Sub-Processors List
Effective Date: 14 April 2026 Last Updated: 29 September 2026 Owner: Privacy Officer Review Frequency: On engagement of any new sub-processor, and at minimum quarterly during the management review
This page lists the sub-processors engaged by Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust (ABN 61 633 823 792) for Maelstrom’s own infrastructure and our support platform. Sections 1 and 2 are the sub-processor list. Annex III of the SCC Addendum, the Standard DPA and the Enterprise DPA refer to this list. The page also names the providers for Maelstrom’s own records. They are not sub-processors under the DPAs.
Maelstrom AI runs one ISMS over downpipes and our support platform.
- downpipes, no-custody backup and disaster recovery for the Cloudflare data layer. Available now.
- Our support platform, Maelstrom’s internal support system. It handles support for downpipes.
The sub-processors in Section 1 relate to Maelstrom’s own infrastructure: the website, and the content-free downpipes surfaces. We list our support platform’s sub-processors separately, in Section 2, because it holds support data under the DPA rather than operating no-custody. downpipes is no-custody: it runs in the customer’s own Cloudflare account, under the customer’s own keys, and Maelstrom holds no customer keys, backup data or Cloudflare tokens for it. No customer backup data is processed by, or on behalf of, Maelstrom for downpipes. For this reason, Maelstrom engages no sub-processor for its customer data, and it adds no entry to this list beyond Section 1. See the downpipes scope note below.
Customers acting as data controllers are deemed to have given general written authorisation under SCC Module 2 Clause 9(a) Option 2 to the sub-processors listed below. Maelstrom AI will give at least 30 days’ advance notice of changes to this list (additions, removals, and material scope changes). Maelstrom AI will give that notice through the notification mechanism described under Notification of Changes.
Maelstrom also uses providers for its own correspondence, billing and accounting records. The section Providers for Maelstrom’s own records lists them. The general authorisation, the 30-day notice and Annex III do not apply to them.
Completeness attestation
As of 25 September 2026, this list names every sub-processor engaged for Maelstrom’s own infrastructure and for our support platform. This page also names every provider for Maelstrom’s own correspondence, billing and accounting records. downpipes.io/trust/sub-processors names the same six providers: Cloudflare, Amazon Web Services, Proton, Stripe, Xero and Airwallex. This list was cross-checked against the Cloudflare account configuration and the records of processing.
downpipes: no sub-processor for customer data
downpipes, Maelstrom AI’s no-custody backup and disaster-recovery platform for the Cloudflare data layer, adds no sub-processor to this list, for the following reasons:
- No-custody architecture. The downpipes engine and console are deployed and run in the customer’s own Cloudflare account, under the customer’s own keys. Backup archives are sealed under customer-held keys (break-glass and archive-signer keys, and an optional operational key, generated by the customer in a guided in-browser key ceremony) using post-quantum hybrid encryption, and are written via a 3-2-1 fan-out to customer-controlled destinations. Through the product itself, Maelstrom holds no customer keys, data or Cloudflare tokens.
- No customer data processed by Maelstrom through the product. Because customer data is never received or processed by, or on behalf of, Maelstrom through the downpipes product itself, the product triggers no processing for which Maelstrom would engage a sub-processor. The Cloudflare services that host the engine, console and customer-controlled destinations are contracted under the customer’s own Cloudflare account: they are the customer’s own infrastructure, not a Maelstrom sub-processor. Where a customer chooses to send Maelstrom a diagnostic bundle (see Consent-based diagnostics, below), that bundle is support data, held by Maelstrom under Section 2, not customer data processed through the product.
- Vendor-operated surfaces are content-free. Maelstrom operates only the control plane (mints licence tokens for customers; holds no customer keys, backup data or Cloudflare tokens) and the static, signature-pinned update channel (pull-only, no phone-home). Neither carries customer backup data or keys, so neither introduces a sub-processor for that data.
