Data Processing & Sub-processors

Last updated: 2026-08-01How APERTURESyndicate processes personal data, the sub-processors we rely on, and the safeguards for international transfers under the GDPR.

Data Processing & Sub-processors

This page explains how APERTURESyndicate OÜ processes personal data, lists the third-party service providers ("sub-processors") we rely on to operate the platform, and describes the safeguards that apply when data is handled outside the European Union.

It is referenced by our Privacy Policy and Data Retention policies, and our legal identity is set out on the Company Registration & Imprint page.

This document is maintained in good faith and is pending review by qualified EU/Estonian legal counsel; the English version is the controlling text.

1. Purpose & Scope

This document serves two purposes:

  1. Transparency. It satisfies our information duties under Articles 13 and 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") by disclosing the sub-processors that may handle personal data when you use APERTURESyndicate services.
  2. Data Processing terms. For business customers who use our services to process personal data on their behalf, this page — together with our Terms of Service — forms our standard data processing terms under Article 28 GDPR, including the authorised list of sub-processors below.

The platform is intended for users aged 16 and over. We do not knowingly process the personal data of anyone under 16.

2. Roles: Controller and Processor

  • As controller. For our own consumer-facing services (accounts, profiles, messaging, AI tools, music, payments and related features), APERTURESyndicate OÜ determines the purposes and means of processing and therefore acts as the data controller. How we process this data is described in our Privacy Policy.
  • As processor. Where a business customer uses our services to process personal data for which they are the controller, APERTURESyndicate OÜ acts as a processor on their documented instructions. In that case the standard Article 28 GDPR processor terms apply: we process only on instruction, ensure confidentiality, implement appropriate security, assist with data-subject requests, and engage sub-processors only as described in Section 7.

In both roles, the sub-processors listed in Section 3 may be engaged to deliver the service.

3. Sub-processors

The following third parties may process personal data on our behalf to provide specific platform functions. Each is engaged only for the stated purpose and is bound by data-protection obligations as described in Section 8. The "Region" column indicates where the provider is primarily established or where processing is likely to take place.

The list is not maintained by hand. It is generated from an internal registry that is checked against our source code automatically: every external service the code talks to must have an entry, and an entry whose service no longer appears in the code is flagged for removal. That is how a monitoring provider we had never actually deployed came to be listed here in earlier versions of this page — and how it was removed.

Not every provider below receives directly identifying data in every case; some process only technical or content data. Where an entry is marked (user-directed), the recipient is chosen by you, not by us — see Section 4.

