Cognitify

// Updated · 2026-09-01

Subprocessors

Cognitify OÜ uses a small set of infrastructure providers (subprocessors) to run cognitify.ai and our products. This page is the authoritative list referenced by our Data Processing Agreement as Annex III: who each provider is, what they do for us, and where they process data. Before a new subprocessor processes customer personal data, we update this page and give customers at least 14 days’ notice; the objection mechanism is described in the DPA.

01

Current Subprocessors

  • Microsoft Ireland Operations Ltd. (Microsoft Azure) — cloud hosting, storage, and AI model hosting (Azure OpenAI Service). Processing location: European Union — Azure West Europe (the Netherlands); replicas and backups stay inside the EU;
  • Cloudflare, Inc. — DNS, network security, bot protection (Turnstile), and cookieless web analytics. Processing location: global edge network, headquartered in the United States; transfers covered by the EU–US Data Privacy Framework and the EU Standard Contractual Clauses;
  • Redis Ltd. (Redis Cloud) — realtime infrastructure (caching and queues). Processing location: managed cloud region in the European Union;
  • Google Ireland Ltd. (Google Analytics) — website analytics, only after cookie consent on cognitify.ai. Processing location: European Union and United States; transfers covered by the EU–US Data Privacy Framework;
  • Meta Platforms Ireland Ltd. — message delivery for Instagram and Facebook Messenger channels a customer connects. Processing location: European Union and United States; transfers covered by the EU–US Data Privacy Framework and Meta’s platform terms;
  • Telegram Messenger Inc. — message delivery for Telegram channels a customer connects. Processing location: global infrastructure operated from the United Arab Emirates; engaged only when the customer connects its own Telegram bot;
  • Stripe Payments Europe, Ltd. — payment processing for paid plans. Processing location: European Union and United States; transfers covered by the EU–US Data Privacy Framework.
02

Changes to This List

When we plan to add or replace a subprocessor that will process customer personal data, we update this page at least 14 days in advance and notify workspace owners by email. Customers may object on reasonable data-protection grounds as described in the Data Processing Agreement. Removals and like-for-like infrastructure changes inside the same provider are reflected on this page without a notice period.

Change log: 2026-09-01 — initial published version of this page (the same seven providers previously listed in the Privacy Policy, now with processing locations).