Third parties that participate in operating the KINDI service, the data each receives, and the region in which each operates. This list is exhaustive as at the version date shown in the issuance particulars below.
KINDI engages the following sub-processors to provide the service. Each entry lists what the sub-processor receives, where it operates, and what it is not permitted to receive. For the definition of “Sub-processor” and the contractual safeguards KINDI flows down, see the Data Processing Addendum.
| Role | Vendor | What it receives | Region |
|---|---|---|---|
| Hosting | In-Kingdom hosting provider | Compute, storage, backups, and operational logs. Receives the encrypted envelope and the masked text in transit during a request; never receives raw request text in cleartext at rest. | Riyadh, Kingdom of Saudi Arabia |
| DNS and TLS issuance | Cloudflarecloudflare.com | DNS records for kindi.me and subdomains. Used for ACME DNS-01 certificate issuance only. Does not proxy customer traffic. Does not receive request text, response text, encrypted envelopes, or any personal data submitted to the service. | Global edge; DNS records only |
| Transactional email | Resendresend.com | The registered email address of an account and the body of operational notices to that address (account-creation confirmation, password reset, billing receipt, incident notice). Never receives the body of a masking request, the body of a masking response, or any encrypted envelope. | United States and European Union |
| Language-model provider (proxy, optional) | OpenAIopenai.com | Masked request text only, when a Customer routes a request through the KINDI proxy to a model from this provider. See the note below the table for the conditions that apply to both language-model rows. | United States |
| Language-model provider (proxy, optional) | Anthropicanthropic.com | Masked request text only, when a Customer routes a request through the KINDI proxy to a model from this provider. See the note below the table for the conditions that apply to both language-model rows. | United States |
| Payment processing | Tap Payments (forthcoming)tap.company | The top-up amount, the billing identity of the paying account, and a card token. Engaged only at the moment of a top-up. Not yet engaged: KINDI is not integrated with a live payment provider, and customer self-checkout is not enabled. This row is listed in advance so that the notice period in § II runs before the provider is first used. | Kingdom of Saudi Arabia |
Note on the language-model rows. Both language-model providers are engaged only when a Customer routes a request through the KINDI proxy; the direct masking and file-redaction endpoints never contact either of them. In every case the personal-data spans have been replaced with deterministic placeholders before the text is forwarded, and the original values and the placeholder mapping are not sent. A production request is authenticated with the Customer’s own provider key, passed through for that single request and never stored by KINDI. A dashboard demo request is authenticated with KINDI’s own operated account with that provider, under per-account and system-wide caps.
KINDI will publish a notice at least 14 days in advance of adding, replacing, or materially changing the role of any sub-processor listed above. Notices are posted on this page, with a corresponding version increment at the head of the document, and emailed to the registered address on file for each account.
A Customer that objects to a new sub-processor on reasonable data-protection grounds may, within the 14-day notice period, terminate the affected service and receive a pro-rata refund of any unused prepaid balance. The objection must be submitted in writing via the contact form at kindi.me/contact, marked for the attention of the Data Protection Officer, and must state the basis for the objection.
Hosting, storage, backups, and operational logs all remain inside the Kingdom of Saudi Arabia. Four sub-processors in the table above operate outside the Kingdom: the DNS and TLS-issuance provider, the transactional-email provider, and the two language-model providers the optional proxy reaches. Each receives the data described in the “What it receives” column and no more. The DNS provider receives no personal data at all; the language-model providers receive masked text only.
A Customer may send the masked text to a frontier language model in one of two ways. In the direct integration, the Customer’s own client makes the call to the model; KINDI is not party to that transfer, and the Customer is the Controller for it. In the optional KINDI proxy, KINDI forwards the masked text to the model on the Customer’s behalf, using the Customer’s own provider key for a production request or KINDI’s operated account for a dashboard demo; the providers reached by the proxy are listed in the table above. In both cases the text that crosses the frontier carries only deterministic placeholders, the original personal data never leaves the Kingdom, and the placeholder mapping is held in the request only and is discarded once the response is returned. The Customer remains the Controller for the cross-border transfer and is responsible for satisfying the requirements of the Transfer Regulation, including any Transfer Risk Assessment expected under Article 7 of the same regulation.