SUB-PROCESSORS
TemsSoft B.V., trading as TemsAI
Version 1.0
Last updated: 01.09.2026
This page is published pursuant to Clause 8.3 of the Data Processing Agreement and forms part of Annex IV to that agreement. It identifies the sub-processors engaged by TemsSoft B.V. ("TemsAI") in the provision of the TemsAI platform and related services (the "Services"), together with the purpose of each engagement and the location in which processing is carried out.
Terms defined in the Data Processing Agreement and in the Terms of Service have the same meaning when used on this page.
STATUS OF THIS PAGE
This page is published in order to identify the sub-processors engaged by TemsAI as at the date stated above, and to describe the process by which they are engaged. The list of sub-processors set out in Clause 3 is incorporated into Annex IV of the Data Processing Agreement for the purposes of Article 28 of Regulation (EU) 2016/679.
Save in respect of that list, this page is provided for information only. It does not confer upon any customer any right or remedy additional to those set out in the Data Processing Agreement and the Terms of Service, and shall not be construed as a binding agreement or as a variation of either of them. Rights of objection and of termination arise exclusively under the Data Processing Agreement.
The information on this page is accurate as at the date stated above. TemsAI does not warrant that it remains accurate at any later date, save that changes are published in accordance with Clause 1.3.
WHAT IS A SUB-PROCESSOR
A sub-processor is a third-party data processor engaged by TemsAI which has, or may have, access to or processes customer data which may contain personal data. TemsAI engages sub-processors of different types in order to perform the functions described below.
Third parties which do not have access to and do not process customer data, but which are otherwise used in the provision of the Services - including content delivery networks, professional advisers and providers of internal corporate systems which hold no customer data - are subcontractors and not sub-processors, and are not required to be listed on this page.
1. HOW THIS PAGE OPERATES
1.1 General authorisation. Each customer grants TemsAI general written authorisation, within the meaning of Article 28(2) of Regulation (EU) 2016/679, to engage sub-processors for the provision, hosting, security, support and continuous improvement of the Services. The selection of sub-processors is a technical and operational decision of TemsAI.
1.2 Due diligence. TemsAI applies a commercially reasonable selection process by which it evaluates the security, privacy and confidentiality practices of each proposed sub-processor which will or may have access to or process customer data. That process forms part of the supplier management procedure within TemsAI's information security management system certified to ISO/IEC 27001, and addresses security posture, certifications, data protection compliance and, where relevant, transfer safeguards.
1.2.1 Contractual safeguards. TemsAI requires each sub-processor to accept obligations equivalent to those undertaken by TemsAI as processor under the Data Processing Agreement, including obligations to:
(a) process personal data only in accordance with the documented instructions of the controller, as communicated in writing to the sub-processor by TemsAI;
(b) engage in connection with such processing only personnel who are reliable and who are subject to a binding obligation of confidentiality and of data protection;
(c) provide regular training in security and data protection to personnel granted access to personal data;
(d) implement and maintain appropriate technical and organisational measures, consistent so far as relevant with those to which TemsAI is committed, and provide an annual certification evidencing compliance with that obligation, in the absence of which TemsAI reserves the right to audit the sub-processor;
(e) inform TemsAI promptly of any actual or potential security breach; and
(f) cooperate with TemsAI in dealing with requests from controllers, data subjects and supervisory authorities.
1.2.2 In the case of providers of artificial intelligence models, the contract additionally prohibits the use of customer personal data, and of inputs and outputs, for the training of models.
1.3 Notification of changes. TemsAI notifies additions and replacements by updating this page not less than fifteen (15) days before the new sub-processor commences processing customer personal data. Publication on this page, and where subscribed the corresponding notification, constitute the information required under Article 28(2) GDPR, and no separate or individually negotiated notice is given.
1.4 Subscription to notifications. Customers may subscribe to receive notification of changes to this page by sending a request to welcome@tems.ai stating the electronic mail address to be notified. It is the customer's responsibility to subscribe and to monitor notifications received.
1.5 Objection and deemed acceptance. A customer may object to a new sub-processor within fifteen (15) days of notification, by written notice to welcome@tems.ai setting out specific and reasonable data protection grounds. Objections upon commercial grounds, or upon grounds of preference for an alternative provider, are not valid. Where no objection is received within that period, the new sub-processor is deemed accepted.
1.5.1 Where an objection is received, TemsAI shall be entitled to address it by one of the following means, to be selected at TemsAI's sole discretion:
(a) ceasing to use the sub-processor in respect of that customer's personal data;
(b) taking such corrective steps as remove the grounds of the objection, and proceeding to use the sub-processor; or
(c) ceasing to provide, or agreeing with the customer that the customer will not use, whether temporarily or permanently, the particular aspect of the Services which would involve the use of that sub-processor.
1.5.2 Where none of the foregoing resolves the objection, the customer's rights are as set out in Clause 8.4 of the Data Processing Agreement. Termination rights arise exclusively under that agreement.
1.6 Urgent replacement. Where a sub-processor must be added or replaced without delay in order to maintain the security, availability or continuity of the Services, TemsAI may make the change immediately and shall update this page and notify subscribed customers as soon as reasonably practicable thereafter.
1.7 Responsibility. TemsAI remains fully liable to its customers for the performance of the data protection obligations of each sub-processor.
