Sub-processors
Last updated: 24 July 2026
This page lists every third party that processes data on our behalf in delivering the AI Maturity Diagnostic, what each one receives, and where. It is maintained as a standing list because "who else sees this?" is a reasonable first question, and an assessment product that could not answer it would be failing its own instrument.
Current sub-processors
| Provider | Purpose | What it receives | Location |
|---|---|---|---|
| Google Asia Pacific Pte. Ltd. (Google Cloud Vertex AI - Gemini 2.5 Flash) | Interpreting answers written in free text, and checking whether a cited extract describes an event or a rule. | The question, and the words you wrote or the extract you cited. Not your name, not your organisation's name, not any colleague's answers. | Singapore. Google Cloud Vertex AI, invoked on the asia-southeast1 (Singapore) regional endpoint, which keeps processing in that region. |
| Hetzner Online GmbH | Hosting the application and its database. | All assessment data. Sensitive content - answers, free text, evidence citations, signer names, organisation names - is encrypted at rest. | Nuremberg, Germany |
| Cloudflare | DNS and traffic proxying. | Connection metadata (IP address, request routing). Not assessment content. | Global edge network |
| ImprovMX | Sending assessment invitations and results by email. | Recipient email address and the message body. | Global |
What this means in practice
Most answers never reach a sub-processor at all
Short, unambiguous answers - "No", "Not my area", "We don't track this" - are resolved by ordinary software on our own server. They are never sent to any AI service. Only answers that genuinely require interpretation are, and free-text answering is optional throughout: you can complete any assessment by selecting from the listed options, in which case no text of yours reaches any model.
We never receive your documents
Where an assessment is answered from your organisation's own material, your own AI reads it where it already lives. We do not connect to your systems and we never receive your files. What reaches us is the answer plus a citation: the document's name, where in it you looked, and a quoted extract of up to 600 characters. That extract is stored, encrypted, as part of the audit trail - because an answer that cannot be traced to its source is not evidence.
Not used to train models
Google does not use content submitted to Vertex AI to train its models, and model providers have no access to it. We do not use your assessment content to train any model of our own.
On "in region"
We say processed in Singapore because the model runs on Vertex AI's asia-southeast1 (Singapore) regional endpoint, which keeps processing in that one region. An earlier version of this service used a provider whose inference profile spanned several Asia-Pacific regions, so it could only claim "within the Asia-Pacific region"; that is no longer the case, and we state the narrower, truer claim.
Changes to this list
We will update this page before adding a new sub-processor that handles assessment content. Organisations with a written agreement that includes notification of sub-processor changes will be notified in accordance with that agreement.
Questions
Centre for AI Leadership Ltd.
[email protected]
See also: Privacy Policy · Terms of Use · Data Processing Agreement