C4AIL AI Maturity Diagnostic

Sub-processors

Last updated: 24 July 2026

This page lists every third party that processes data on our behalf in delivering the AI Maturity Diagnostic, what each one receives, and where. It is maintained as a standing list because "who else sees this?" is a reasonable first question, and an assessment product that could not answer it would be failing its own instrument.

Current sub-processors

ProviderPurposeWhat it receivesLocation
Google Asia Pacific Pte. Ltd.
(Google Cloud Vertex AI - Gemini 2.5 Flash)
Interpreting answers written in free text, and checking whether a cited extract describes an event or a rule. The question, and the words you wrote or the extract you cited. Not your name, not your organisation's name, not any colleague's answers. Singapore. Google Cloud Vertex AI, invoked on the asia-southeast1 (Singapore) regional endpoint, which keeps processing in that region.
Hetzner Online GmbH Hosting the application and its database. All assessment data. Sensitive content - answers, free text, evidence citations, signer names, organisation names - is encrypted at rest. Nuremberg, Germany
Cloudflare DNS and traffic proxying. Connection metadata (IP address, request routing). Not assessment content. Global edge network
ImprovMX Sending assessment invitations and results by email. Recipient email address and the message body. Global

What this means in practice

Most answers never reach a sub-processor at all

Short, unambiguous answers - "No", "Not my area", "We don't track this" - are resolved by ordinary software on our own server. They are never sent to any AI service. Only answers that genuinely require interpretation are, and free-text answering is optional throughout: you can complete any assessment by selecting from the listed options, in which case no text of yours reaches any model.

We never receive your documents

Where an assessment is answered from your organisation's own material, your own AI reads it where it already lives. We do not connect to your systems and we never receive your files. What reaches us is the answer plus a citation: the document's name, where in it you looked, and a quoted extract of up to 600 characters. That extract is stored, encrypted, as part of the audit trail - because an answer that cannot be traced to its source is not evidence.

Not used to train models

Google does not use content submitted to Vertex AI to train its models, and model providers have no access to it. We do not use your assessment content to train any model of our own.

On "in region"

We say processed in Singapore because the model runs on Vertex AI's asia-southeast1 (Singapore) regional endpoint, which keeps processing in that one region. An earlier version of this service used a provider whose inference profile spanned several Asia-Pacific regions, so it could only claim "within the Asia-Pacific region"; that is no longer the case, and we state the narrower, truer claim.

Changes to this list

We will update this page before adding a new sub-processor that handles assessment content. Organisations with a written agreement that includes notification of sub-processor changes will be notified in accordance with that agreement.

Questions

Centre for AI Leadership Ltd.
[email protected]

See also: Privacy Policy · Terms of Use · Data Processing Agreement