Data Processing & Sub-processors
This page explains how APERTURESyndicate OÜ processes personal data, lists the third-party service providers ("sub-processors") we rely on to operate the platform, and describes the safeguards that apply when data is handled outside the European Union.
It is referenced by our Privacy Policy and Data Retention policies, and our legal identity is set out on the Company Registration & Imprint page.
This document is maintained in good faith and is pending review by qualified EU/Estonian legal counsel; the English version is the controlling text.
1. Purpose & Scope
This document serves two purposes:
- Transparency. It satisfies our information duties under Articles 13 and 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") by disclosing the sub-processors that may handle personal data when you use APERTURESyndicate services.
- Data Processing terms. For business customers who use our services to process personal data on their behalf, this page — together with our Terms of Service — forms our standard data processing terms under Article 28 GDPR, including the authorised list of sub-processors below.
The platform is intended for users aged 16 and over. We do not knowingly process the personal data of anyone under 16.
2. Roles: Controller and Processor
- As controller. For our own consumer-facing services (accounts, profiles, messaging, AI tools, music, payments and related features), APERTURESyndicate OÜ determines the purposes and means of processing and therefore acts as the data controller. How we process this data is described in our Privacy Policy.
- As processor. Where a business customer uses our services to process personal data for which they are the controller, APERTURESyndicate OÜ acts as a processor on their documented instructions. In that case the standard Article 28 GDPR processor terms apply: we process only on instruction, ensure confidentiality, implement appropriate security, assist with data-subject requests, and engage sub-processors only as described in Section 7.
In both roles, the sub-processors listed in Section 3 may be engaged to deliver the service.
3. Sub-processors
The following third parties may process personal data on our behalf to provide specific platform functions. Each is engaged only for the stated purpose and is bound by data-protection obligations as described in Section 8. The "Region" column indicates where the provider is primarily established or where processing is likely to take place.
The list is not maintained by hand. It is generated from an internal registry that is checked against our source code automatically: every external service the code talks to must have an entry, and an entry whose service no longer appears in the code is flagged for removal. That is how a monitoring provider we had never actually deployed came to be listed here in earlier versions of this page — and how it was removed.
Not every provider below receives directly identifying data in every case; some process only technical or content data. Where an entry is marked (user-directed), the recipient is chosen by you, not by us — see Section 4.
| Sub-processor | Purpose | Data categories | Region | Transfer mechanism |
|---|---|---|---|---|
| Apple (iTunes Search API) | Track metadata lookup when matching lyrics | The search string — track and artist name entered by the user | US | SCCs and/or adequacy decision, as applicable |
| Arbitrary media hosts (yt-dlp) (user-directed) | Downloading media from a link pasted by the user in ASVentor and for AI video transcription | Our server's IP address and the requested URL; no user personal data is transmitted | Varies — determined by the user | Determined by the user; we are not a party to any agreement with that recipient |
| AI inference providers (category) | Running the models behind ASAI Mini and ASAI Arc: chat and roleplay responses, coding help, text embeddings, and AI image generation and editing | Prompts, conversation context, attachments and tool-call results | US and EU | SCCs (EU Standard Contractual Clauses) |
| Speech-to-text providers (category) | Transcribing audio you attach or link to, and voice you dictate into the app | The audio itself | US and EU | SCCs (EU Standard Contractual Clauses) |
| Web search and URL-reading providers (category) | Looking something up live so an AI answer can be grounded, reading a page or document at a URL, and reverse image search | The search query or URL you supplied; a presigned link to an image you asked us to search with | US and EU | SCCs (EU Standard Contractual Clauses) |
| Document parsing providers (category) | Converting an uploaded PDF or document into text so an AI feature can read it | The contents of the document you uploaded | US and EU | SCCs (EU Standard Contractual Clauses) |
| Code execution providers (category) | Running generated or user-supplied code in an isolated cloud sandbox | Source code, files uploaded into the sandbox, and execution output | US and EU | SCCs (EU Standard Contractual Clauses) |