- Consent-based diagnostics only. There is no standing vendor access path. Diagnostics, when needed, use a redaction-safe signed support bundle plus owner-minted, time-boxed, scoped, immediately-revocable read-only pull credentials, initiated by the customer. No customer data leaves the customer’s account by default.
Today, downpipes operations engage no sub-processor that processes customer data. If they later engage one, Maelstrom will add it to this list under the Notification of Changes procedure. Our ISMS scope statement (available to customers, prospects and auditors on request) describes the complementary user-entity controls for the customer-operated engine and console (including the customer’s own selection of Cloudflare and delivery destinations).
1. Infrastructure sub-processors
1.1 Cloudflare, Inc.
| Field | Detail |
|---|---|
| Sub-processor | Cloudflare, Inc. |
| Address | 101 Townsend Street, San Francisco, CA 94107, USA |
| Services delivered | Cloudflare Workers, Cloudflare Workers KV, Cloudflare R2 object storage, Cloudflare Secrets Store, Cloudflare Email Service (outbound licence and subscription email), Cloudflare Email Routing (inbound mail for downpipes.io), Cloudflare DNS, Cloudflare managed challenge (CAPTCHA replacement), Cloudflare WAF |
| Purpose | Hosting and execution of the Maelstrom AI website, the downpipes control plane (mints licence tokens for customers) and the signature-pinned update channel |
| Data shared | The website sets no cookies of its own and has no forms (see Privacy Policy Section 2.1). The control plane and update channel carry no customer backup data and hold no customer keys or Cloudflare tokens. The control plane processes the business contact details (names, work email addresses and role titles) of each licensee’s nominated contacts. For a Business self-serve subscription, it also holds the billing name and email address given at Stripe checkout. It also holds the Stripe customer and subscription references, the band and the subscription status. When a customer activates a licence, the control plane records the claim code and the zone that the licence is activated from. It does not record a zone that many unrelated tenants share, such as workers.dev. It also records the Cloudflare account id when the deployment supplies it. When a customer turns on the optional advisory beacon, the control plane receives aggregate counts and version identifiers, with the Cloudflare account tag. Cloudflare’s own CDN and bot-management services process request metadata, including IP addresses, for security purposes across this infrastructure. |
| Retention | The control plane keeps a customer record while the customer relationship continues. It keeps a prospective customer’s record, with the contact details they gave, in the same way. When an operator marks a record as ended, the control plane deletes it five years after its last change. Until then, the record has no time limit. An erasure request removes the contact details from an ended record. The control plane keeps the licence email log (recipient address, subject and outcome) for two years. An erasure request does not remove its entries. The control plane keeps the administrative audit log, which can include the address a licence email went to, without a time limit. An erasure request does not remove its entries either. Workers Logs keep request records, including caller IP addresses, for seven days. |
| Processing locations | Cloudflare global edge network. Traffic is served from the data centre nearest the requester. |
| Certifications | SOC 2 Type II, ISO 27001, ISO 27018 (cloud PII processor extension), PCI DSS Level 1 (for the relevant services), GDPR-compliant data processing |
| DPA in place | Yes. Cloudflare master Data Processing Addendum is the binding instrument. EU Standard Contractual Clauses (Decision 2021/914, Module 2: controller to processor) apply for transfers out of the EEA. The UK International Data Transfer Addendum applies for transfers out of the UK. |
| DPA reference | Cloudflare Data Processing Addendum, current version, accepted via the Cloudflare dashboard. |
| Sub-processor of Cloudflare | Cloudflare maintains its own published sub-processor list at https://www.cloudflare.com/gdpr/subprocessors/cloudflare-services/. Maelstrom AI monitors this list as part of supplier management. |
| Audit rights | Right to audit incorporated by reference into the DPA. Cloudflare publishes SOC 2 Type II reports under NDA. |
| Onward transfer | Cloudflare may sub-process within its own corporate group and to its named sub-processors; covered under its own DPA. |
