OpsRabbit Trust Center

Subprocessors and AI Providers

Current provider allocation for the customer-hosted OpsRabbit deployment model.

PublicVersion 1.0September 2026

Overview

This disclosure distinguishes the OpsRabbit product provider from services selected and contracted directly by the customer. That distinction determines who performs due diligence, configures the service and manages contractual data-protection obligations.

The current register is followed by the assessment, change-notification and customer-responsibility process.

Current register

Provider categoryCurrent partyRoleStatus
OpsRabbit product providerApplied AI ConsultingProduct delivery, support and agreed processingProvider / processor as applicable
Cloud / hostingCustomer-selectedRuns customer-hosted infrastructure and storageCustomer-managed provider
Foundation model endpointCustomer-selectedPerforms inference under customer configurationCustomer-managed provider
Customer integrationsCustomer-selectedProvides authorized operational signals and actionsCustomer-managed provider

Change management

If OpsRabbit provider appoints a subprocessor to process customer data, this page will identify the entity, purpose, processing location and relevant service dependency. OpsRabbit provider will provide notice of material additions or replacements as required by the applicable DPA and agreement.

Definitions and decision rules

An OpsRabbit provider-appointed subprocessor is a third party engaged by OpsRabbit provider to process customer personal data for OpsRabbit. A customer-managed provider is selected, contracted or directly controlled by the customer. An AI provider supplies a model or inference endpoint. Classification depends on the contractual relationship and actual processing, not simply on technical interoperability.

Provider assessment

Before appointing a subprocessor, OpsRabbit provider evaluates the service purpose, information involved, hosting and processing locations, security posture, access model, retention and deletion, incident obligations, business continuity, subcontracting and international-transfer implications. Approval must be documented before customer data is enabled.

Required register fields

  • Legal entity and service name
  • Purpose and OpsRabbit feature dependency
  • Categories of data and data subjects
  • Processing and hosting countries
  • Whether the provider is optional or required
  • Retention and deletion behavior
  • Model training or service-improvement settings, when applicable
  • Effective date and material-change notice date

Change notification and objections

Material additions or replacements of OpsRabbit provider-appointed subprocessors are communicated through the contractual notice channel or this register as required by the DPA. Customers may raise a reasoned data-protection objection within the contractual period. OpsRabbit provider will assess configuration alternatives, additional safeguards or, where no reasonable resolution exists, the contractual termination remedy.

Customer obligations

The customer must evaluate and contract with customer-managed cloud, identity, model and integration providers; configure retention and training settings; and notify OpsRabbit provider of restrictions that affect OpsRabbit. OpsRabbit provider will provide product data-flow information needed for that assessment but does not make warranties on behalf of those providers.