Sub-processorPurposeData categoriesRegionTransfer mechanism
Apple (iTunes Search API)Track metadata lookup when matching lyricsThe search string — track and artist name entered by the userUSSCCs and/or adequacy decision, as applicable
Arbitrary media hosts (yt-dlp) (user-directed)Downloading media from a link pasted by the user in ASVentor and for AI video transcriptionOur server's IP address and the requested URL; no user personal data is transmittedVaries — determined by the userDetermined by the user; we are not a party to any agreement with that recipient
AI inference providers (category)Running the models behind ASAI Mini and ASAI Arc: chat and roleplay responses, coding help, text embeddings, and AI image generation and editingPrompts, conversation context, attachments and tool-call resultsUS and EUSCCs (EU Standard Contractual Clauses)
Speech-to-text providers (category)Transcribing audio you attach or link to, and voice you dictate into the appThe audio itselfUS and EUSCCs (EU Standard Contractual Clauses)
Web search and URL-reading providers (category)Looking something up live so an AI answer can be grounded, reading a page or document at a URL, and reverse image searchThe search query or URL you supplied; a presigned link to an image you asked us to search withUS and EUSCCs (EU Standard Contractual Clauses)
Document parsing providers (category)Converting an uploaded PDF or document into text so an AI feature can read itThe contents of the document you uploadedUS and EUSCCs (EU Standard Contractual Clauses)
Code execution providers (category)Running generated or user-supplied code in an isolated cloud sandboxSource code, files uploaded into the sandbox, and execution outputUS and EUSCCs (EU Standard Contractual Clauses)
CloudflareCDN, edge caching, WAF and DNS in front of all public domains; separately cdnjs as a public stylesheet CDNIP address, User-Agent, request URL and TLS metadata of every visitorUS / globalSCCs (EU Standard Contractual Clauses)
CoinGeckoCryptocurrency market data for an AI toolCoin identifiers only; no personal data is transmittedVariesSCCs and/or adequacy decision, as applicable
DeezerTrack metadata lookup when matching lyricsThe search string — track and artist name entered by the userEU (France)Within EU/EEA — no transfer mechanism required
DiscordRich Presence in the Resonance desktop client — showing the current track on the user's profileTrack title and artist, cover art, playback timestamps; visible to other Discord usersUSSCCs (EU Standard Contractual Clauses)
GitHubSign-in via GitHub OAuth, reading public repositories for AI features, submitting user contributions to a repository, and loading SYNX documentation in the browserEmail and GitHub profile on sign-in; the contents of a user submission; visitor IP when documentation is loadedUSSCCs (EU Standard Contractual Clauses)
GitHub (Copilot MCP)MCP connector to the user's repositories, issues and pull requestsPrompts and tool-call arguments, the user's OAuth token, and the contents of their repositoriesUSSCCs (EU Standard Contractual Clauses)
Google (s2 favicon service)Displaying site icons in the source list of an AI answerVisitor IP address and the domain shown in the sources listUSSCCs (EU Standard Contractual Clauses)
Google (Sign-In)Sign-in and registration via Google OAuthEmail, name, avatar and Google account identifierUSSCCs (EU Standard Contractual Clauses)
Google Drive (MCP)MCP connector to the user's Google Drive filesPrompts and tool-call arguments, OAuth token, and Drive file contentsUSSCCs (EU Standard Contractual Clauses)
Google Firebase Cloud MessagingDelivery of push notifications to mobile applicationsDevice push token, platform, notification title and bodyUSSCCs (EU Standard Contractual Clauses)
Google FontsLoading web fontsVisitor IP address and User-AgentUSSCCs (EU Standard Contractual Clauses)
HetznerApplication hosting, databases and object storage (S3) for media and uploadsAll platform data — accounts, profiles, messages, uploaded files, logsEU (Germany, Finland)Within EU/EEA — no transfer mechanism required
ipapi.coApproximate location lookup by IP when browser geolocation is unavailableThe user's IP address — disclosed implicitly by the request itself, which is made from the browserUSSCCs (EU Standard Contractual Clauses)
jsDelivrLoading a markdown-rendering JS library on SYNX portal pagesVisitor IP address and User-AgentGlobalSCCs and/or adequacy decision, as applicable
LRCLIBLookup of synchronised song lyricsThe search string — track and artist name entered by the userVariesSCCs and/or adequacy decision, as applicable
NotionMCP connector to the user's Notion pages and databases, plus the connector OAuth flowPrompts and tool-call arguments, OAuth token, and Notion page contentsUSSCCs (EU Standard Contractual Clauses)
Open-MeteoWeather data and place geocoding for an AI toolThe place name or coordinates supplied by the userEUWithin EU/EEA — no transfer mechanism required
OpenStreetMap NominatimReverse-geocoding browser coordinates into a city and countryThe user's precise GPS coordinates obtained from the browser Geolocation APIEUWithin EU/EEA — no transfer mechanism required
ResendTransactional email delivery over SMTP — verification codes, account recovery, invitationsRecipient email address, name, and message body including one-time codes and linksUSSCCs (EU Standard Contractual Clauses)
SoundCloudASMusic catalogue integration — track links and cover art fetched through the image optimiserPublic track metadata; no user personal data is transmittedEU (Germany)Within EU/EEA — no transfer mechanism required
SpotifyTrack metadata lookup by link via oEmbed in the ASVentor downloaderThe URL pasted by the userUS / Sweden (EU)SCCs and/or adequacy decision, as applicable
StripePayment processing, subscriptions and webhook handlingEmail, user identifier, payment and billing dataUS / Ireland (EU)SCCs and/or adequacy decision for non-EU processing
SupadataRetrieving YouTube transcripts when public captions are unavailableThe video identifier requested by the userVariesSCCs and/or adequacy decision, as applicable
TelegramPublishing ASMusic releases to a channel and operational alerts about Studio actionsRelease metadata and cover art, including artist names; alert text with the action and operator identifierVariesSCCs and/or adequacy decision, as applicable
TikTokoEmbed link previews and retrieval of video detailsThe video URL supplied by the userVariesSCCs and/or adequacy decision, as applicable
TradingViewEmbedded market chart on the Lysicon Quanture landing pageIP address, User-Agent and page-view data — the widget script executes in the visitor's browserUSSCCs (EU Standard Contractual Clauses)
TuneCoreDistribution of ASMusic releases to third-party stores and streaming services, and royalty reportingArtist and rights-holder name, contact and payee details, release metadata, audio masters and cover artUSSCCs (EU Standard Contractual Clauses)
unpkgLoading the ffmpeg WASM core in the browser for media conversion in ASVentorVisitor IP address and User-AgentGlobalSCCs and/or adequacy decision, as applicable
User-configured MCP servers (user-directed)A user may connect an arbitrary third-party MCP server at a URL of their choosingPrompts and tool-call arguments, model responses, and the bearer token the user suppliesVaries — determined by the userDetermined by the user; we are not a party to any agreement with that recipient
VimeoEmbedding Vimeo videos in user content via iframeIP address and User-Agent of the visitor viewing the page with the embedUSSCCs (EU Standard Contractual Clauses)
YouTube (Google)Fetching captions, oEmbed link previews and video thumbnailsThe video URL or identifier supplied by the user; visitor IP when a thumbnail is loaded by the browserUSSCCs (EU Standard Contractual Clauses)

