Sub-processors — A1 Voice

Extracted from Schedule 3 of the A1 Voice Data Processing Agreement. For the full DPA see /dpa.

Schedule 3 — List of Approved Sub-processors

The Sub-processors listed below are authorised at the date of this DPA. Each one processes Customer Personal Data on behalf of the Processor under a written contract imposing data-protection obligations no less protective than this DPA. Updates are made under clause 4.4.

Sub-processor Purpose Region of processing
Amazon Web Services (AWS) Hosting, compute, storage, networking — including the call-handling pipeline (WebRTC, audio storage, transcripts, dashboard, database) UK (eu-west-2, London) — all infrastructure pinned to AWS's London region
Google (Gemini API via Vertex AI) Large-language-model inference for call handling EU multi-region (eu) — pinned via the Vertex AI EU multi-region endpoint (aiplatform.eu.rep.googleapis.com); auth via service-account ADC. Live on both staging and production since 2026-09-08. Requests are served from a location within the European Union; the multi-region does not extend outside the EEA. Previous pins: europe-west8 (Milan) from 2026-05-28, and europe-west2 (London) from 2026-05-11. A second endpoint also ran, and this row did not disclose it at the time: from 2026-05-30 until 2026-09-08 a latency backup leg at europe-west4 (Netherlands) was live alongside the Milan primary, engaging on the slow tail of turns; it was retired on 2026-09-08 with the rest of the hedge. Both were EU endpoints, so processing stayed inside the EEA throughout and the clause 5.2 residency commitment was met — what was incomplete was this Schedule, which clause 5.4 makes the statement of the regions in which Sub-processors process Customer Personal Data. The omission and its correction are recorded in full in the Processor's Transfer Impact Assessment (Appendix C, v0.4.1), which is shared with Controllers on request. The 2026-09-08 move was compelled by Google's retirement of the Gemini 2.5 series on 2026-10-16 — its replacement generation is not served from any single-region endpoint — and NOT by a relaxation of residency: the alternative global endpoint was rejected precisely because it would route outside the EEA. Where a fail-over outside the UK / EEA is exceptionally required, UK IDTA / SCCs apply.
OpenRouter (where configured) Alternative LLM routing for some agent roles Not currently configured in the production profile; this row is retained for transparency in case it is re-enabled. If re-enabled, OpenRouter would route to the underlying provider it judges best (no region pin); UK IDTA / SCCs would apply, and the Processor would re-notify Controllers per clause 4.4.4.

Notes: