This list enumerates, one by one, the third parties that process personal data on behalf of Custodio Legal — the subprocessors — with the name under which they contract, the country from which they provide the service, what each one receives, the safeguard the transfer travels under and the retention policy they publish. It is the annex the privacy policy and the Terms of Service point to, and it exists so that a data processing agreement can cite it without having to cite a single clause of a document that is versioned for other reasons.
It is not a document that is signed: it has no consent version of its own. What it does declare is its version and the date of its last review, because a data processing agreement has to be able to require the list to be current.
Google is not on this list. It does not process data on behalf of Custodio Legal or under its instructions: it is an independent controller, and section 15 of the privacy policy says what it receives, under which instrument and before whom rights are exercised.
The subprocessors, one by one
- Railway (United States) — Platform hosting: the servers, the database, the task queue and their backups. It is the processor that hosts every piece of data the platform stores. Safeguard: data processing agreement incorporated into its own terms of service (railway.com/legal/dpa, consulted on September 4, 2026). Retention: the platform's own; the provider declares no separate period.
- Resend (United States) — Transactional email delivery: it receives your email address and the content of the notices. Safeguard: data processing agreement incorporated into its terms (resend.com/legal/dpa, consulted on September 4, 2026).
- Polar.sh (United States) — Payment gateway and billing: it receives the contact email and the name of the firm. Safeguard: data processing agreement incorporated into its terms (polar.sh/legal/data-processing-addendum, consulted on September 4, 2026).
- Nebius B.V., a Dutch company domiciled at Schiphol Boulevard 165, 1118 BG Schiphol, the Netherlands, which operates the Nebius Token Factory service (the Netherlands; inference in the European Union, in Israel or in the United States depending on the model) — Text generation with the GLM-5.3-Flash model for the Artificial Intelligence features. Governing law: that of the Netherlands; forum: the courts of Amsterdam. Safeguard: data processing agreement incorporated into its terms of service, with the Standard Contractual Clauses of Implementing Decision (EU) 2021/914 for transfers outside the European Economic Area. Retention: the next section describes it in full.
- Voyage AI (United States) — Generation of the vector representations (embeddings) of the text of your documents, which make the semantic search of the cited-answer feature (Q&A) possible. Safeguard: published data processing agreement (voyageai.com/dpa, consulted on August 12, 2026). Retention: zero days under the opt-out Custodio Legal has had active since August 12, 2026, which governs going forward and not over earlier submissions.
- Sentry (United States) — Technical error monitoring: it receives the route where the error occurred and your internal user identifier; before sending each event we strip your email, your name and your IP address. Safeguard: data processing agreement incorporated into its terms (sentry.io/legal/dpa, consulted on September 4, 2026).
- Cloudflare (United States) — Delivery and protection network for the site and the application: all traffic between your browser and us passes through its network, so it processes the IP address and the metadata of each connection in transit; it also controls access to our internal documentation. Since September 19, 2026 it also runs the anti-abuse verification of the no-account case lookup (Cloudflare Turnstile): when somebody uses that lookup, their browser talks directly to Cloudflare, which for that check processes — according to its own Turnstile privacy policy, consulted on September 19, 2026 — the IP address, the TLS fingerprint, the
User-Agentheader and the site's public key with its origin, and states that it cannot directly identify an individual from those signals. That verification writes no cookie: Cloudflare publishes that Turnstile does not use cookies to collect or store information of any kind, and thecf_clearancecookie is only issued with "pre-clearance" enabled, which is off on our widget. Safeguard: data processing agreement v6.4, in force since April 3, 2026, incorporated by reference into the subscription contract, which requires notification of an incident without undue delay. - Alternate text generation providers, registered and with no traffic today: Anthropic (United States) and JINGSHENG HENGXING TECHNOLOGY PTE. LTD., domiciled at 10 Anson Road #26-03, Singapore, which operates the z.ai service. Neither of the two receives your data: the platform keeps their connection configured so it can fall back to them if the generation provider stops being available. Activating one would change the processor and the jurisdiction of the transfer, so we would not do it without raising the version of the privacy policy and asking you for a new authorization. Declared retention: Anthropic normally deletes inputs and outputs within thirty days, with the exceptions it publishes; z.ai declares that it does not store API content.
For two of them we publish the full legal entity and its domicile, because they are the ones that declare it in the instruments that govern the engagement: Nebius B.V. and JINGSHENG HENGXING TECHNOLOGY PTE. LTD. For the rest we publish the name under which they contract and the country from which they provide the service, which is what their own terms declare; we do not invent a corporate name the source does not publish.
We do not claim to have negotiated with any of them clauses different from the ones their own terms incorporate, nor to have a separately signed contract, nor that they hold security certifications we have audited.
What we do claim, and it is the opposite of hiding behind a list: we answer for them as if they were us. When the contracting firm is domiciled in Brazil, the data processing agreement adopts the cláusulas-padrão contratuais of Annex II to Resolução CD/ANPD nº 19 of 23 August 2024, and its Clause 18.2, c) states that the importer «será considerado o responsável por eventuais irregularidades praticadas pelo terceiro destinatário da Transferência Posterior». That is not a referral: it is our direct liability towards the Brazilian data subject for whatever any subprocessor on this list does. The same clause, in its point b), requires us to guarantee by written contractual instrument that the safeguards of those clauses reach them, and it is why every row above names the instrument the transfer travels under instead of saying «agreement in force». A subprocessor whose safeguard cannot be named does not go on this list.
The text generation provider and its zero data retention
Zero data retention is enabled in our organization with the text generation provider since September 4, 2026. According to what that provider publishes, with zero data retention enabled the inputs (the text sent to it) and the outputs (the text it returns) are not stored in its systems after each request is processed, are not used for speculative decoding and are not used to train, fine-tune or improve any model, its own or a third party's; the option applies at the organization level and covers all of its projects and endpoints (published Nebius legal guide, «Legal Quick Guide», consulted on September 4, 2026 on the provider's documentation site).
We also tell you, with the same precision, what that guarantee does NOT settle: it is a statement published by the provider and not a control we have audited; it operates going forward and does not reach submissions made before 4 September 2026, over which the default processing of its terms of service continued to apply; its published documents do NOT say whether Zero Data Retention reaches any records the provider may keep to detect abuse of the service, nor whether it applies in the same way to responses delivered as a stream, so we claim neither of those two things; and enabling it is up to us, so if we ever disabled it we would update the privacy policy before doing so.
The provider publicly declares ISO 27001, ISO 27701 and SOC 2 Type II certifications and publishes the list of its own subprocessors, but that is a statement of its own that we have neither audited nor verified against the certificates.
How this list changes
This list is reviewed at least once a year and, in addition, every time a subprocessor enters, leaves or changes, one of them changes jurisdiction or changes its retention configuration. The date of the last review is the one at the top of this document.
When the change alters who processes your data or where, updating this list is not enough: the privacy policy moves up a version and the platform asks you for a new authorization over the text in force, as its section 12 promises. When the change only narrows what an already authorized subprocessor retains, this list is updated and the policy says so, without asking you again.