1.2 Amazon Web Services, Inc.
| Field | Detail |
|---|---|
| Sub-processor | Amazon Web Services, Inc. |
| Address | 410 Terry Avenue North, Seattle, WA 98109-5210, USA |
| Services delivered | Amazon S3 in the Asia Pacific (Sydney) region, with S3 Object Lock in compliance mode |
| Purpose | An off-account backup copy of Maelstrom’s own systems, so that it survives a compromise of the Cloudflare account |
| Data shared | Backup archives of Maelstrom’s Cloudflare account and zone configuration, the control plane’s licence records and beacon store, the update-channel bucket, and Maelstrom’s vendor secrets. The licence records hold the licensee contact details described in Section 1.1. Each archive is encrypted before upload under keys that Maelstrom holds. AWS stores ciphertext and cannot read the contents. AWS holds no support data. |
| Retention | Each backup object is locked for 30 days and then deleted. A copy keeps any details that were erased or expired after it was made, until the copy is deleted. |
| Processing locations | Asia Pacific (Sydney), Australia |
| DPA in place | Yes. The AWS Data Processing Addendum, incorporated into the AWS Service Terms, which includes the Standard Contractual Clauses. |
2. Support sub-processors
Our support platform is Maelstrom’s internal support system. Unlike downpipes, it holds data directly, in Maelstrom’s own Cloudflare account, under the DPA. It processes support conversations, customer email addresses and display names, attachments, support bundles, and operator notes. Cloudflare Workers Logs additionally hold operator email addresses and caller IP addresses.
This section is new as of 3 September 2026. Legal counsel reviewed it. The data categories below reflect the configuration as of 2026-09-03. Each entry below states its retention.
2.1 Cloudflare, Inc. (support platform)
| Field | Detail |
|---|---|
| Sub-processor | Cloudflare, Inc. See Section 1.1 for the corporate record (address, certifications, DPA reference). This entry adds the support platform’s own data categories. |
| Services delivered | Cloudflare Durable Objects and Cloudflare R2 store support tickets, messages, attachments and support bundles. Cloudflare Email Routing and the support Email Worker receive mail sent to support@downpipes.io, privacy@downpipes.io and most other downpipes.io addresses. Mail sent to sales@downpipes.io goes to a Proton mailbox instead. Cloudflare Email Service sends our replies. Cloudflare Workers Logs and an R2 log bucket hold technical log records. |
| Purpose | Store and retrieve support tickets, messages, attachments and support bundles; run the SLA engine; operate the support platform; route inbound support mail |
| Data shared | Customer email address and display name, ticket subject and message content, attachments, support bundle contents, operator notes, entitlement snapshot, outbound reply content. Workers Logs additionally hold operator email addresses and caller IP addresses. |
| Retention | Closed tickets and attachments: 365 days after close. Support bundles: 30 days after upload, and also deleted when the ticket closes. Technical log records (operator email addresses and caller IP addresses): 90 days. |
| Processing locations | Cloudflare global edge network, within Maelstrom’s own Cloudflare account. |
| DPA in place | Yes, under the same Cloudflare master Data Processing Addendum described in Section 1.1. |
Providers for Maelstrom’s own records
The providers in this section process Maelstrom’s own correspondence, billing and accounting records. They do not process support data or customer data under the DPAs. They are not sub-processors under the DPAs, and Annex III does not include them. The general authorisation and the 30-day notice in this page do not apply to them. We handle email that you send to a maelstrom.au address under the Privacy Policy.
