ARGOS Subprocessor and Third-Party Service List
Version
1.0-beta- Last updated17 August 2026
This page distinguishes:
- Subprocessors, which process personal data for the ARGOS Operator in order to provide the Service; and
- user-directed connected services, which a user independently chooses to connect and which generally process data under their own terms.
Only services actually enabled in production should appear as active subprocessors. Contracting entity, region, retention, model-training treatment and transfer safeguards must be verified against the specific account and contract, not a provider's general marketing page.
Core subprocessors
| Provider | Service and purpose | Data categories | Expected locations | Transfer/safeguard verification |
|---|---|---|---|---|
| Microsoft | Azure Container Apps, Blob Storage, Key Vault, Container Registry and related hosting/security; Microsoft Entra identity and Microsoft 365 support mail | Account identifiers, durable user data, secrets, logs, application traffic and support correspondence | Primary ARGOS deployment: Switzerland North; identity, support and telemetry may involve other locations under contract | Microsoft data-protection terms and applicable Swiss/EEA transfer safeguards |
| Gemini API generative-AI processing, when configured and accepted | Prompt, selected profile/connector context, attachments or extracted text, generated output, technical metadata | Processing location depends on the exact Gemini service and project configuration and may include locations outside Switzerland/EEA | Google API/cloud data terms and applicable Swiss/EEA transfer safeguards | |
| OpenAI | OpenAI API generative-AI processing | Same categories as above | Not active in the current private-beta provider selection; contracting entity, region and endpoint must be disclosed before enablement | Verify business/API DPA, retention controls, training treatment and transfer mechanism before enablement |
| Microsoft | Azure OpenAI generative-AI processing | Same categories as above | Not active in the current private-beta provider selection; contracting entity and deployment region must be disclosed before enablement | Verify Azure OpenAI data terms, abuse-monitoring configuration, region and transfers before enablement |
| None currently | Custom OpenAI-compatible endpoint | Same categories as above | Custom providers are disabled for the current private beta | A custom provider must not be enabled until contract, security, retention, training and transfer review is complete |
Local Ollama processing does not create an external AI subprocessor when it runs solely within infrastructure controlled by the Operator. The underlying hosting provider remains listed where applicable.
Operational providers to verify
Add any provider that can receive production personal data for:
- application monitoring, telemetry or error reporting;
- transactional email and support;
- domain/DNS or content delivery where request identifiers are logged;
- payment and subscription processing;
- customer support or issue tracking;
- backups and disaster recovery; or
- legal/compliance case management.
GitHub Pages hosts the public errandom.com site and may process ordinary web-request metadata, but it does not host authenticated ARGOS account data. The list will be updated if domain/DNS, source deployment, monitoring or other operational providers begin receiving production personal data.
User-directed connected services
Depending on what the user enables, ARGOS may exchange data with services such as:
- Google Gmail, Calendar, Drive/YouTube and health APIs;
- Microsoft Outlook, Calendar, OneDrive and Microsoft Graph;
- TikTok and other social platforms;
- travel, booking and transport providers;
- Uber or mobility providers;
- health and fitness providers;
- household, energy and smart-home providers; and
- communication or messaging providers.
These providers are not automatically subprocessors of the Operator merely because the user connects them. They may act as independent controllers under their own terms. The connector screen should identify the provider, requested permissions, data exchanged and whether ARGOS stores derived or cached data.
Provider-change notice
We will publish changes to this list before a new subprocessor begins processing
existing user data where the applicable contract or law requires advance notice.
An external AI provider change is also a provider-specific disclosure and consent
event where consent is relied upon. Users may object through
info@errandom.com; available remedies depend on the circumstances and
applicable law.