2. CATEGORIES OF SUB-PROCESSORS
2.1 Cloud infrastructure - hosting, storage, backup and disaster recovery. Safeguards: hosting in the region stated in the applicable agreement; ISO 27001 or equivalent certification; encryption in transit and at rest.
2.2 Artificial intelligence model providers - model inference supporting the assistant, search, transcription, translation and content generation. Safeguards: enterprise terms prohibiting the use of customer personal data for the training of models; zero or minimal retention configured where the provider offers such a facility.
2.3 Productivity and identity platforms - integration with the customer's Microsoft 365 environment and identity provider. Safeguards: processing limited to that which the integration requires; access governed by the customer's own tenant permissions.
2.4 Support and service management - customer support, ticketing and incident management. Safeguards: access upon a need-to-know basis; confidentiality obligations; audit logging.
2.5 Monitoring and observability - application performance monitoring, error reporting and security monitoring. Safeguards: minimisation and, where feasible, pseudonymisation of data contained in telemetry.
2.6 Billing and payments - subscription management, checkout and invoicing for self-service plans. Safeguards: payment card data is submitted directly to the payment provider and is at no time received or stored by TemsAI.
3. SUB-PROCESSORS CURRENTLY ENGAGED
3.0 TemsAI controls access to the infrastructure upon which customer data submitted to the Services is hosted. The production systems for the Services are located within the European Economic Area. Customer data remains within that region, but may be moved between data centres and availability zones within the region in order to ensure the performance, resilience and availability of the Services.
3.1 Amazon Web Services EMEA SARL
Category: Cloud infrastructure
Purpose: Hosting, storage, database, search, backup and outbound transactional electronic mail for the Services
Processing location: European Union (Frankfurt)
3.2 Amazon Web Services EMEA SARL
Category: Artificial intelligence model providers
Purpose: Model inference for the artificial intelligence assistant, content generation, image understanding and AI-assisted editing
Processing location: European Union
3.3 OpenAI Ireland Limited
Category: Artificial intelligence model providers
Purpose: Speech-to-text transcription of audio and video submitted by the customer; search embeddings; fallback content generation
Processing location: United States
3.4 Google Cloud EMEA Limited
Category: Artificial intelligence model providers
Purpose: Machine translation of customer PDF content into the customer's configured languages
Processing location: European Union and United States
3.5 Functional Software, Inc., trading as Sentry
Category: Monitoring and observability
Purpose: Application error and crash reporting
Processing location: European Union
3.6 PostHog, Inc.
Category: Monitoring and observability
Purpose: Product usage analytics
Processing location: European Union
3.7 Stripe Payments Europe, Limited
Category: Billing and payments
Purpose: Subscription management and payment processing for self-service plans
Processing location: European Union, with onward transfer to the United States
3.8 No sub-processor is currently engaged in the categories "Productivity and identity platforms" or "Support and service management". Customer support is provided by TemsAI's own personnel using the infrastructure identified above.
4. CONTENT DELIVERY NETWORKS
4.1 The Services use a content delivery network in order to deliver content efficiently and securely according to the geographic location of the person accessing it. A content delivery network does not have access to customer data. Website content and domain information may be cached within the network in order to expedite transmission, and information transmitted across it may be accessed by the network operator in order to perform that function.
4.2 Content delivery network used: Amazon CloudFront, operated by Amazon Web Services EMEA SARL - global points of presence - European Union entity.
4.3 In accordance with Clause 0.a, content delivery networks are subcontractors and not sub-processors.
5. COMPONENTS OPERATED BY TEMSAI
Components of the Services which TemsAI operates itself within its own infrastructure - including the identity and single sign-on service, the retrieval and search stack, the workflow engine and the embedded manufacturing module - are not sub-processors, as no customer personal data is disclosed to any third party by their use.
6. TRANSFERS OUTSIDE THE EUROPEAN ECONOMIC AREA
6.1 Where a sub-processor processes customer personal data outside the European Economic Area, the transfer is effected pursuant to the standard contractual clauses adopted by the European Commission by Implementing Decision (EU) 2021/914, incorporated by Clause 11.2 and Annex V of the Data Processing Agreement, or pursuant to an adequacy decision or approved certification where one applies.
6.2 Each such transfer is supported by a documented transfer impact assessment, a copy of which is available upon request to welcome@tems.ai.
6.3 In the case of providers of artificial intelligence models, the contract additionally prohibits the use of inputs and outputs for the training of models.
7. WEBSITE SERVICE PROVIDERS
7.1 The following providers support TemsAI's public website only. They form no part of the Services, do not operate within any customer environment, and process no customer personal data. They are accordingly not sub-processors for the purposes of the Data Processing Agreement.
7.2 Wix.com Ltd - website hosting, content management and enquiry forms.
7.3 Google Ireland Limited - website analytics, deployed only where the visitor has given consent by means of the cookie notice.
7.4 The processing described in this Clause 7 is governed by the Privacy Policy at www.tems.ai/privacy.
8. RECORD OF CHANGES
Changes to this page are recorded below. Each entry states the date of publication and the date upon which the change took effect.
01.09.2026 - Version 1.0 published. Initial list of sub-processors.
9. CONTACT
Questions concerning this page, requests to subscribe to notifications, and objections under Clause 8.4 of the Data Processing Agreement, shall be addressed to welcome@tems.ai.
RELATED DOCUMENTS
TemsSoft B.V. - welcome@tems.ai
