Sub-processors
This page explains the third-party providers that Senex Intelligence Ltd (Senex) uses to process Customer Data for Mosaic Theory AI.
1. Current default posture
Cloudflare is Senex's core infrastructure provider and the sole Approved Sub-processor for the default locked pilot and Entry-tier configuration.
Senex configures Customer Content storage and other persistent data stores for European Union jurisdiction where supported by the relevant Cloudflare service and confirmed in Senex's technical configuration. Senex also configures the identified document-parsing Containers and consolidation/parser-pool scheduler Durable Objects with Cloudflare European Union jurisdiction constraints, as production-verified by Senex.
This is not a blanket European-Union-only processing claim. Cloudflare edge compute, artificial-intelligence inference, vector search, queues, logs, analytics, operational metadata, support, and administrative processing may be subject to Cloudflare's global network, service-specific regional controls, and documented exceptions. Unless an Order Form expressly states otherwise, Senex does not represent that every Cloudflare processing operation, metadata item, log, inference operation, or vector-search operation occurs only in the European Union.
2. Approved Sub-processor
| Sub-processor | Purpose | Location and regional posture | Customer Data processed | Status |
|---|---|---|---|---|
| Cloudflare | Core application infrastructure, edge compute, Workers AI inference, databases, object storage, vector search-index infrastructure, key-value storage, queues, Durable Objects, Containers, security controls, analytics/logging, and audit-log storage |
Cloudflare global network with service-specific regional
controls. Senex configures Customer Content storage, audit
archives, D1 tenant/application data, worker-log object
storage, the identified document-parsing Containers, and the
identified consolidation/parser-pool scheduler Durable Objects
for European Union jurisdiction where supported and
production-verified. Worker-log object-storage residency
depends on delivery through the European Union S3-compatible
endpoint into an eu-jurisdiction R2 bucket; it is
not a jurisdiction binding on Logpush or log generation.
General edge compute, artificial-intelligence inference,
vector search, key-value storage, queues, access paths, log
generation and pre-delivery processing, analytics, support,
administrative processing, billing/debug records, identifiers,
and operational metadata may remain global or subject to
documented service-specific exceptions.
| Customer Content, extracted text, derived search data, prompts, questions, retrieved passages, Outputs, user/account data, audit and security logs, operational metadata, and support data where applicable | Approved for the Cloudflare-only default configuration |
3. Cloudflare service-by-service map
| Cloudflare service | Mosaic Theory AI usage | Current publication position |
|---|---|---|
| R2 object storage | Customer documents and retention-protected audit archives | European Union-jurisdiction buckets where supported and confirmed. The audit bucket uses an age-based bucket-lock retention rule. This is not represented as per-object compliance-mode write-once-read-many storage. |
| D1 | Per-tenant settings, application records, audit index, billing, and metadata | European Union-jurisdiction databases where supported and confirmed. Workers may still access a jurisdiction-constrained database from Cloudflare's global network. D1 Time Travel retains restorable history for up to 30 days on Workers Paid plans or 7 days on Workers Free plans. |
| Workers | Gateway and per-tenant application compute | Global edge network unless a separate Order Form expressly states and configures a narrower commitment. |
| Workers AI | Query embeddings and answer generation in the default Cloudflare-only configuration | Cloudflare service-specific/global processing. Not represented as European-Union-only. |
| Vectorize | Per-tenant vector search | Cloudflare service-specific/global processing. Not represented as European-Union-only. |
| KV | Transient cache and state | Cloudflare service-specific/global processing. Not represented as European-Union-only. |
| Queues | Asynchronous ingest dispatch | Cloudflare service-specific/global processing. Queue messages are intended to contain operational metadata, such as tenant identifiers, document identifiers, and job state, not raw Customer Content. |
| Durable Objects — consolidation and parser-pool schedulers | Scheduling, debounce state, parser-pool coordination, and related operational state | The identified production namespaces are created through Cloudflare European Union-jurisdiction bindings. Those Durable Objects run and persist state in the European Union. Workers may invoke them from Cloudflare's global network, and Durable Object identifiers plus billing/debugging or operational metadata may be logged outside the jurisdiction. Scheduler state is intended to contain opaque operational metadata rather than raw Customer Content. |
| Containers — document parsing | Transient document conversion, parsing, extraction, and normalisation |
The identified production Containers are configured with
Cloudflare's eu jurisdiction placement constraint,
restricting container execution to European regions. They may
process Customer Content transiently but are not intended to
persist it. Worker access paths, deployment/control-plane data,
support, billing/debugging, and operational metadata are not
represented as European-Union-only.
|
| Logpush to R2 | Worker logs |
Worker-log object storage is localised by delivering Logpush
output through Cloudflare's S3-compatible European Union
jurisdiction endpoint into an R2 bucket created in the
eu jurisdiction. This is a destination-storage
control, not a jurisdiction binding on Logpush or log
generation, and does not establish that all processing before
delivery is European-Union-only. Log generation, transport
before delivery, analytics, support, administrative handling,
and operational metadata may remain service-specific or global.
|
4. Conditional Sub-processors — optional, DPA-gated features
The providers below are not part of the Cloudflare-only default configuration. Senex uses them for Customer Data only where an authorised Customer representative has affirmatively accepted the current, versioned feature terms through binding electronic acceptance or another written authorisation, and Senex has recorded durable evidence of that authorisation.
