Note on legal entity. The customer of record for this annex is the Genie entity named in the order form. See §0 of the customer compliance package for the full legal entity name.
A.1 Scope
The subprocessors listed here are engaged by the processor named in the order form to provide the Genie service. For each listed subprocessor, a signed Data Processing Agreement (DPA) or Standard Contractual Clauses (SCC) are in place.A.2 Default path and third-country strategy
Genie processes personal data in the EU by default. For GDPR-sensitive setups — in particular Teams workspaces and larger enterprise customers — the following applies:- EU-only default (Teams). LLM inference for Teams accounts is configured to route via AWS Bedrock (
eu-central-1, Germany). Under this configuration, prompts and completions are, to our knowledge, not processed outside the EU. The remaining core services (AWS Aurora, S3, DynamoDB, KMS, Auth0, Vercel Functions, Resend, Supabase provisioning) are likewise EU-resident. We recommend this path as the enterprise and GDPR default. - Contractual no-training-on-inputs commitments. Where LLM providers receive live customer data, we hold contractual zero-data-retention / no-training-on-inputs commitments (Anthropic, OpenAI, AWS Bedrock, Google Vertex). These commitments are backed by the respective DPAs and provider statements; auditable evidence (DPA excerpts, provider statements) is available on request via
privacy@genie-app.de. For Google Vertex, the relevant commitment is publicly documented in the Google Cloud Data Processing Addendum (CDPA), which covers Google Cloud Platform including Vertex AI (as of June 2026). - US providers — optional opt-in, not the default. Anthropic and OpenAI (outside Bedrock), Perplexity, Replicate, Hugging Face, xAI, and optionally Voyage are used only for Starter / Genie plans or after explicit activation by the customer in the project settings. For Teams customers, they are not the default path and can be fully disabled.
- Third-country transfer basis. Transfers outside the EU/EEA rely on the EU Standard Contractual Clauses (Modules 2/3, Implementing Decision 2021/914) and, where applicable, the EU–US Data Privacy Framework. For every US provider with access to personal data, we hold an internal Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020. TIAs are updated at least annually and on an ad hoc basis. Summaries are available on request.
- Data minimization for third-country transfers. Only the prompt and completion data required for inference is transmitted. Stable internal identifiers are, where technically possible, replaced with pseudonyms before transmission; live user identities (email, real name, Auth0 IDs) are, by design, not intended to be part of LLM payloads. Plaintext secrets, MCP credentials, and billing bodies are excluded from payloads by documented filtering and logging rules.
- Provider deactivation. Customers can disable individual LLM providers in workspace settings. Teams customers can restrict the provider scope to “EU-only / AWS Bedrock”; in this configuration, requests to US providers are technically blocked. A central overview of active providers per workspace is available in admin settings.
A.3 Subprocessors in use
The following services are directly involved in operating the Genie platform and customer apps. They process end users’ personal data.A.4 Notification of changes
Customers receive an email notification at least 30 days before a new subprocessor begins processing, or before an existing subprocessor is replaced, sent to the primary contact named in the order form. Objections under Art. 28(2) GDPR are handled viaprivacy@genie-app.de.
A.5 Contact and document status
- Privacy / DPA / subprocessor requests:
privacy@genie-app.de - Security reports:
security@genie-app.de - Versioning. This annex is reviewed annually and whenever the subprocessor list changes materially, and is kept in sync with the customer compliance package.
