Subprocessors

The services that power Conferences.Center

To run the platform, we rely on a small set of trusted third-party providers (subprocessors). Each one processes a specific, limited category of data on our behalf. We keep this page current. Customers with a signed agreement receive change notice as specified in that agreement.

Last updated: 2026-07-29

Current subprocessors

Railway

Purpose
API hosting and background workers
Data processed
Application requests and the records needed for API and worker processing
Notes
Primary compute host. Deployment secrets are held server-side.

Railway Postgres

Purpose
Managed PostgreSQL database
Data processed
Application records at rest, including accounts, conferences, submissions, reviews, registrations, and audit logs
Notes
Primary relational database, hosted on Railway's private network. Connections use TLS.

Vercel

Purpose
Frontend hosting and global content delivery network (CDN)
Data processed
Requests for the web application; standard edge/CDN request metadata
Notes
Serves the Next.js frontend. No primary business records are stored here.

Stripe

Purpose
Payment processing
Data processed
Cardholder and payment data entered at checkout; transaction and payout metadata
Notes
Card numbers are handled by Stripe-hosted checkout — the app never stores them. Currently in test mode pre-launch.

AI providers (see the AI subprocessors table below)

Purpose
AI assistance features (advisory, human-in-the-loop) and the site assistant
Data processed
Prompt content needed for a chosen assist. The platform does not add account email addresses, but user-supplied content may contain identifiers.
Notes
Assistance is advisory only; a human makes the final decision. Every approved AI provider is listed individually below, with its processing region and transfer position.

Resend

Purpose
Transactional email delivery
Data processed
Recipient email address and the contents of transactional messages (e.g., confirmations, notifications)
Notes
Used for system email such as receipts, invitations, and account notices.

S3-compatible object storage

Purpose
Storage for uploaded files
Data processed
Uploaded documents such as manuscripts, camera-ready files, and attachments
Notes
Stores user file uploads. Access is scoped and served to authorized users only.

Cloudflare (Turnstile)

Purpose
Bot / abuse prevention on public forms
Data processed
A challenge token plus request metadata (e.g., IP) at signup and other public submissions
Notes
Used to distinguish humans from automated abuse. No business records are stored here.

Sentry

Purpose
Application error monitoring
Data processed
Diagnostic error events and technical context; sensitive fields are scrubbed before sending
Notes
Helps detect and fix failures. Not used for tracking or advertising.

Identity providers (Google, Microsoft, ORCID)

Purpose
Optional single sign-on / social login
Data processed
Authentication requests and the profile fields you consent to share (e.g., name, email)
Notes
Only engaged when a user or organization chooses SSO / social login.

AI subprocessors

Every AI provider the platform can be configured to use is listed here, whether or not it is currently the active one. The platform will not send content to an AI provider that is not on this list — the same approved list drives both this page and the code that makes the request. AI assistance is advisory: a human makes the final decision, and AI output does not by itself accept, reject, rank, or charge a person.

Google Gemini / Google AI

Active — current default

Legal entity
Google LLC
Endpoint
generativelanguage.googleapis.com
Purpose
AI assistance features (advisory, human-in-the-loop) and the public site assistant
Data processed
Prompt content submitted for the chosen assist; Assistant chat messages typed by the visitor; Model output returned to the requester
Processing region
United States and other Google-operated regions; no customer-selected residency region in beta
Transfer mechanism
Google's standard online terms, including its EU Standard Contractual Clauses; no platform-specific transfer assessment has been completed for beta
Retention
Transient processing for the request; Google retains limited data for abuse monitoring per its API terms
Trains on your data
No on the paid tier — Google states paid-tier Gemini API prompts and responses are not used to train its models. The FREE tier is used to improve Google products, so only a paid-tier key may be configured.

OpenAI

Approved — engaged only if configured

Legal entity
OpenAI, L.L.C.
Endpoint
api.openai.com
Purpose
AI assistance features (advisory, human-in-the-loop) and the public site assistant
Data processed
Prompt content submitted for the chosen assist; Assistant chat messages typed by the visitor; Model output returned to the requester
Processing region
United States; no customer-selected residency region in beta
Transfer mechanism
OpenAI's standard API terms and Data Processing Addendum, including its EU Standard Contractual Clauses; no platform-specific transfer assessment has been completed for beta
Retention
OpenAI states API inputs and outputs are retained up to 30 days for abuse monitoring and then deleted, unless a zero-retention arrangement is in place (we do not currently have one)
Trains on your data
No — OpenAI states API inputs and outputs are not used to train its models by default

Anthropic (Claude)

Approved — engaged only if configured

Legal entity
Anthropic, PBC
Endpoint
api.anthropic.com
Purpose
AI assistance features (advisory, human-in-the-loop) and the public site assistant
Data processed
Prompt content submitted for the chosen assist; Assistant chat messages typed by the visitor; Model output returned to the requester
Processing region
United States; no customer-selected residency region in beta
Transfer mechanism
Anthropic's commercial terms and Data Processing Addendum, including its EU Standard Contractual Clauses; no platform-specific transfer assessment has been completed for beta
Retention
Anthropic states API inputs and outputs are retained for a limited trust-and-safety window (up to 30 days in the ordinary case) and longer where a request is flagged
Trains on your data
No — Anthropic states commercial API inputs and outputs are not used to train its models by default

Moonshot AI (Kimi)

Approved — engaged only if configured

Legal entity
Moonshot AI (Beijing Moonshot AI Technology Co., Ltd.)
Endpoint
api.moonshot.cn
Purpose
AI assistance features (advisory, human-in-the-loop) and the public site assistant
Data processed
Prompt content submitted for the chosen assist; Assistant chat messages typed by the visitor; Model output returned to the requester
Processing region
Mainland China — the configured endpoint api.moonshot.cn is operated in the People's Republic of China
Transfer mechanism
None in place. There is no adequacy decision, Standard Contractual Clauses arrangement, or completed transfer assessment covering this provider. Do not configure it for data originating in the EEA/UK or where a transfer mechanism is contractually required.
Retention
Not verified — Moonshot's published retention terms have not been assessed by us
Trains on your data
Not verified — Moonshot's published training terms have not been assessed by us; treat prompts as potentially used for model improvement until reviewed

Getting notified of changes

This page is the current public list of our subprocessors. When a provider changes, we update this page. Advance notice is provided only where a signed customer agreement requires it.

To subscribe to change notifications or request a data processing agreement, email privacy@conferences.center.

Related: Privacy Policy · Data Retention · Security