Sub-Processors List

Authorised sub-processors used by Maelstrom AI for the website, the downpipes licence and our support platform, and the providers for Maelstrom's own records.

Public

Sub-Processors List

Effective Date: 14 April 2026 Last Updated: 29 September 2026 Owner: Privacy Officer Review Frequency: On engagement of any new sub-processor, and at minimum quarterly during the management review

This page lists the sub-processors engaged by Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust (ABN 61 633 823 792) for Maelstrom’s own infrastructure and our support platform. Sections 1 and 2 are the sub-processor list. Annex III of the SCC Addendum, the Standard DPA and the Enterprise DPA refer to this list. The page also names the providers for Maelstrom’s own records. They are not sub-processors under the DPAs.

Maelstrom AI runs one ISMS over downpipes and our support platform.

  • downpipes, no-custody backup and disaster recovery for the Cloudflare data layer. Available now.
  • Our support platform, Maelstrom’s internal support system. It handles support for downpipes.

The sub-processors in Section 1 relate to Maelstrom’s own infrastructure: the website, and the content-free downpipes surfaces. We list our support platform’s sub-processors separately, in Section 2, because it holds support data under the DPA rather than operating no-custody. downpipes is no-custody: it runs in the customer’s own Cloudflare account, under the customer’s own keys, and Maelstrom holds no customer keys, backup data or Cloudflare tokens for it. No customer backup data is processed by, or on behalf of, Maelstrom for downpipes. For this reason, Maelstrom engages no sub-processor for its customer data, and it adds no entry to this list beyond Section 1. See the downpipes scope note below.

Customers acting as data controllers are deemed to have given general written authorisation under SCC Module 2 Clause 9(a) Option 2 to the sub-processors listed below. Maelstrom AI will give at least 30 days’ advance notice of changes to this list (additions, removals, and material scope changes). Maelstrom AI will give that notice through the notification mechanism described under Notification of Changes.

Maelstrom also uses providers for its own correspondence, billing and accounting records. The section Providers for Maelstrom’s own records lists them. The general authorisation, the 30-day notice and Annex III do not apply to them.

Completeness attestation

As of 25 September 2026, this list names every sub-processor engaged for Maelstrom’s own infrastructure and for our support platform. This page also names every provider for Maelstrom’s own correspondence, billing and accounting records. downpipes.io/trust/sub-processors names the same six providers: Cloudflare, Amazon Web Services, Proton, Stripe, Xero and Airwallex. This list was cross-checked against the Cloudflare account configuration and the records of processing.

downpipes: no sub-processor for customer data

downpipes, Maelstrom AI’s no-custody backup and disaster-recovery platform for the Cloudflare data layer, adds no sub-processor to this list, for the following reasons:

  • No-custody architecture. The downpipes engine and console are deployed and run in the customer’s own Cloudflare account, under the customer’s own keys. Backup archives are sealed under customer-held keys (break-glass and archive-signer keys, and an optional operational key, generated by the customer in a guided in-browser key ceremony) using post-quantum hybrid encryption, and are written via a 3-2-1 fan-out to customer-controlled destinations. Through the product itself, Maelstrom holds no customer keys, data or Cloudflare tokens.
  • No customer data processed by Maelstrom through the product. Because customer data is never received or processed by, or on behalf of, Maelstrom through the downpipes product itself, the product triggers no processing for which Maelstrom would engage a sub-processor. The Cloudflare services that host the engine, console and customer-controlled destinations are contracted under the customer’s own Cloudflare account: they are the customer’s own infrastructure, not a Maelstrom sub-processor. Where a customer chooses to send Maelstrom a diagnostic bundle (see Consent-based diagnostics, below), that bundle is support data, held by Maelstrom under Section 2, not customer data processed through the product.
  • Vendor-operated surfaces are content-free. Maelstrom operates only the control plane (mints licence tokens for customers; holds no customer keys, backup data or Cloudflare tokens) and the static, signature-pinned update channel (pull-only, no phone-home). Neither carries customer backup data or keys, so neither introduces a sub-processor for that data.
  • Consent-based diagnostics only. There is no standing vendor access path. Diagnostics, when needed, use a redaction-safe signed support bundle plus owner-minted, time-boxed, scoped, immediately-revocable read-only pull credentials, initiated by the customer. No customer data leaves the customer’s account by default.

Today, downpipes operations engage no sub-processor that processes customer data. If they later engage one, Maelstrom will add it to this list under the Notification of Changes procedure. Our ISMS scope statement (available to customers, prospects and auditors on request) describes the complementary user-entity controls for the customer-operated engine and console (including the customer’s own selection of Cloudflare and delivery destinations).

