Vesence Subprocessors

Version 1.1.0 · Effective 2 October 2026

This page lists the subprocessors that Vesence AB engages to process Customer Content under the Vesence Data Processing Agreement for the Service: the workspace at desktop.vesence.com, the Vesence desktop app, and related features and support. The Vesence add-ins for Microsoft Word, Excel, PowerPoint and Outlook, and the web application at app.vesence.com, have their own list at vesence.com/subprocessors.

Subprocessors that process Customer Content

Legal entityRoleWhere Customer Content is processedTransfer mechanismStatus
Cloudflare, Inc. (San Francisco, USA)Hosting and network. Compute: the application, Durable Objects, and each User's cloud computer. Storage: files, chats, the user directory and backups. Logs.EU Workspaces: files, chats and directory in Cloudflare's EU jurisdiction. US Workspaces: files and chats in Cloudflare's US jurisdiction. Cloud computers and their disk snapshots: not location-limited, although every computer started so far ran in the matching region. Requests pass through Cloudflare's global network.EU–US Data Privacy Framework; EU Standard Contractual Clauses (Cloudflare DPA)Required
OpenAI Ireland Ltd (Dublin, Ireland)AI models for EU Workspaces: chat, Agents, web search, chat titles, voice dictationEU, through OpenAI's European data residency (eu.api.openai.com)Not applicable (EEA)Required
OpenAI, L.L.C. (San Francisco, USA)AI models for US Workspaces: same functions as aboveUnited StatesNot applicable for US Workspaces; DPF/SCCs where EU personal data is involvedRequired (US Workspaces)
Amazon Web Services EMEA SARL (Luxembourg)Claude models (Anthropic), through AWS Bedrockeu-central-1 (Frankfurt), for all WorkspacesNot applicable (EEA)Optional: used when a User selects a Claude model

OpenAI retention. EU Workspaces use OpenAI's European data residency endpoint, which OpenAI processes in-region with zero data retention (OpenAI). Vesence also sends every request with storage switched off. To make responses faster and cheaper, Vesence uses OpenAI's extended prompt caching. OpenAI keeps encrypted key/value tensors computed from recent prompts on its machines for up to 24 hours, within the same processing region. The cache is never shared across organizations (OpenAI docs).

Notes

  • Primary region is not residency. Clause 4.2 of the Terms explains this. Files and chats follow the region. Cloud computers, AI inference and Cloudflare's network may not. For US Workspaces, the user directory has a US location hint but no Cloudflare jurisdiction. A small routing index, holding identifiers only, is always kept in the EU.
  • No training, minimal retention. None of the providers above may train on Customer Content. Vesence sends OpenAI requests with storage switched off. AWS states that model providers cannot access Bedrock prompts or completions.
  • Connected Services are not subprocessors. Microsoft 365 and Google Workspace are the Customer's own providers. Vesence accesses them for the User and on the User's instruction. Access tokens are stored encrypted with Cloudflare.
  • Software Users install themselves is not a subprocessor. Examples are third-party AI agents or CLIs installed on a cloud computer. The Customer engages those tools directly (Terms clause 4.3).
  • Service providers that do not process Customer Content. Our payment provider processes billing data, for which Vesence is controller. These providers appear in the Privacy Notice, not on this list.
  • Changes. We update this page before a new subprocessor starts processing Customer Content. Customers can subscribe to updates, and DPA section 7 sets out the right to object.