Sub-processors

Last updated August 22, 2026 3 min read

1. Current Sub-processors

This page is the current, authoritative list of the sub-processors Kronisys Inc. engages to deliver Strata. It is reproduced in the Privacy Policy and in Annex II of the Data Processing Addendum; where those differ from this page, this page governs.

Each sub-processor is bound by data-protection obligations no less protective than those in our DPA, and Kronisys remains responsible for their performance.

SubprocessorPurposeData ProcessedLocation
Microsoft Azure (App Service, SQL Database, Blob Storage, Communication Services)Hosting, database, file storage, transactional emailAll customer dataUnited States (Azure region varies by deployment)
Microsoft Azure AI FoundryAI model routing and inference. Models from OpenAI, Anthropic, xAI, DeepSeek, Mistral AI, Cohere, and Microsoft are provisioned and reached through Foundry; these providers are bound by Microsoft's enterprise terms, which prohibit training on customer data.Prompts and responsesUnited States
Brave Search (Brave Software, Inc.)Returning live web results for conversations where web search is enabledSearch queries derived from promptsUnited States
Stripe, Inc.Payment processing, invoicing, and subscription billing (ACH debit, card, and hosted invoices)Billing contact details, billing address, and tax ID; payment-method metadata such as card brand and last four digits or bank last four. Full card and bank account numbers are entered on Stripe-hosted surfaces and are not received or stored by Kronisys.United States
Atlassian (Jira and Confluence Cloud)Reading from, and — where an administrator has enabled writes — creating content in, your organization's Atlassian Cloud site. Engaged only where your organization enables the Jira or Confluence extension.Jira issue and request fields and comments; Confluence page and space content and comments; the project, queue, space, and participant metadata returned with themThe region of your organization's Atlassian Cloud site, as set when that site was created
Mapbox, Inc.Rendering interactive maps, converting addresses into coordinates (geocoding), and looking up named places when Strata answers a location question. Engaged only where your organization allows geocoding.Address, place-name and search text drawn from prompts, query results, or connected data, and the coordinates returned for it. Map styles and tiles load directly in the browser, so the viewing device's IP address and the map area being viewed also reach Mapbox.United States
Google LLC (Google Places API)Retrieving a photograph of a named venue for a place card, and only where a place lookup was run with venue detail requested.The venue name, address and coordinate already resolved through Mapbox. Photographs are relayed through Kronisys, so no browser IP address reaches Google.United States
ipapi.coIP geolocation lookup, so an administrator can see the approximate location of a sign-in. First provider tried. Engaged only where remote geolocation is enabled for the deployment.A truncated IP address only — the final octet of an IPv4 address is zeroed, and an IPv6 address is cut to its first three segments. No account or content data is sent.United States
ip-api.comIP geolocation lookup. Fallback, used only when the provider above fails or times out.A truncated IP address only, as above. This provider is reached over plain HTTP rather than TLS — see Privacy Policy § Security.Not disclosed by the provider
ipwho.isIP geolocation lookup. Fallback, used only when both providers above fail or time out.A truncated IP address only, as above.Not disclosed by the provider
CARTO (Carto Inc.) and unpkgServing the fallback map. When Mapbox is unavailable — no token, no WebGL, or its tiles are blocked — Strata draws the map with the Leaflet library (loaded from unpkg) over CARTO basemap tiles, so a map still renders.The viewing device’s IP address and the map area being viewed, because tiles and the library load directly in the browser. No address text, prompt content, or account data is sent — the coordinates were already resolved before the map is drawn.United States

The three IP geolocation providers form a single fallback chain and are tried in the order listed; the first one to answer ends the request. Kronisys does not send a full IP address to any of them.

2. Change Notice & Objection

Kronisys will provide enterprise customers at least 30 days' notice before adding or replacing a sub-processor, by email to designated administrators. Customer may object in writing on reasonable data-protection grounds within 30 days of notice by emailing legal@kronisys.com. If Kronisys cannot reasonably accommodate the objection, Customer may terminate the affected portion of the Services without penalty by giving written notice within 30 days of Kronisys's response.

To be added to the notification list, email legal@kronisys.com with the addresses that should receive notices.

3. Customer-Engaged Providers

Some providers are reached through your own account or tenant rather than through Kronisys. Atlassian (Jira and Confluence Cloud) is the current example: it is engaged only where your organization enables that extension, and the terms governing its processing are those of your own agreement with Atlassian for the site you connect. Kronisys's obligation is to access it only as you instruct.

The same principle applies to Microsoft 365 data reached through your tenant — OneDrive, Outlook, SharePoint and Teams — which Strata accesses under the permissions your administrator grants.

4. Your Own AI Engine

Strata routes model inference through Microsoft Azure AI Foundry. Organizations supply their own Azure AI Foundry endpoint and key, so prompts and responses are processed in your Azure tenant under your Microsoft agreement. The model providers reached through Foundry are contractually prohibited from training on customer data.

5. Contact

Questions about this list, or requests for our DPA:

  • Kronisys Inc. — 801 S Olive Ave, Unit 405, West Palm Beach, FL 33401, United States
  • Email: legal@kronisys.com