1. Infrastructure sub-processors

1.1 Cloudflare, Inc.

FieldDetail
Sub-processorCloudflare, Inc.
Address101 Townsend Street, San Francisco, CA 94107, USA
Services deliveredCloudflare Workers, Cloudflare Workers KV, Cloudflare R2 object storage, Cloudflare Secrets Store, Cloudflare Email Service (outbound licence and subscription email), Cloudflare Email Routing (inbound mail for downpipes.io), Cloudflare DNS, Cloudflare managed challenge (CAPTCHA replacement), Cloudflare WAF
PurposeHosting and execution of the Maelstrom AI website, the downpipes control plane (mints licence tokens for customers) and the signature-pinned update channel
Data sharedThe website sets no cookies of its own and has no forms (see Privacy Policy Section 2.1). The control plane and update channel carry no customer backup data and hold no customer keys or Cloudflare tokens. The control plane processes the business contact details (names, work email addresses and role titles) of each licensee’s nominated contacts. For a Business self-serve subscription, it also holds the billing name and email address given at Stripe checkout. It also holds the Stripe customer and subscription references, the band and the subscription status. When a customer activates a licence, the control plane records the claim code and the zone that the licence is activated from. It does not record a zone that many unrelated tenants share, such as workers.dev. It also records the Cloudflare account id when the deployment supplies it. When a customer turns on the optional advisory beacon, the control plane receives aggregate counts and version identifiers, with the Cloudflare account tag. Cloudflare’s own CDN and bot-management services process request metadata, including IP addresses, for security purposes across this infrastructure.
RetentionThe control plane keeps a customer record while the customer relationship continues. It keeps a prospective customer’s record, with the contact details they gave, in the same way. When an operator marks a record as ended, the control plane deletes it five years after its last change. Until then, the record has no time limit. An erasure request removes the contact details from an ended record. The control plane keeps the licence email log (recipient address, subject and outcome) for two years. An erasure request does not remove its entries. The control plane keeps the administrative audit log, which can include the address a licence email went to, without a time limit. An erasure request does not remove its entries either. Workers Logs keep request records, including caller IP addresses, for seven days.
Processing locationsCloudflare global edge network. Traffic is served from the data centre nearest the requester.
CertificationsSOC 2 Type II, ISO 27001, ISO 27018 (cloud PII processor extension), PCI DSS Level 1 (for the relevant services), GDPR-compliant data processing
DPA in placeYes. Cloudflare master Data Processing Addendum is the binding instrument. EU Standard Contractual Clauses (Decision 2021/914, Module 2: controller to processor) apply for transfers out of the EEA. The UK International Data Transfer Addendum applies for transfers out of the UK.
DPA referenceCloudflare Data Processing Addendum, current version, accepted via the Cloudflare dashboard.
Sub-processor of CloudflareCloudflare maintains its own published sub-processor list at https://www.cloudflare.com/gdpr/subprocessors/cloudflare-services/. Maelstrom AI monitors this list as part of supplier management.
Audit rightsRight to audit incorporated by reference into the DPA. Cloudflare publishes SOC 2 Type II reports under NDA.
Onward transferCloudflare may sub-process within its own corporate group and to its named sub-processors; covered under its own DPA.

1.2 Amazon Web Services, Inc.

FieldDetail
Sub-processorAmazon Web Services, Inc.
Address410 Terry Avenue North, Seattle, WA 98109-5210, USA
Services deliveredAmazon S3 in the Asia Pacific (Sydney) region, with S3 Object Lock in compliance mode
PurposeAn off-account backup copy of Maelstrom’s own systems, so that it survives a compromise of the Cloudflare account
Data sharedBackup archives of Maelstrom’s Cloudflare account and zone configuration, the control plane’s licence records and beacon store, the update-channel bucket, and Maelstrom’s vendor secrets. The licence records hold the licensee contact details described in Section 1.1. Each archive is encrypted before upload under keys that Maelstrom holds. AWS stores ciphertext and cannot read the contents. AWS holds no support data.
RetentionEach backup object is locked for 30 days and then deleted. A copy keeps any details that were erased or expired after it was made, until the copy is deleted.
Processing locationsAsia Pacific (Sydney), Australia
DPA in placeYes. The AWS Data Processing Addendum, incorporated into the AWS Service Terms, which includes the Standard Contractual Clauses.

2. Support sub-processors

Our support platform is Maelstrom’s internal support system. Unlike downpipes, it holds data directly, in Maelstrom’s own Cloudflare account, under the DPA. It processes support conversations, customer email addresses and display names, attachments, support bundles, and operator notes. Cloudflare Workers Logs additionally hold operator email addresses and caller IP addresses.

This section is new as of 3 September 2026. Legal counsel reviewed it. The data categories below reflect the configuration as of 2026-09-03. Each entry below states its retention.