| Cloudflare | CDN, edge caching, WAF and DNS in front of all public domains; separately cdnjs as a public stylesheet CDN | IP address, User-Agent, request URL and TLS metadata of every visitor | US / global | SCCs (EU Standard Contractual Clauses) |
| CoinGecko | Cryptocurrency market data for an AI tool | Coin identifiers only; no personal data is transmitted | Varies | SCCs and/or adequacy decision, as applicable |
| Deezer | Track metadata lookup when matching lyrics | The search string — track and artist name entered by the user | EU (France) | Within EU/EEA — no transfer mechanism required |
| Discord | Rich Presence in the Resonance desktop client — showing the current track on the user's profile | Track title and artist, cover art, playback timestamps; visible to other Discord users | US | SCCs (EU Standard Contractual Clauses) |
| GitHub | Sign-in via GitHub OAuth, reading public repositories for AI features, submitting user contributions to a repository, and loading SYNX documentation in the browser | Email and GitHub profile on sign-in; the contents of a user submission; visitor IP when documentation is loaded | US | SCCs (EU Standard Contractual Clauses) |
| GitHub (Copilot MCP) | MCP connector to the user's repositories, issues and pull requests | Prompts and tool-call arguments, the user's OAuth token, and the contents of their repositories | US | SCCs (EU Standard Contractual Clauses) |
| Google (s2 favicon service) | Displaying site icons in the source list of an AI answer | Visitor IP address and the domain shown in the sources list | US | SCCs (EU Standard Contractual Clauses) |
| Google (Sign-In) | Sign-in and registration via Google OAuth | Email, name, avatar and Google account identifier | US | SCCs (EU Standard Contractual Clauses) |
| Google Drive (MCP) | MCP connector to the user's Google Drive files | Prompts and tool-call arguments, OAuth token, and Drive file contents | US | SCCs (EU Standard Contractual Clauses) |
| Google Firebase Cloud Messaging | Delivery of push notifications to mobile applications | Device push token, platform, notification title and body | US | SCCs (EU Standard Contractual Clauses) |
| Google Fonts | Loading web fonts | Visitor IP address and User-Agent | US | SCCs (EU Standard Contractual Clauses) |
| Hetzner | Application hosting, databases and object storage (S3) for media and uploads | All platform data — accounts, profiles, messages, uploaded files, logs | EU (Germany, Finland) | Within EU/EEA — no transfer mechanism required |
| ipapi.co | Approximate location lookup by IP when browser geolocation is unavailable | The user's IP address — disclosed implicitly by the request itself, which is made from the browser | US | SCCs (EU Standard Contractual Clauses) |
| jsDelivr | Loading a markdown-rendering JS library on SYNX portal pages | Visitor IP address and User-Agent | Global | SCCs and/or adequacy decision, as applicable |
| LRCLIB | Lookup of synchronised song lyrics | The search string — track and artist name entered by the user | Varies | SCCs and/or adequacy decision, as applicable |
| Notion | MCP connector to the user's Notion pages and databases, plus the connector OAuth flow | Prompts and tool-call arguments, OAuth token, and Notion page contents | US | SCCs (EU Standard Contractual Clauses) |
| Open-Meteo | Weather data and place geocoding for an AI tool | The place name or coordinates supplied by the user | EU | Within EU/EEA — no transfer mechanism required |
| OpenStreetMap Nominatim | Reverse-geocoding browser coordinates into a city and country | The user's precise GPS coordinates obtained from the browser Geolocation API | EU | Within EU/EEA — no transfer mechanism required |
| Resend | Transactional email delivery over SMTP — verification codes, account recovery, invitations | Recipient email address, name, and message body including one-time codes and links | US | SCCs (EU Standard Contractual Clauses) |
| SoundCloud | ASMusic catalogue integration — track links and cover art fetched through the image optimiser | Public track metadata; no user personal data is transmitted | EU (Germany) | Within EU/EEA — no transfer mechanism required |
| Spotify | Track metadata lookup by link via oEmbed in the ASVentor downloader | The URL pasted by the user | US / Sweden (EU) | SCCs and/or adequacy decision, as applicable |
| Stripe | Payment processing, subscriptions and webhook handling | Email, user identifier, payment and billing data | US / Ireland (EU) | SCCs and/or adequacy decision for non-EU processing |
| Supadata | Retrieving YouTube transcripts when public captions are unavailable | The video identifier requested by the user | Varies | SCCs and/or adequacy decision, as applicable |
