Sub-processors - TauCAD Limited

Effective date: December 29, 2025

This page lists all third-party service providers (sub-processors) that process personal data on behalf of TauCAD Limited in connection with our Service. This list is maintained in accordance with our Privacy Policy and applicable data protection laws.

We require all sub-processors to implement appropriate technical and organizational security measures and to process personal data only for the purposes we specify.

Infrastructure and Hosting

Sub-processorPurposeData ProcessedLocationCertifications
Fly.ioAPI application hostingData stored and transmitted through our API hosting infrastructure, including request/response data, IP addresses, and server logsUSASOC 2 Type II
NetlifyFrontend hosting and CDNStatic assets, IP addresses, request headersUSASOC 2 Type II
SupabaseDatabase and backend servicesUser account data, authentication data, application data stored in PostgreSQL databaseUSASOC 2 Type II, HIPAA

AI and Machine Learning Services

When you use AI-assisted CAD features, your prompts and relevant context may be processed by the following providers. Your data is not retained by these providers for their own training purposes.

Sub-processorPurposeData ProcessedLocationCertifications
OpenAIAI language models (GPT)Prompts, CAD context, conversation historyUSASOC 2 Type II
AnthropicAI language models (Claude)Prompts, CAD context, conversation historyUSASOC 2 Type II
Google (Vertex AI)AI model services (Gemini)Prompts, CAD context, conversation historyUSASOC 1/2/3, ISO 27001, ISO 27017, ISO 27018
SambaNovaAI model services (optional)Prompts, CAD context when model is selectedUSASOC 2 Type II
CerebrasAI model services (optional)Prompts, CAD context when model is selectedUSASOC 2 Type II
TavilyWeb search for AI featuresSearch queries when web search is enabledUSASOC 2 Type II

CAD Processing

Sub-processorPurposeData ProcessedLocationCertifications
Zoo.dev (KittyCAD)KCL CAD kernel processingCAD code, model geometry, rendering dataUSASOC 2 Type II

Analytics and Observability

Sub-processorPurposeData ProcessedLocationCertifications
PostHogProduct analytics (with consent)Usage data, device info, interaction patternsUSASOC 2 Type II
LangSmithAI feature observabilityAI interaction logs, prompt/response metadataUSASOC 2 Type II

Payment Processing

Sub-processorPurposeData ProcessedLocationCertifications
StripePayment processingPayment method details, billing informationUSAPCI DSS Level 1, SOC 1/2, ISO 27001

Authentication Services

When you choose to sign in using third-party authentication, we receive certain information from these providers.

Sub-processorPurposeData ProcessedLocationCertifications
GitHubOAuth authenticationEmail, username, profile picture (if authorized)USASOC 1/2, ISO 27001
GoogleOAuth authenticationEmail, name, profile picture (if authorized)USASOC 1/2/3, ISO 27001

Changes to This List

We will update this list when we add or remove sub-processors. For material changes, we will notify you in accordance with our Privacy Policy.

Notification of Changes

To receive notifications when we update this sub-processor list, you may:

We will provide at least 30 days' notice before engaging new sub-processors that process personal data, allowing you to review and raise any objections.

Contact Us

If you have questions about our sub-processors or data processing practices, please contact us at privacy@tau.new.