2.1 Cloudflare, Inc. (support platform)

FieldDetail
Sub-processorCloudflare, Inc. See Section 1.1 for the corporate record (address, certifications, DPA reference). This entry adds the support platform’s own data categories.
Services deliveredCloudflare Durable Objects and Cloudflare R2 store support tickets, messages, attachments and support bundles. Cloudflare Email Routing and the support Email Worker receive mail sent to support@downpipes.io, privacy@downpipes.io and most other downpipes.io addresses. Mail sent to sales@downpipes.io goes to a Proton mailbox instead. Cloudflare Email Service sends our replies. Cloudflare Workers Logs and an R2 log bucket hold technical log records.
PurposeStore and retrieve support tickets, messages, attachments and support bundles; run the SLA engine; operate the support platform; route inbound support mail
Data sharedCustomer email address and display name, ticket subject and message content, attachments, support bundle contents, operator notes, entitlement snapshot, outbound reply content. Workers Logs additionally hold operator email addresses and caller IP addresses.
RetentionClosed tickets and attachments: 365 days after close. Support bundles: 30 days after upload, and also deleted when the ticket closes. Technical log records (operator email addresses and caller IP addresses): 90 days.
Processing locationsCloudflare global edge network, within Maelstrom’s own Cloudflare account.
DPA in placeYes, under the same Cloudflare master Data Processing Addendum described in Section 1.1.

Providers for Maelstrom’s own records

The providers in this section process Maelstrom’s own correspondence, billing and accounting records. They do not process support data or customer data under the DPAs. They are not sub-processors under the DPAs, and Annex III does not include them. The general authorisation and the 30-day notice in this page do not apply to them. We handle email that you send to a maelstrom.au address under the Privacy Policy.

Proton AG

FieldDetail
ProviderProton AG
Services deliveredCompany email on the maelstrom.au domain, calendar and meetings
PurposeMaelstrom’s company mailboxes, including support@maelstrom.au. Mail sent to sales@downpipes.io is forwarded to a maelstrom.au mailbox.
Data sharedNames, email addresses and the content of correspondence that people send to a maelstrom.au address or to sales@downpipes.io
Processing locationsSwitzerland. Switzerland has an EU adequacy decision.
Support dataOur support platform does not use Proton. It receives, stores and sends support mail through Cloudflare, as Section 2.1 describes. If you email support material to a maelstrom.au address, it is stored in that mailbox.

Stripe

FieldDetail
ProviderStripe
Services deliveredCheckout, subscription billing and the billing portal for downpipes Business self-serve subscriptions
PurposeCollect payment and manage subscriptions
Data sharedThe purchaser’s name, email address and card details, the band chosen and the subscription status. Stripe collects card details on its own pages. Card details do not reach Maelstrom.
Processing locationsUnited States and global
TermsStripe’s services agreement, which includes Stripe’s data processing terms

Xero

FieldDetail
ProviderXero
Services deliveredInvoicing and accounting
PurposeIssue invoices for invoiced plans and keep the accounting records that the law requires
Data sharedBilling contact details and invoice records
Processing locationsNew Zealand and the United States

Airwallex

FieldDetail
ProviderAirwallex
Services deliveredInternational payments
PurposeReceive payments from customers outside Australia
Data sharedPayment and remittance details
Processing locationsAustralia and global

Banking

We receive Australian invoice payments through an Australian bank. A bank that receives a payment is an independent financial institution under banking law. It is not our processor, so this page does not list it.

3. Notification of changes

Maelstrom AI will notify customer-controllers of additions, removals, or material scope changes to this list via:

  • Update to this page (/trust/legal/sub-processors), with a dated entry in the Changelog below.
  • Direct email notification to the controller’s nominated privacy contact for any change that triggers SCC Clause 9(a) Option 2 prior-notice obligations, no later than 30 days before the new sub-processor begins processing.

A controller may object to a new sub-processor under the procedure documented in the Standard DPA and the Enterprise DPA.

4. Cross-references

DocumentRelationship
Standard DPAThis list satisfies the sub-processor disclosure obligation in the Standard DPA.
Enterprise DPAThis list satisfies the sub-processor disclosure obligation in the Enterprise DPA.
SCC AddendumAnnex III of the SCC Addendum refers to this list for the sub-processor inventory.
Support Privacy NoticeDiscloses this list’s support-platform sub-processors to support-portal data subjects.
Records of processing and supplier management procedure (available to auditors on request)Reference and support the sub-processor entries here.

Changelog

VersionDateSummary
1.62026-09-04Editorial update.
1.72026-09-04Editorial update.
2.02026-09-04Scope and sub-processor update.
2.12026-09-24Editorial update. Clarified that Proton AG hosts the maelstrom.au mailboxes and is not a sub-processor of support data. No change to the sub-processors that process customer data.
2.22026-09-24Added Amazon Web Services (Section 2.2) for encrypted backup copies of support data. Technical log records are kept for 90 days.
2.32026-09-25Moved Amazon Web Services to Section 1.2. It holds encrypted backup copies of Maelstrom’s own systems, including the control plane’s licence records, and holds no support data. Listed the control plane’s data categories in Section 1.1.
2.42026-09-25Replaced the company email note with a section for the providers of Maelstrom’s own records: Proton, Stripe, Xero and Airwallex. These providers are not sub-processors under the DPAs. Sections 1 and 2 do not change. Section 1.1 states how long the control plane keeps licence records.
2.52026-09-29Plain English rewrite. No change to any commitment, right or obligation.

Document Information

FieldValue
OwnerPrivacy Officer
Version2.5
Effective date14 April 2026
Last updated29 September 2026
Next reviewOn engagement of any new sub-processor, and at minimum at the next quarterly management review
ClassificationPublic