| Telegram | Publishing ASMusic releases to a channel and operational alerts about Studio actions | Release metadata and cover art, including artist names; alert text with the action and operator identifier | Varies | SCCs and/or adequacy decision, as applicable |
| TikTok | oEmbed link previews and retrieval of video details | The video URL supplied by the user | Varies | SCCs and/or adequacy decision, as applicable |
| TradingView | Embedded market chart on the Lysicon Quanture landing page | IP address, User-Agent and page-view data — the widget script executes in the visitor's browser | US | SCCs (EU Standard Contractual Clauses) |
| TuneCore | Distribution of ASMusic releases to third-party stores and streaming services, and royalty reporting | Artist and rights-holder name, contact and payee details, release metadata, audio masters and cover art | US | SCCs (EU Standard Contractual Clauses) |
| unpkg | Loading the ffmpeg WASM core in the browser for media conversion in ASVentor | Visitor IP address and User-Agent | Global | SCCs and/or adequacy decision, as applicable |
| User-configured MCP servers (user-directed) | A user may connect an arbitrary third-party MCP server at a URL of their choosing | Prompts and tool-call arguments, model responses, and the bearer token the user supplies | Varies — determined by the user | Determined by the user; we are not a party to any agreement with that recipient |
| Vimeo | Embedding Vimeo videos in user content via iframe | IP address and User-Agent of the visitor viewing the page with the embed | US | SCCs (EU Standard Contractual Clauses) |
| YouTube (Google) | Fetching captions, oEmbed link previews and video thumbnails | The video URL or identifier supplied by the user; visitor IP when a thumbnail is loaded by the browser | US | SCCs (EU Standard Contractual Clauses) |
Why the AI providers appear as categories. Our AI products are ASAI Mini and ASAI Arc. Which models sit behind those names, and which vendors supply the inference, transcription, retrieval, parsing and sandbox infrastructure underneath them, is confidential to our business — that stack is what we build on, and publishing it hands our architecture to anyone who asks. Article 13(1)(e) of the GDPR requires us to identify "recipients or categories of recipients", and the category rows above do exactly that: what leaves the platform, when, to what kind of provider, in which region, and under which transfer safeguard. Every one of them is bound by the same obligations set out in Section 8 — instructions only, no use for their own purposes, no training on your content.
If you are a business customer or a controller whose own compliance obligations require the named list, write to [email protected] and we will provide it under confidentiality.
Three further notes beyond the table:
- Music distribution. Releases you submit through ASMusic are delivered to stores and streaming services through TuneCore, our distribution partner. This happens outside the platform, under a separate agreement, so it is not visible in our code — it is listed here because it is a real recipient of artist data, not because a scanner found it.
- Not every feature is used by everyone. Most AI-related entries only receive data if you actually use the feature that calls them.
- Categories change membership, not meaning. We add, replace and remove providers inside a category as the technology moves. That is not a change of recipient category and does not alter what is sent or how it is protected, so it does not trigger the notice in Section 7 — a change to the categories themselves does.
4. Recipients you choose yourself
Some features let you decide where data goes. The set of possible recipients is therefore open-ended: we cannot publish a complete list, because the list is written by you at the moment you use the feature.
MCP servers you connect. ASAI lets you attach a third-party MCP server by entering its URL and, usually, a token. Once attached, your prompts, the arguments of any tool call the model makes, and the model's responses may be sent to that server. We do not select it, we have no contract with its operator, and we cannot audit what it does with what it receives. The only limits we impose are technical: connections must use HTTPS and must resolve to a public address, so that a connector cannot be pointed at our internal network.
Links you paste into the downloader. ASVentor fetches media from the address you give it. Our server contacts that host, which therefore learns our server's IP address and the URL requested. No account data of yours is sent.
For both of these, the recipient is a separate controller, not our sub-processor. Their handling of the data is governed by their own terms and privacy policy, and you should read those before connecting a server or pasting a link you do not trust. Our own catalogue of pre-integrated connectors (listed individually in the table above) is different: those we selected, and they are covered by the safeguards in Sections 5 and 8.
