rates (no personal data)
  • OpenRouter Inc. — AI model pricing metadata (no user data)
  • Google (YouTube Transcript API) — Public video transcript content when customers ingest YouTube URLs into their Knowledge Base

Excluded from Sub-Processor List

The following services may appear in our infrastructure but are explicitly NOT sub-processors of personal data:

  • UptimeRobot: monitors only health-check endpoints; no personal data
  • Snyk: scans source code and dependencies in CI/CD; no production personal data

Sub-Processor Change Notifications

In accordance with Article 28(2) GDPR and our Data Processing Agreement, we notify customers of changes to this sub-processor list as follows:

  • New sub-processor additions or material changes: at least 30 days' prior notice by email to the designated administrator contact at each customer organization, with a link to the updated version of this page.
  • Sub-processor removals: notice given through the updated version of this page.
  • Right to object: within the 30-day notice period, customer organizations may object to a new sub-processor by contacting privacy@ns-ai.io with the basis of their objection. We will work in good faith to address the objection. If we cannot resolve it satisfactorily, the customer's exclusive remedy is to terminate the affected services in accordance with the applicable agreement.

To subscribe to sub-processor change notifications, ensure that your organization's designated administrator email is current in your account settings.

Locations and DPF Verification

For sub-processors marked `` above, the current EU-US Data Privacy Framework certification status can be verified at https://www.dataprivacyframework.gov/list by searching the sub-processor's name. We monitor DPF certification status and rely on Standard Contractual Clauses (SCCs) as fallback where DPF certification is not in place or has been suspended.

For sub-processors processing personal data outside the European Economic Area, we have conducted Transfer Impact Assessments (TIAs) and implemented supplementary technical and organizational measures, including encryption in transit and at rest, contractual restrictions on government access, and no-training clauses for AI providers.

Contact and Documentation

For our overall data processing practices, see our Privacy Policy and Data Processing Agreement.

Version History

This Sub-Processors Disclosure is published in English. A Romanian summary is available at ns-ai.io/subprocessors?lang=ro. In case of any discrepancy, the English version prevails for legal interpretation.

ControllerData Protection ContactAddress
NORTH STAR AI S.R.L., a company registered in Romania, VAT RO54842326, with registered office at Sat Ghionea, Comuna Ulmi, Jud. Giurgiu, cf 747 N, acting as data controller for the NorthStar Platform (ns-ai.io, app.ns-ai.io).privacy@ns-ai.ioSat Ghionea, Comuna Ulmi, Jud. Giurgiu, cf 747 N

We use strictly necessary cookies to run the platform, and functional cookies (with your consent) to remember your preferences. We do not use advertising or tracking cookies. Cookie Policy