Requesty

Sub Processors

Requesty Ltd: Sub‑processor Disclosure

Last updated: 30 August 2026

Sub‑processors are third‑party businesses engaged by Requesty Ltd ("Requesty", "we", "our") to process Personal Data on our behalf while we provide services to our customers ("Controllers"). Under the UK GDPR and EU GDPR these companies must offer sufficient guarantees, via contract, to implement appropriate technical and organisational measures that meet the regulation's requirements.

This page explains (1) our governance approach and (2) the current list of sub‑processors we rely on for the Requesty Large‑Language‑Model Router and related pay‑as‑you‑go services.

1 Governance

Due‑diligence & risk assessment. Every prospective sub‑processor undergoes security, privacy and compliance reviews before onboarding. We examine certifications (e.g. ISO 27001, SOC 2), security white‑papers, audit reports and data‑protection controls.

Contractual safeguards. Each sub‑processor signs a data‑processing agreement with Requesty that:• mirrors or exceeds the obligations in our customer DPA;• includes a robust personal‑data‑breach notification provision; and• commits to suitable technical and organisational measures.

Ongoing monitoring. We conduct annual reviews and monitor security advisories, incident reports and regulatory developments affecting each sub‑processor.

Notification & objection. Customers are notified at least 30 days in advance of any intended change to this list (via email or in‑app banner). If you have reasonable grounds to object, email support@requesty.ai within the notice period.

2 Current Sub-processors

This list is divided in the way clause 8.1 of our DPA requires. Part A lists Infrastructure Sub-processors, which we engage for every customer. Part B lists Model Providers, each of which is engaged only where, and to the extent that, you route a request to a model it operates. A Model Provider you never route to processes none of your data, and you can narrow Part B for your own organisation at any time by configuring Approved Models. Unless stated otherwise, Personal Data is limited to that necessary to provide the indicated service and is encrypted in transit and at rest.

Part A: Infrastructure Sub-processors

VendorLocation of ProcessingPurposePrivacy Policy
Amazon Web Services Inc. (AWS)🇩🇪 Frankfurt, Germany (EU Central 1)Primary cloud infrastructure (compute, storage, networking) hosting the Requesty platform and databaseshttps://aws.amazon.com/privacy/

Part B: Model Providers (Inference)

The Data Retention and Trains on Prompts columns reproduce each provider's own published position, as returned per model in our API metadata. A provider marked Yes under Trains on Prompts operates one or more models we label as Training Permitted Models; it does not follow that every model that provider operates trains on prompts, so check the per model metadata.

VendorLocationData RetentionRetention PeriodTrains on PromptsPrivacy Policy
OpenAI Inc.🇺🇸 USYes30 daysNoOpenAI Privacy Policy
Anthropic PBC🇺🇸 USYes30 daysNoAnthropic Privacy Policy
Google LLC (Gemini API)🌍 GlobalYes-NoGemini API Terms
Google LLC (Vertex AI)🇺🇸 US / 🇪🇺 EUNo-NoVertex AI Data Governance
Microsoft Azure AI🇺🇸 US / 🇪🇺 EUNo-NoMicrosoft Privacy Statement
AWS Bedrock🇺🇸 US / 🇪🇺 EUNo-NoAWS Privacy Notice
Mistral AI SAS🇪🇺 EUNo-NoMistral Privacy Policy
xAI Corp.🇺🇸 USYes30 daysNoxAI Privacy Policy
DeepInfra Inc.🇺🇸 USNo-NoDeepInfra Privacy Policy
Alibaba Cloud🇸🇬 SingaporeNo-NoAlibaba Cloud Privacy Policy
DeepSeek🇨🇳 ChinaYes-NoDeepSeek Privacy Policy
Groq Inc.🇺🇸 USNo-NoGroq Privacy Policy
Nebius AI🇪🇺 EUNo-NoNebius Privacy Policy
NetMind.AI🇬🇧 UKNo-NoNetMind Privacy Policy
Novita AI🇺🇸 USYes-NoNovita AI Privacy Policy
Parasail🇺🇸 USNo-NoParasail Privacy Policy
Perplexity AI🇺🇸 USYes-NoPerplexity Privacy Policy
Together AI Inc.🇺🇸 USNo-NoTogether AI Privacy Policy
Moonshot AI🇨🇳 ChinaYes-NoMoonshot Privacy Policy
Z.ai🇸🇬 SingaporeNo-NoZ AI Privacy Policy
Fireworks AI🇺🇸 USNo-NoFireworks Privacy Policy
MiniMax🇸🇬 SingaporeYes-NoMiniMax Privacy Policy
Inceptron AB🇪🇺 EU (Sweden)No-NoInceptron Privacy Policy
NVIDIA🇺🇸 USYes-YesNVIDIA Privacy Policy
Poolside🇺🇸 USYes-YesPoolside Privacy Policy
Sakana AI🇯🇵 JapanYes-NoSakana AI Privacy Policy
Xiaomi🇨🇳 ChinaYes-NoXiaomi Privacy Policy
Tencent🇨🇳 ChinaYes-NoTencent Cloud Privacy Policy
Doubleword🇬🇧 UK, 🌍 Global inferenceYes-NoDoubleword Data Usage Policy
sference🇪🇺 EU (Finland)No-Nosference Privacy Policy
TensorX Ltd.🇪🇺 EU (Ireland)No-NoTensorX Privacy Policy
Runware Inc.🇬🇧 UK, 🇪🇺 EU inferenceNo-NoRunware Privacy Policy
Relace (Squack, Inc.)🇺🇸 USNo-NoRelace Privacy Policy
Sail Research Co.🇺🇸 USNo-NoSail Research Privacy Policy
Regolo.ai🇪🇺 EU (Italy)No (Zero Data Retention)-NoRegolo Privacy Policy
Scaleway SAS🇪🇺 EU (France)No (Zero Data Retention)-NoScaleway Generative APIs Privacy Policy

When you send a request, the prompt and the model output are transmitted securely to the provider of the model you selected. Whether that provider retains them, and whether it uses them to train or improve its own models, is set by that provider and not by us. We publish each provider's stated position per model, in the model metadata returned by the API and at requesty.ai/models. Models we label as Training Permitted Models retain prompts and outputs and train on them. Every one of them is offered at no charge and they are available only on our free plan: for pay as you go, Enterprise and MSA accounts they are excluded by default, and Section 5.9 of our Terms of Service describes them. Zero Data Retention and the EU endpoint govern our own processing and do not change what a provider does. The control that restricts which providers receive your prompts is Approved Models, which you configure for your organisation.

Contact

Questions or objections? Email support@requesty.ai or write to: Requesty Ltd, 71‑75 Shelton Street, Covent Garden, London WC2H 9JQ, UK.