Proton AG
| Field | Detail |
|---|---|
| Provider | Proton AG |
| Services delivered | Company email on the maelstrom.au domain, calendar and meetings |
| Purpose | Maelstrom’s company mailboxes, including support@maelstrom.au. Mail sent to sales@downpipes.io is forwarded to a maelstrom.au mailbox. |
| Data shared | Names, email addresses and the content of correspondence that people send to a maelstrom.au address or to sales@downpipes.io |
| Processing locations | Switzerland. Switzerland has an EU adequacy decision. |
| Support data | Our support platform does not use Proton. It receives, stores and sends support mail through Cloudflare, as Section 2.1 describes. If you email support material to a maelstrom.au address, it is stored in that mailbox. |
Stripe
| Field | Detail |
|---|---|
| Provider | Stripe |
| Services delivered | Checkout, subscription billing and the billing portal for downpipes Business self-serve subscriptions |
| Purpose | Collect payment and manage subscriptions |
| Data shared | The purchaser’s name, email address and card details, the band chosen and the subscription status. Stripe collects card details on its own pages. Card details do not reach Maelstrom. |
| Processing locations | United States and global |
| Terms | Stripe’s services agreement, which includes Stripe’s data processing terms |
Xero
| Field | Detail |
|---|---|
| Provider | Xero |
| Services delivered | Invoicing and accounting |
| Purpose | Issue invoices for invoiced plans and keep the accounting records that the law requires |
| Data shared | Billing contact details and invoice records |
| Processing locations | New Zealand and the United States |
Airwallex
| Field | Detail |
|---|---|
| Provider | Airwallex |
| Services delivered | International payments |
| Purpose | Receive payments from customers outside Australia |
| Data shared | Payment and remittance details |
| Processing locations | Australia and global |
Banking
We receive Australian invoice payments through an Australian bank. A bank that receives a payment is an independent financial institution under banking law. It is not our processor, so this page does not list it.
3. Notification of changes
Maelstrom AI will notify customer-controllers of additions, removals, or material scope changes to this list via:
- Update to this page (
/trust/legal/sub-processors), with a dated entry in the Changelog below. - Direct email notification to the controller’s nominated privacy contact for any change that triggers SCC Clause 9(a) Option 2 prior-notice obligations, no later than 30 days before the new sub-processor begins processing.
A controller may object to a new sub-processor under the procedure documented in the Standard DPA and the Enterprise DPA.
4. Cross-references
| Document | Relationship |
|---|---|
| Standard DPA | This list satisfies the sub-processor disclosure obligation in the Standard DPA. |
| Enterprise DPA | This list satisfies the sub-processor disclosure obligation in the Enterprise DPA. |
| SCC Addendum | Annex III of the SCC Addendum refers to this list for the sub-processor inventory. |
| Support Privacy Notice | Discloses this list’s support-platform sub-processors to support-portal data subjects. |
| Records of processing and supplier management procedure (available to auditors on request) | Reference and support the sub-processor entries here. |
Changelog
| Version | Date | Summary |
|---|---|---|
| 1.6 | 2026-09-04 | Editorial update. |
| 1.7 | 2026-09-04 | Editorial update. |
| 2.0 | 2026-09-04 | Scope and sub-processor update. |
| 2.1 | 2026-09-24 | Editorial update. Clarified that Proton AG hosts the maelstrom.au mailboxes and is not a sub-processor of support data. No change to the sub-processors that process customer data. |
| 2.2 | 2026-09-24 | Added Amazon Web Services (Section 2.2) for encrypted backup copies of support data. Technical log records are kept for 90 days. |
| 2.3 | 2026-09-25 | Moved Amazon Web Services to Section 1.2. It holds encrypted backup copies of Maelstrom’s own systems, including the control plane’s licence records, and holds no support data. Listed the control plane’s data categories in Section 1.1. |
| 2.4 | 2026-09-25 | Replaced the company email note with a section for the providers of Maelstrom’s own records: Proton, Stripe, Xero and Airwallex. These providers are not sub-processors under the DPAs. Sections 1 and 2 do not change. Section 1.1 states how long the control plane keeps licence records. |
| 2.5 | 2026-09-29 | Plain English rewrite. No change to any commitment, right or obligation. |
Document Information
| Field | Value |
|---|---|
| Owner | Privacy Officer |
| Version | 2.5 |
| Effective date | 14 April 2026 |
| Last updated | 29 September 2026 |
| Next review | On engagement of any new sub-processor, and at minimum at the next quarterly management review |
| Classification | Public |