1. What This List Is
AUTONOMi engages a small set of third-party processors to deliver our service. This page is a complete, current list of those processors — what they do, what categories of personal data they process on our behalf, and where that processing takes place. It supplements our Privacy Policy and Data Processing Agreement.
We update this list when sub-processors change. The footer of this page records the date of the last revision. Material changes are announced via email to administrators of dealer accounts at least 30 days before they take effect, giving you a reasonable window to object.
2. Definitions
- Sub-processor — a third party we engage to process personal data on our behalf, in service of providing the AUTONOMi platform to you.
- Personal data — information that identifies or can be used to identify a natural person, as defined under GDPR Article 4 and equivalent regional law.
- Region — primary processing region for the named sub-processor; some providers replicate to additional regions for resilience as documented in their public DPAs.
3. Infrastructure Sub-processors
These providers host the platform, store data, and execute the underlying compute that AUTONOMi depends on.
Google Cloud Platform — Cloud Run
Purpose: Containerized application hosting for all three AUTONOMi services (engine, app, landing).
Data categories: All platform data in transit; ephemeral request/response payloads.
Region: us-east1 (engine), europe-west1 (app + landing).
DPA: Google Cloud Data Processing Addendum
Google Cloud Platform — Cloud SQL (PostgreSQL)
Purpose: Primary application database. Stores dealer records, campaign metadata, audit ledger entries, and authentication state.
Data categories: Account contact information, dealer business data, campaign artifacts, hash-chained decision audit trail.
Region: us-east1.
DPA: Same Google Cloud DPA above.
Google Cloud Platform — Cloud Storage
Purpose: Asset storage (rendered video creative, inventory feed CSVs, generated brand artifacts).
Data categories: Vehicle inventory data, dealer-uploaded brand assets, rendered campaign media.
Region: us-east1 + multi-region replication for public assets.
Google Cloud Platform — Secret Manager + KMS
Purpose: Secret storage for API keys, OAuth tokens, database credentials, and signing keys for the audit ledger.
Data categories: No personal data — credentials and cryptographic material only.
Region: us-east1.
Google Cloud Platform — Cloud Logging + Cloud Monitoring
Purpose: Application and infrastructure observability.
Data categories: Request logs, error traces, performance metrics. Personal data is redacted at the application layer before emission.
Region: us-east1.
4. AI & Model Inference
AEGIS — our autonomous agent system — runs entirely on Anthropic model APIs. No customer data is used to train any third-party model.
Anthropic — Claude API
Purpose: Model inference for AEGIS agents (intelligence pulls, budget allocation, campaign generation, compliance audit, etc.).
Data categories: Dealer-context payloads assembled from your business data, sent as request bodies. Anthropic does not train on data sent via the API per their published commercial terms.
Region: US (Anthropic API region).
DPA: Anthropic Data Processing Addendum
5. Communications & Workflow
Make.com (Integromat)
Purpose: Workflow automation for inbound contact form submissions and notify-me list routing (press inquiries, AXIOM alpha access requests, webinar subscriptions, status subscriptions).
Data categories: Email address, name, free-text notes provided by the visitor.
Region: EU (Czech Republic), US replication.
Stripe
Purpose: Payment processing for subscription billing and one-time charges.
Data categories: Cardholder name, billing address, payment instrument data (Stripe is a PCI-DSS Level 1 processor; we never store full card numbers).
Region:US + EU per Stripe's regional setup.
DPA: Stripe Data Processing Agreement
Google reCAPTCHA
Purpose: Bot detection on public form submissions (contact, signup).
Data categories: IP address, browser fingerprint signals, interaction telemetry assembled by Google.
Region: Global (Google).
6. Observability & Error Tracking
Sentry
Purpose: Application error and exception tracking on the landing and app services.
Data categories:Stack traces, browser metadata, request URL paths. Personal data is scrubbed via Sentry's beforeSend hook before transmission.
Region: US (Sentry SaaS).
DPA: Sentry Data Processing Addendum
7. Ad-Platform Integrations (Pass-Through)
AUTONOMi acts as a pass-through to your authorized ad-platform accounts when you connect them. We don't process or store the underlying ad-platform data ourselves beyond what is required to orchestrate campaigns and report on outcomes. Each platform remains a controller for the data it holds about your account.
- Google Ads — campaign management, Merchant Center feed sync.
- Microsoft Advertising — native Bulk API campaign management.
- Meta Ads — Marketing API + catalog + pixel integration.
- TikTok Ads — Marketing API + catalog integration.
- YouTube — video upload + Google Ads Demand Gen creative.
You authorize these integrations via OAuth; AUTONOMi stores only the access tokens required to act on your behalf.
8. Internal Affiliates
AUTONOMi is operated by AUTONOMi Tech, Inc. We may share data internally between corporate affiliates as needed to provide the service. All affiliates are bound by the same data-protection obligations described in our Privacy Policy.
9. How to Object to a Sub-processor
If you have a legitimate basis for objecting to a new or existing sub-processor — for example, a regulatory restriction on cross-border data transfer that the sub-processor cannot satisfy — please contact dpo@goautonomi.com within 30 days of the change announcement (for new processors) or at any time (for existing processors). We will work with you in good faith to find an alternative arrangement; if no resolution can be reached, you may terminate the relevant service per the terms of our Master Service Agreement.
10. Notification of Changes
When we add, remove, or materially change a sub-processor, we publish the update here and notify dealer-account administrators by email at least 30 days in advance. The "Last Updated" date in the page header reflects the most recent revision.