Table of Contents

Data Processors

AIVAX uses third-party services for specific operations such as infrastructure, object storage, email delivery, payment processing, web search, AI inference, reranking, and image generation. The providers involved in a request depend on the selected model, gateway, tool, and integration.

This page is a technical inventory, not legal advice. Provider policies may change, and Account Managers should review the provider terms that apply to their selected models and tools before sending personal, confidential, regulated, or sensitive data.

The data protection law column summarizes the principal frameworks identified in each provider's current privacy policy or data processing addendum. Applicability may vary by contracting entity, data subject location, and processing region.

Operations, Services, and Infrastructure

Provider Used for Data protection law
Cloudflare Reverse proxy/security where deployed, Workers AI reranking, and embedding services EU/UK GDPR, Swiss FADP, and CCPA/CPRA
Hetzner Compute infrastructure and hosting GDPR and BDSG
netcup Compute infrastructure and hosting GDPR and BDSG
Backblaze Object and file storage for generated media, uploaded media, generated documents, exposed files, and error artifacts EU/UK GDPR and CCPA/CPRA
Brevo Transactional email and notifications GDPR, French Data Protection Act, CCPA/CPRA, PIPEDA, and LGPD
InfinitePay Payment invoice creation and payment confirmation LGPD (Brazilian Law No. 13,709/2018)
Stripe Payment event processing where Stripe checkout is configured EU/UK GDPR, Irish Data Protection Act 2018, and CCPA/CPRA
Twitter/X Built-in X/Twitter search and post reading tools EU/UK GDPR, Swiss FADP, CCPA, and LGPD
Linkup Web search for context enrichment GDPR, French Data Protection Act, ePrivacy Directive, and CCPA/CPRA
Tavily Web search for context enrichment GDPR, UK Data Protection Act 2018, and applicable U.S. state privacy laws
Sinkin AI Image generation for selected image models EU/UK GDPR, CCPA, and Virginia CDPA
Pollinations Image generation for selected image models GDPR

Direct Inference, Embedding, and Reranking Providers

Provider Used for Data protection law
Groq LLM inference through an OpenAI-compatible endpoint EU/UK GDPR, Swiss FADP, CCPA/CPRA, and Saudi PDPL
Jina AI Embeddings, reranking, and web research GDPR and BDSG
OpenRouter Model routing and fallback for many model families and Grok Voice TTS GDPR, CCPA/CPRA, and applicable U.S. state privacy laws
Xiaomi MiMo Xiaomi model inference PIPL, EU/UK GDPR, and Swiss FADP
Inception Labs Mercury model inference California Civil Code §§ 1798.83–1798.84 and Nevada Revised Statutes Chapter 603A
Cloudflare Workers AI Smart reranking and embedding services EU/UK GDPR, Swiss FADP, and CCPA/CPRA

Model Families and Underlying Providers

The model catalog also identifies model families or underlying providers that may be selected directly or reached through aggregators such as OpenRouter. Not every request is sent to every provider.

Provider Used for Data protection law
OpenAI OpenAI model families exposed in the catalog or compatible integrations EU/UK GDPR, CCPA/CPRA, and applicable U.S. state privacy laws
Google Vertex AI Gemini and other Google model families EU/UK GDPR, Swiss FADP, and CCPA/CPRA
Anthropic Claude model families EU/UK GDPR, Swiss FADP, LGPD, and applicable U.S. state privacy laws
AWS AWS-hosted model families such as Amazon Nova or Bedrock-backed providers EU/UK GDPR, Swiss FADP, and CCPA/CPRA
Cohere Cohere model families PIPEDA, GDPR, and CCPA/CPRA
xAI Grok model families and Grok Voice through configured routes EU/UK GDPR, Swiss FADP, and CCPA/CPRA
Mistral AI Mistral model families GDPR, French Data Protection Act, and CCPA/CPRA
DeepSeek DeepSeek model families PIPL, Data Security Law, and Cybersecurity Law of the People's Republic of China
Z.ai GLM/Z.ai model families Singapore PDPA and GDPR/UK GDPR where applicable
Alibaba Cloud Qwen/Alibaba model families GDPR/UK GDPR and applicable regional laws, including PIPL
Cerebras Cerebras model families GDPR and CCPA/CPRA
Nebius Nebius-backed model families EU/UK GDPR, Dutch GDPR Implementation Act, and Swiss FADP
Fireworks AI Fireworks-backed model families EU/UK GDPR, CCPA/CPRA, and applicable U.S. state privacy laws
Novita Novita-backed model families CCPA/CPRA
Azure Azure-backed model families EU/UK GDPR, CCPA/CPRA, and PIPEDA
LongCat LongCat/Meituan model family metadata PIPL, Data Security Law, and Cybersecurity Law of the People's Republic of China; GDPR and CCPA where applicable

Data Handling Notes

By default, AIVAX does not use Account Manager Input Content, Generated Content, or Conversations to train proprietary AIVAX models. Eligible RAG and Reflex search records are used for model development only when an authorized Account Manager enables the optional program described in Data Collecting. Document indexing and storage are excluded.

Third-party providers and aggregators may have their own processing, retention, abuse-monitoring, and model-improvement rules. The selected model, provider, tool, or integration determines which third party receives data for a specific request.

Avoid sending sensitive, confidential, regulated, or personal information to a provider unless you have reviewed that provider's current terms and have an appropriate legal basis for the processing.