Loracta utiliza un conjunto limitado de subprocesadores para ofrecer la plataforma. Esta página se genera a partir de la fuente autorizada de subprocesadores de la plataforma y muestra tanto proveedores siempre activos como condicionales según funciones.
Resumen
Versión de la fuente de subprocesadores: 2026-05-27. Los proveedores condicionales se activan solo cuando la función, integración o configuración de implementación relevante del cliente está habilitada.
Cada proveedor está sujeto a términos contractuales apropiados, incluyendo un acuerdo de procesamiento de datos cuando sea necesario. Las transferencias fuera de la UE/EEE se basan en decisiones de adecuación, Cláusulas Contractuales Estándar de la UE y medidas complementarias como se indica a continuación.
Lista actual
AI — large language models (chat / assistant)
| Proveedor | Propósito | Región | Mecanismo de transferencia |
|---|---|---|---|
|
OpenAI, L.L.C.
Condicional |
Hosted large-language-model inference for chat/assistant flows when the operator selects OpenAI as the chat provider.
Engaged only when the platform/tenant configures OpenAI as the chat provider. Datos: User chat messages, Retrieved content snippets, System prompt text |
United States | EU SCCs (2021/914) + supplementary measures; data-processing addendum. |
|
Anthropic, PBC
Condicional |
Hosted large-language-model inference for chat/assistant flows when the operator selects Anthropic as the chat provider.
Engaged only when the platform/tenant configures Anthropic as the chat provider. Datos: User chat messages, Retrieved content snippets, System prompt text |
United States | EU SCCs (2021/914) + supplementary measures; data-processing addendum. |
AI — speech-to-text transcription
| Proveedor | Propósito | Región | Mecanismo de transferencia |
|---|---|---|---|
|
AssemblyAI, Inc.
Condicional |
Speech-to-text transcription with speaker diarization for uploaded audio/video, when the tenant's ASR data-residency policy permits cloud processing.
Engaged only when the tenant's `asr_data_residency` setting is `cloud_us` or `cloud_any` AND diarization is required. Datos: Uploaded audio/video media, Resulting transcripts and speaker labels |
United States | EU SCCs + DPA. |
|
Groq, Inc.
Condicional |
Hosted Whisper-compatible speech-to-text inference for non-diarized transcription when the tenant's ASR residency policy permits cloud processing.
Engaged only when the tenant's `asr_data_residency` setting is `cloud_us` or `cloud_any` AND diarization is not required. Datos: Uploaded audio/video media, Resulting transcripts |
United States | EU SCCs + DPA. |
Payments and donations
| Proveedor | Propósito | Región | Mecanismo de transferencia |
|---|---|---|---|
| Stripe Payments Europe, Ltd. |
Payment processing for subscriptions, donations, and Connect-based tenant payouts.
Datos: Donor / customer name and email, Payment card information (handled by Stripe; never received by Loracta), Donation amount and currency, Transaction metadata |
European Union (Ireland) with US-based group entities | Intra-group SCCs; Stripe DPA. |
Transactional email delivery
| Proveedor | Propósito | Región | Mecanismo de transferencia |
|---|---|---|---|
| SMTP delivery provider (configured per environment) |
Transactional email delivery (verification codes, password resets, magic-link rights requests, system notifications).
Specific provider depends on the deployment environment; the active provider is disclosed on request. Datos: Recipient email address, Message subject and body |
European Union (preferred); falls back per operator configuration | Operator selects a provider with SCCs/DPA in place. |
Object storage (media, transcripts, derived artifacts)
| Proveedor | Propósito | Región | Mecanismo de transferencia |
|---|---|---|---|
| S3-compatible object storage (MinIO or hosted equivalent) |
Persistent storage for uploaded media (audio, video, images, PDFs), transcripts, generated TTS audio, and thumbnails.
Datos: Uploaded media files, Derived artifacts (transcripts, thumbnails, TTS) |
European Union (preferred); per operator configuration | Operator selects a storage provider with SCCs/DPA in place. |
User-initiated content import
| Proveedor | Propósito | Región | Mecanismo de transferencia |
|---|---|---|---|
|
Google Ireland Limited (Google Drive)
Condicional |
Assisted document import from a user-connected Google Drive account via OAuth.
Engaged only when a user explicitly connects their Google Drive account to assist with imports. Datos: Google account email and basic profile, Drive file listings and the specific file contents imported by the user |
European Union (Ireland) | Google Workspace DPA; SCCs for any onward US transfer. |
Error reporting and logging
| Proveedor | Propósito | Región | Mecanismo de transferencia |
|---|---|---|---|
| Functional Software, Inc. (Sentry) |
Application error reporting, performance monitoring, and profiling.
Datos: Application errors and stack traces, Request URL (path), HTTP method, status code, Aggregated performance traces |
United States | EU SCCs + DPA; Loracta configures Sentry with `send_default_pii=False` and redacts cookies, POST bodies, and sensitive headers before send. |
| Grafana Labs / self-hosted Loki |
Structured application log aggregation.
Datos: Structured log lines (request id, tenant id, log level, message), IP addresses are truncated before logging (see `app/utils/observability.py`) |
European Union (preferred); per operator configuration | Self-hosted or operator-selected hosted Loki with DPA. |
Aviso de cambios
Las adiciones o reemplazos materiales se anuncian a través de la bandeja de entrada del espacio de trabajo u otro canal duradero al menos 14 días antes cuando sea factible. Los clientes pueden objetar por motivos razonables de protección de datos bajo el DPA.
Historial de versiones
Actualizamos esta página cuando cambian materialmente el procesamiento subyacente, los términos del servicio o las referencias legales.