← Back to Legal & Compliance

Sub-Processor List

Armour Consortium AI - Cart Recovery API
Legal Basis: Article 28(2) UK GDPR / EU GDPR | Last Updated: December 2025

1. Overview

Armour Consortium AI engages the following sub-processors for the Cart Recovery API service. By using our API, you consent to the use of these sub-processors.


2. AI/Ensemble Sub-Processors

These sub-processors are used for content generation:

Sub-ProcessorServicePurposeLocationTransfer MechanismDPA Status
AnthropicClaudeAI Content GenerationUSAStandard Contractual ClausesActive
GoogleGeminiAI Content GenerationUSA/EUStandard Contractual ClausesActive
OpenAIGPT-4oAI Content GenerationUSAStandard Contractual ClausesActive
xAIGrok 4AI Content GenerationUSAStandard Contractual ClausesActive

2.1 Data Minimisation

When data is sent to AI model providers:

Sent to AI ModelsNOT Sent to AI Models
First nameEmail address
Cart items (titles, prices)Phone number
Cart valueCustomer ID
Brand voice settingFull address
CurrencyOrder history

Key protections:


3. Payment Sub-Processors

Sub-ProcessorServicePurposeLocationTransfer MechanismDPA Status
Coinbasex402 ProtocolPayment verification for API callsUSAStandard Contractual ClausesActive
StripePayment GatewaySubscription billingUSAStandard Contractual ClausesActive

4. Infrastructure Sub-Processors

Sub-ProcessorServicePurposeLocationTransfer MechanismDPA Status
ReplitHostingAPI hosting and executionUSAStandard Contractual ClausesActive
NeonPostgreSQLAnalytics databaseUSA/EUStandard Contractual ClausesActive

5. Communication Sub-Processors

These are used by subscription customers (not API-only users):

Sub-ProcessorServicePurposeLocationTransfer MechanismDPA Status
Elastic EmailEmail DeliveryEmail sending for subscribersUSA/EUStandard Contractual ClausesActive
PlivoSMS DeliverySMS sending for subscribersUSAStandard Contractual ClausesActive

Note: API-only users handle their own message delivery. These sub-processors only apply to specific Armour Consortium AI subscribers where we handle full orchestration.

Note: Merchants using their own ESP/SMS provider (e.g., Klaviyo) bypass these entirely.


6. Security and Transfer Safeguards

6.1 Standard Contractual Clauses

All US-based sub-processors have signed EU Standard Contractual Clauses (SCCs) as approved by the European Commission. The UK IDTA addendum is applied where required.

6.2 Supplementary Measures

MeasureImplementation
EncryptionTLS 1.3 for all transfers
Data MinimisationOnly necessary data transmitted
Transient ProcessingNo persistent storage at sub-processors
Access ControlsAPI-based access only

6.3 Transfer Impact Assessment

A Transfer Impact Assessment has been conducted for each sub-processor, considering:


7. Sub-Processor Changes

7.1 Notification

We will update this page when sub-processors change. Material changes will be announced via:

7.2 Objection Right

If you object to a new sub-processor:


8. Due Diligence

We conduct the following due diligence on sub-processors:

CheckFrequency
Security certifications (SOC 2, ISO 27001)Annual
DPA/contract reviewAt engagement, then annual
Privacy policy reviewAnnual
Incident response capabilityAt engagement

9. Version History

VersionDateChanges
1.0December 2025Initial sub-processor list

10. Contact

For questions about our sub-processors:

Email: hello@armourconsortium.ai

This list is maintained as required by Article 28(2) UK GDPR and EU GDPR.