Why the AI providers appear as categories. Our AI products are ASAI Mini and ASAI Arc. Which models sit behind those names, and which vendors supply the inference, transcription, retrieval, parsing and sandbox infrastructure underneath them, is confidential to our business — that stack is what we build on, and publishing it hands our architecture to anyone who asks. Article 13(1)(e) of the GDPR requires us to identify "recipients or categories of recipients", and the category rows above do exactly that: what leaves the platform, when, to what kind of provider, in which region, and under which transfer safeguard. Every one of them is bound by the same obligations set out in Section 8 — instructions only, no use for their own purposes, no training on your content.

If you are a business customer or a controller whose own compliance obligations require the named list, write to [email protected] and we will provide it under confidentiality.

Three further notes beyond the table:

  • Music distribution. Releases you submit through ASMusic are delivered to stores and streaming services through TuneCore, our distribution partner. This happens outside the platform, under a separate agreement, so it is not visible in our code — it is listed here because it is a real recipient of artist data, not because a scanner found it.
  • Not every feature is used by everyone. Most AI-related entries only receive data if you actually use the feature that calls them.
  • Categories change membership, not meaning. We add, replace and remove providers inside a category as the technology moves. That is not a change of recipient category and does not alter what is sent or how it is protected, so it does not trigger the notice in Section 7 — a change to the categories themselves does.

4. Recipients you choose yourself

Some features let you decide where data goes. The set of possible recipients is therefore open-ended: we cannot publish a complete list, because the list is written by you at the moment you use the feature.

MCP servers you connect. ASAI lets you attach a third-party MCP server by entering its URL and, usually, a token. Once attached, your prompts, the arguments of any tool call the model makes, and the model's responses may be sent to that server. We do not select it, we have no contract with its operator, and we cannot audit what it does with what it receives. The only limits we impose are technical: connections must use HTTPS and must resolve to a public address, so that a connector cannot be pointed at our internal network.

Links you paste into the downloader. ASVentor fetches media from the address you give it. Our server contacts that host, which therefore learns our server's IP address and the URL requested. No account data of yours is sent.

For both of these, the recipient is a separate controller, not our sub-processor. Their handling of the data is governed by their own terms and privacy policy, and you should read those before connecting a server or pasting a link you do not trust. Our own catalogue of pre-integrated connectors (listed individually in the table above) is different: those we selected, and they are covered by the safeguards in Sections 5 and 8.

5. International Transfers

Personal data is hosted within the European Union. Where a sub-processor in Section 3 processes data outside the EU/European Economic Area, we rely on one or more of the safeguards permitted by Chapter V of the GDPR:

  • the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), supplemented by transfer risk assessments and additional technical and organisational measures where appropriate; and/or
  • an adequacy decision of the European Commission, where one applies to the recipient country or framework.

