Loracta verwendet eine begrenzte Anzahl von Unterauftragsverarbeitern zur Bereitstellung der Plattform. Diese Seite wird aus der autoritativen Quelle der Plattform-Unterauftragsverarbeiter generiert und zeigt sowohl stets aktive als auch funktionsabhängige Anbieter.
Übersicht
Version der Unterauftragsverarbeiter-Quelle: 2026-05-27. Funktionsabhängige Anbieter werden nur aktiviert, wenn die entsprechende Kundenfunktion, Integration oder Bereitstellungseinstellung aktiviert ist.
Jeder Anbieter ist durch angemessene vertragliche Bedingungen gebunden, einschließlich einer Vereinbarung zur Datenverarbeitung, wo erforderlich. Übermittlungen außerhalb der EU/EEA basieren auf Angemessenheitsbeschlüssen, EU-Standardvertragsklauseln und ergänzenden Maßnahmen, wie unten angegeben.
Aktuelle Liste
AI — large language models (chat / assistant)
| Anbieter | Zweck | Region | Übertragungsmechanismus |
|---|---|---|---|
|
OpenAI, L.L.C.
Funktionsabhängig |
Hosted large-language-model inference for chat/assistant flows when the operator selects OpenAI as the chat provider.
Engaged only when the platform/tenant configures OpenAI as the chat provider. Daten: User chat messages, Retrieved content snippets, System prompt text |
United States | EU SCCs (2021/914) + supplementary measures; data-processing addendum. |
|
Anthropic, PBC
Funktionsabhängig |
Hosted large-language-model inference for chat/assistant flows when the operator selects Anthropic as the chat provider.
Engaged only when the platform/tenant configures Anthropic as the chat provider. Daten: User chat messages, Retrieved content snippets, System prompt text |
United States | EU SCCs (2021/914) + supplementary measures; data-processing addendum. |
AI — speech-to-text transcription
| Anbieter | Zweck | Region | Übertragungsmechanismus |
|---|---|---|---|
|
AssemblyAI, Inc.
Funktionsabhängig |
Speech-to-text transcription with speaker diarization for uploaded audio/video, when the tenant's ASR data-residency policy permits cloud processing.
Engaged only when the tenant's `asr_data_residency` setting is `cloud_us` or `cloud_any` AND diarization is required. Daten: Uploaded audio/video media, Resulting transcripts and speaker labels |
United States | EU SCCs + DPA. |
|
Groq, Inc.
Funktionsabhängig |
Hosted Whisper-compatible speech-to-text inference for non-diarized transcription when the tenant's ASR residency policy permits cloud processing.
Engaged only when the tenant's `asr_data_residency` setting is `cloud_us` or `cloud_any` AND diarization is not required. Daten: Uploaded audio/video media, Resulting transcripts |
United States | EU SCCs + DPA. |
Payments and donations
| Anbieter | Zweck | Region | Übertragungsmechanismus |
|---|---|---|---|
| Stripe Payments Europe, Ltd. |
Payment processing for subscriptions, donations, and Connect-based tenant payouts.
Daten: Donor / customer name and email, Payment card information (handled by Stripe; never received by Loracta), Donation amount and currency, Transaction metadata |
European Union (Ireland) with US-based group entities | Intra-group SCCs; Stripe DPA. |
Transactional email delivery
| Anbieter | Zweck | Region | Übertragungsmechanismus |
|---|---|---|---|
| SMTP delivery provider (configured per environment) |
Transactional email delivery (verification codes, password resets, magic-link rights requests, system notifications).
Specific provider depends on the deployment environment; the active provider is disclosed on request. Daten: Recipient email address, Message subject and body |
European Union (preferred); falls back per operator configuration | Operator selects a provider with SCCs/DPA in place. |
Object storage (media, transcripts, derived artifacts)
| Anbieter | Zweck | Region | Übertragungsmechanismus |
|---|---|---|---|
| S3-compatible object storage (MinIO or hosted equivalent) |
Persistent storage for uploaded media (audio, video, images, PDFs), transcripts, generated TTS audio, and thumbnails.
Daten: Uploaded media files, Derived artifacts (transcripts, thumbnails, TTS) |
European Union (preferred); per operator configuration | Operator selects a storage provider with SCCs/DPA in place. |
User-initiated content import
| Anbieter | Zweck | Region | Übertragungsmechanismus |
|---|---|---|---|
|
Google Ireland Limited (Google Drive)
Funktionsabhängig |
Assisted document import from a user-connected Google Drive account via OAuth.
Engaged only when a user explicitly connects their Google Drive account to assist with imports. Daten: Google account email and basic profile, Drive file listings and the specific file contents imported by the user |
European Union (Ireland) | Google Workspace DPA; SCCs for any onward US transfer. |
Error reporting and logging
| Anbieter | Zweck | Region | Übertragungsmechanismus |
|---|---|---|---|
| Functional Software, Inc. (Sentry) |
Application error reporting, performance monitoring, and profiling.
Daten: Application errors and stack traces, Request URL (path), HTTP method, status code, Aggregated performance traces |
United States | EU SCCs + DPA; Loracta configures Sentry with `send_default_pii=False` and redacts cookies, POST bodies, and sensitive headers before send. |
| Grafana Labs / self-hosted Loki |
Structured application log aggregation.
Daten: Structured log lines (request id, tenant id, log level, message), IP addresses are truncated before logging (see `app/utils/observability.py`) |
European Union (preferred); per operator configuration | Self-hosted or operator-selected hosted Loki with DPA. |
Hinweis auf Änderungen
Wesentliche Ergänzungen oder Ersatzmaßnahmen werden, sofern möglich, mindestens 14 Tage im Voraus über den Arbeitsbereich-Posteingang oder einen anderen dauerhaften Kanal angekündigt. Kunden können aus berechtigten Datenschutzgründen gemäß DPA Widerspruch einlegen.
Versionsverlauf
Wir aktualisieren diese Seite, wenn sich die zugrunde liegende Verarbeitung, die Servicebedingungen oder rechtliche Verweise wesentlich ändern.