A separately signed amendment or Order Form is required only where that document is the agreed authorisation basis. Electronic acceptance must still identify the Customer legal entity, accepting representative, exact terms version and disclosure accepted, scope, and timestamp.
These conditional features are not approved for Protected Health Information subject to the United States Health Insurance Portability and Accountability Act unless Senex has executed a separate Business Associate Agreement, confirmed the complete sub-processor agreement chain, and approved an eligible configuration in writing. The ordinary feature-consent flow is not such an approval.
| Provider | Feature key | Purpose | Location / regional posture | Customer Data processed | Required feature terms | Status |
|---|---|---|---|---|---|---|
| Anthropic | anthropic_platform | Senex-managed artificial-intelligence model processing using a Senex-held Anthropic API/platform account, including answer generation, summarisation, classification, extraction, reasoning, citation-aware response generation, and ingest-time corpus preparation such as generating descriptive titles for document artifacts and converting image-only tables or visuals into searchable text | Anthropic service locations, including the United States and other locations used by Anthropic. Not Cloudflare-only and not represented as European-Union-only or Swiss-only. | Prompts, questions, retrieved passages, document excerpts, bounded adjacent context, tables, titles, document-derived image crops or visual regions, source metadata, outputs, request metadata, and operational metadata needed for the authorised feature | anthropic-platform-dpa-v2026-07-20 at
/legal/dpa/amendments/anthropic-platform-v2026-07-20 | Conditional only. Disabled unless Customer has accepted the current feature terms and Senex has a valid consent evidence record. May operate at query time or automatically during authorised document ingest. Not approved for Protected Health Information or Health Insurance Portability and Accountability Act-regulated workloads under the ordinary configuration. |
| Modal Labs, Inc. | modal_ingest | Optional ingest processing, document conversion, parsing, text extraction, table/layout extraction, file normalisation, and transient job execution | United States or other Modal service locations, subject to configured region settings where available and expressly committed. Not Cloudflare-only and not represented as European-Union-only or Swiss-only unless an Order Form expressly says so. | Uploaded documents, filenames, file metadata, document identifiers, job identifiers, extracted text, conversion outputs, parse errors, and operational metadata needed for the authorised ingest job | modal-ingest-dpa-v2026-07-07 at
/legal/dpa/amendments/modal-ingest-v2026-07-07 | Conditional only. Disabled unless Customer has accepted the current feature terms and Senex has a valid consent evidence record. Not approved for Protected Health Information or Health Insurance Portability and Accountability Act-regulated workloads under the ordinary configuration. |
Invalid or stale authorisation
A placeholder page, “terms coming soon” label, stale terms version, missing consent evidence reference, mismatched disclosure hash, or acceptance by a user who has not represented that they can bind the Customer is not valid Customer authorisation.
If a separate signed amendment, Order Form, or written instruction is the stated authorisation basis, the corresponding external agreement reference must also be recorded.
5. Not approved or enabled by default
The following providers or configurations are not approved for the Cloudflare-only default configuration unless separately authorised under the customer agreement, Data Processing Agreement, product setting, or Order Form.
| Provider or configuration | Potential purpose | Status |
|---|---|---|
| Anthropic BYOK | Customer-enabled answer generation using Customer's own Anthropic API/Console account and application programming interface key | Not enabled by default. Customer must expressly authorise transmission to Anthropic, confirm the applicable Anthropic commercial/API and data-processing terms, and consider any additional transfer or sector safeguards required for its use case. |
Anthropic public-source retrieval / public_web_search | Public web search/fetch and possible persistent ingestion of external public materials |
Not covered merely by anthropic_platform. Requires
its own published, versioned Public Source Retrieval terms, the
same ordinary-configuration Protected Health Information
exclusion, and separate affirmative tenant authorisation before
production egress.
|
| cloudscale.ch or another Swiss-sovereign hosting provider | Future Enterprise-tier hosting and compute substrate | Not active for the default Entry tier. Enterprise-specific terms require separate review before first Enterprise customer signature. |
| OpenAI or Google artificial-intelligence services | Artificial-intelligence model processing | Not used for Customer Data unless Customer expressly authorises the provider through a binding written or electronic instruction under current versioned terms. |
| Protected Health Information / Health Insurance Portability and Accountability Act-regulated configuration | Processing that would require Senex or a sub-processor to act under a Business Associate Agreement | Not supported under the ordinary Service or conditional-provider clickwrap. Requires a separately executed Business Associate Agreement, verified eligible provider configuration, and express written approval by Senex before any such data is submitted. |
6. New or replacement Sub-processors
Senex will notify Customers at least 30 days before appointing a new or replacement Approved Sub-processor, unless shorter notice is reasonably necessary to maintain the security, availability, or continuity of the Service.
Customers may object to a new or replacement Approved Sub-processor on reasonable data-protection grounds by notifying Senex within 15 days after receiving notice. The parties will work in good faith to resolve the objection.
7. Contact
Questions about sub-processors or data-processing terms can be sent to hello@senex.ch.