For processing that takes place entirely within the EU/EEA (for example, our core hosting), no additional transfer mechanism is required. For the user-directed recipients in Section 4 we cannot provide a transfer mechanism, because we are not a party to that relationship — the choice, and its consequences, are yours.

6. Security Measures

We apply appropriate technical and organisational measures to protect personal data, proportionate to the risk, including:

  • Encryption in transit for all traffic, and encryption at rest for specific high-risk secrets. What is and is not encrypted at the application layer is described precisely on our Security page.
  • Access controls with authentication and authorisation, applied on a least-privilege basis so that staff and systems access only what is necessary.
  • Logical separation of data between services: each service can read only its own database schema.
  • Logging and monitoring to detect and respond to security events.
  • Vendor diligence before engaging a sub-processor, and contractual data-protection commitments thereafter.

We continually review and improve these measures. We do not publish low-level configuration details, as doing so would itself create a security risk.

7. Changes to Sub-processors

We may add or replace a sub-processor as the platform evolves. When we make a material change to the list in Section 3:

  • We update this page and revise the "Last updated" date.
  • For business customers acting as controllers, we provide reasonable advance notice of a new or replacement sub-processor before it begins processing their data.
  • A controller who has a legitimate data-protection concern about a new sub-processor may object by writing to the contact in Section 9 within the notice period. We will work in good faith to address the concern; where it cannot be resolved, the controller may terminate the affected service in accordance with the Terms of Service.

8. Sub-processor Obligations

Each sub-processor is engaged under a written agreement that imposes data-protection obligations equivalent in substance to those we are bound by, as required by Article 28(4) GDPR. In particular, each sub-processor is required to:

  • process personal data only for the agreed purpose and on documented instructions;
  • maintain appropriate technical and organisational security measures;
  • ensure that personnel handling personal data are bound by confidentiality;
  • support compliance with data-subject rights and breach notification; and
  • apply a valid transfer mechanism (see Section 5) for any processing outside the EU/EEA.

We remain responsible to you for the performance of our sub-processors' data-protection obligations. This does not extend to the recipients in Section 4, which you engage directly.

9. Data-Subject Assistance & Contact

We assist with requests to exercise data-subject rights under the GDPR — including access, rectification, erasure, restriction, portability, and objection. Details of how these rights work and how data is kept are set out in our GDPR & Your Data page and Data Retention policy.

We operate a single official contact address. For any request or question about this document, our processing, or our sub-processors, email [email protected] (use the subject line "GDPR request" for data-subject requests).

PurposeContact
All inquiries (data processing, GDPR requests, sub-processors)[email protected]
Websiteaperturesyndicate.com

APERTURESyndicate OÜ is established in the Republic of Estonia (EU); this document and our processing are governed by the law of Estonia and the GDPR, with the courts of Tallinn having jurisdiction. See Company Registration & Imprint for full legal-entity details.

Version history

  • v1.3 — 2026-08-01 — AI providers are now listed by category, not by name. The vendors supplying inference, speech-to-text, retrieval, document parsing and code sandboxing are the infrastructure behind ASAI Mini and ASAI Arc, and that stack is confidential to our business. Their individual rows were replaced by five category rows stating what is sent, when, to what kind of provider, in which region and under which safeguard — the "categories of recipients" disclosure Article 13(1)(e) of the GDPR provides for. Named list available to business customers on request, under confidentiality. Everything outside the AI stack is still named individually.
  • v1.2 — 2026-08-01 — Separate vision-inference route retired on 2026-07-31; requests containing images now follow the same path as every other model request, and the registry check confirms no call to that provider remains anywhere in the code. Listing a recipient we no longer send data to is as wrong as omitting one we do. Speech-to-text entries corrected to describe what they actually do — transcription only.
  • v1.1 — 2026-07-31 — Sub-processor table regenerated from the machine-checked registry: Sentry removed (never deployed), TuneCore added, and a new section added for recipients you choose yourself.
  • v1.0 — 2026-06-22 — Initial publication.
Data Processing & Sub-processors | AS Docs