Third Party Index

Snapshot 19497

Document
Subprocessor list
URL
https://celldelta.ai/subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
33228 bytes
SHA-256 (raw)
6008a6a128e45306cb84342fc890f26d148c8e97867461732d96dfd0799ff76f
SHA-256 (normalized text)
fa9e7753c6aa174e1beffa054cfc003974cbf65fc8e1c6e5a8851b1ae6a4f364

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Sub-processors
Sub-processors
Last updated: 24 September 2026
01What this page is
This page lists the sub-processors that CellDelta (Krzysztof Dalewski, sole proprietor, ul. Capri 4/18, 02‑762 Warsaw, Poland) engages to operate its verification service and the celldelta.ai website. A sub-processor is a third party we use to process personal data on behalf of our customers, or to run our own business.
It complements our Privacy Policy. Where we act as a processor for customer workbook content on the managed service, this list satisfies the Article 28 GDPR requirement to identify our sub-processors; the customer remains the controller of that content.
02Controller / processor split
Two deployment modes. On the managed service, a workbook you submit for a full-file check is processed on our cloud infrastructure to produce a verdict and then deleted; for that content the customer is the controller and CellDelta acts as processor under a Data Processing Agreement. In a self-hosted deployment, your workbooks and verdicts never reach us, and none of the sub-processors below receives your content.
For data where CellDelta is itself the controller (for example, what you send us through the website contact form, and account details), the same sub-processors may be involved, on the legal bases set out in our Privacy Policy.
03Current sub-processors
The following vendors process personal data on our behalf, under data-processing terms, strictly to run the service. We keep this set small and review it before adding to it.
Sub-processors as of 24 September 2026
Sub-processor	Purpose	Personal data processed	Location	Transfer safeguard
Railway Corporation	Cloud hosting, compute, ephemeral artifact storage and durable storage for the hash-chained audit archive for the managed service, the MCP server and the website endpoint that receives the contact form.	Name, email address and any optional details (company, phone number, message) from the contact form, and a short one-way fingerprint (hash) of the email address kept for 24 hours to avoid duplicate confirmations; client IP for security; transient workbook artifacts submitted for a full-file check (1-hour sliding TTL, then evicted); durably retained audit digests and metadata (24 months, configurable). No persisted cell values.	United States	EU‑US Data Privacy Framework (certified) and/or EU Standard Contractual Clauses.
Cloudflare, Inc.	CDN, edge and DNS proxy in front of the website and service.	Visitor IP address and standard request metadata, processed at the edge for delivery, security and rate-limiting.	United States	EU Standard Contractual Clauses, and the EU‑US Data Privacy Framework where the recipient is certified.
Brevo (Sendinblue)	Transactional email / SMTP relay for the contact-form emails (the notification to us and the confirmation to the sender) and account email.	Recipient and sender email addresses and message content for the notification, the confirmation and account messages.	European Union	Processed in the EU; for any US leg, Sendinblue Inc. is covered by the EU‑US Data Privacy Framework and SCCs.
GitHub, Inc. (Microsoft)	Source-code hosting. Not part of the customer-content processing path in normal operation.	No customer workbook content and no website visitor data. Developer account metadata only.	United States	EU‑US Data Privacy Framework (certified).
Business email / mailbox provider	Receives the contact-form notification email at [email protected] and holds our business correspondence.	The name, email address and any optional details from the contact form, and the IP address and browser type included in the notification, as they rest in our mailbox; our replies.	US / EU	EU‑US Data Privacy Framework and/or EU Standard Contractual Clauses, as applicable to the provider.
Locations and safeguards reflect the position at the "last updated" date above. The EU‑US Data Privacy Framework remains valid: the EU General Court upheld it on 3 September 2025 in Latombe (T‑553/23); a CJEU appeal is pending.
04No model providers on this list
CellDelta is deterministic: it produces every verdict from fixed, versioned rules and never runs a language model. The verification path makes no outbound network call and no call to any AI provider (such as Anthropic, OpenAI, Google or Microsoft). Outside that path, the system makes only a few operational calls that carry no model data, such as delivering the contact-form emails (Brevo's HTTPS API, with an SMTP relay as fallback). As a result, no AI or model-hosting provider acts as our sub-processor, and your content is never passed to a model by us.
05Self-hosted deployments
In a self-hosted deployment, CellDelta runs inside your own cloud account or on-premises environment. Your workbooks, edits, verdicts and audit records stay within your perimeter, and none of the sub-processors above receives that content. The list on this page applies to the managed service and the celldelta.ai website.
06Changes & notification
We operate on the Article 28 general-authorisation model. We may add or replace a sub-processor as the service evolves, and when we do we update this page with a new "last updated" date.
For customers under a Data Processing Agreement, we give advance notice of any intended addition or replacement of a sub-processor that handles customer content, so you have a reasonable opportunity to object before it takes effect. Where you have a contract or DPA with us, the notice period and objection process in that agreement apply.
To be notified of changes, or to ask for a copy of the relevant transfer safeguard (SCCs or DPF certification), email [email protected].
07Contact
Questions about this list, our processing, or a Data Processing Agreement:
Krzysztof Dalewski (CellDelta)
ul. Capri 4/18, 02‑762 Warsaw, Poland
NIP 5214160761 · REGON 544460460
[email protected]
+48 733 077 407
You can also contact the Polish supervisory authority — Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00‑193 Warsaw, uodo.gov.pl.