5. International Transfers
Personal data is hosted within the European Union. Where a sub-processor in Section 3 processes data outside the EU/European Economic Area, we rely on one or more of the safeguards permitted by Chapter V of the GDPR:
- the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), supplemented by transfer risk assessments and additional technical and organisational measures where appropriate; and/or
- an adequacy decision of the European Commission, where one applies to the recipient country or framework.
For processing that takes place entirely within the EU/EEA (for example, our core hosting), no additional transfer mechanism is required. For the user-directed recipients in Section 4 we cannot provide a transfer mechanism, because we are not a party to that relationship — the choice, and its consequences, are yours.
6. Security Measures
We apply appropriate technical and organisational measures to protect personal data, proportionate to the risk, including:
- Encryption in transit for all traffic, and encryption at rest for specific high-risk secrets. What is and is not encrypted at the application layer is described precisely on our Security page.
- Access controls with authentication and authorisation, applied on a least-privilege basis so that staff and systems access only what is necessary.
- Logical separation of data between services: each service can read only its own database schema.
- Logging and monitoring to detect and respond to security events.
- Vendor diligence before engaging a sub-processor, and contractual data-protection commitments thereafter.
We continually review and improve these measures. We do not publish low-level configuration details, as doing so would itself create a security risk.
7. Changes to Sub-processors
We may add or replace a sub-processor as the platform evolves. When we make a material change to the list in Section 3:
- We update this page and revise the "Last updated" date.
- For business customers acting as controllers, we provide reasonable advance notice of a new or replacement sub-processor before it begins processing their data.
- A controller who has a legitimate data-protection concern about a new sub-processor may object by writing to the contact in Section 9 within the notice period. We will work in good faith to address the concern; where it cannot be resolved, the controller may terminate the affected service in accordance with the Terms of Service.
8. Sub-processor Obligations
Each sub-processor is engaged under a written agreement that imposes data-protection obligations equivalent in substance to those we are bound by, as required by Article 28(4) GDPR. In particular, each sub-processor is required to:
- process personal data only for the agreed purpose and on documented instructions;
- maintain appropriate technical and organisational security measures;
- ensure that personnel handling personal data are bound by confidentiality;
- support compliance with data-subject rights and breach notification; and
- apply a valid transfer mechanism (see Section 5) for any processing outside the EU/EEA.
We remain responsible to you for the performance of our sub-processors' data-protection obligations. This does not extend to the recipients in Section 4, which you engage directly.
9. Data-Subject Assistance & Contact
We assist with requests to exercise data-subject rights under the GDPR — including access, rectification, erasure, restriction, portability, and objection. Details of how these rights work and how data is kept are set out in our GDPR & Your Data page and Data Retention policy.
We operate a single official contact address. For any request or question about this document, our processing, or our sub-processors, email [email protected] (use the subject line "GDPR request" for data-subject requests).
| Purpose | Contact |
|---|---|
| All inquiries (data processing, GDPR requests, sub-processors) | [email protected] |
| Website | aperturesyndicate.com |
APERTURESyndicate OÜ is established in the Republic of Estonia (EU); this document and our processing are governed by the law of Estonia and the GDPR, with the courts of Tallinn having jurisdiction. See Company Registration & Imprint for full legal-entity details.
Version history
- v1.3 — 2026-08-01 — AI providers are now listed by category, not by name. The vendors supplying inference, speech-to-text, retrieval, document parsing and code sandboxing are the infrastructure behind ASAI Mini and ASAI Arc, and that stack is confidential to our business. Their individual rows were replaced by five category rows stating what is sent, when, to what kind of provider, in which region and under which safeguard — the "categories of recipients" disclosure Article 13(1)(e) of the GDPR provides for. Named list available to business customers on request, under confidentiality. Everything outside the AI stack is still named individually.
- v1.2 — 2026-08-01 — Separate vision-inference route retired on 2026-07-31; requests containing images now follow the same path as every other model request, and the registry check confirms no call to that provider remains anywhere in the code. Listing a recipient we no longer send data to is as wrong as omitting one we do. Speech-to-text entries corrected to describe what they actually do — transcription only.
- v1.1 — 2026-07-31 — Sub-processor table regenerated from the machine-checked registry: Sentry removed (never deployed), TuneCore added, and a new section added for recipients you choose yourself.
- v1.0 — 2026-06-22 — Initial publication.