A Loracta utiliza um conjunto limitado de subprocessadores para fornecer a plataforma. Esta página é gerada a partir da fonte autoritativa dos subprocessadores da plataforma e mostra tanto provedores sempre ativos quanto condicionais por recurso.
Visão geral
Versão da fonte do subprocessador: 2026-05-27. Provedores condicionais são ativados apenas quando o recurso, integração ou configuração de implantação relevante do cliente está habilitado.
Cada provedor está vinculado por termos contratuais apropriados, incluindo um acordo de processamento de dados quando necessário. Transferências fora da UE/EEE dependem de decisões de adequação, Cláusulas Contratuais Padrão da UE e medidas suplementares conforme indicado abaixo.
Lista atual
AI — large language models (chat / assistant)
| Provedor | Finalidade | Região | Mecanismo de transferência |
|---|---|---|---|
|
OpenAI, L.L.C.
Condicional |
Hosted large-language-model inference for chat/assistant flows when the operator selects OpenAI as the chat provider.
Engaged only when the platform/tenant configures OpenAI as the chat provider. Dados: User chat messages, Retrieved content snippets, System prompt text |
United States | EU SCCs (2021/914) + supplementary measures; data-processing addendum. |
|
Anthropic, PBC
Condicional |
Hosted large-language-model inference for chat/assistant flows when the operator selects Anthropic as the chat provider.
Engaged only when the platform/tenant configures Anthropic as the chat provider. Dados: User chat messages, Retrieved content snippets, System prompt text |
United States | EU SCCs (2021/914) + supplementary measures; data-processing addendum. |
AI — speech-to-text transcription
| Provedor | Finalidade | Região | Mecanismo de transferência |
|---|---|---|---|
|
AssemblyAI, Inc.
Condicional |
Speech-to-text transcription with speaker diarization for uploaded audio/video, when the tenant's ASR data-residency policy permits cloud processing.
Engaged only when the tenant's `asr_data_residency` setting is `cloud_us` or `cloud_any` AND diarization is required. Dados: Uploaded audio/video media, Resulting transcripts and speaker labels |
United States | EU SCCs + DPA. |
|
Groq, Inc.
Condicional |
Hosted Whisper-compatible speech-to-text inference for non-diarized transcription when the tenant's ASR residency policy permits cloud processing.
Engaged only when the tenant's `asr_data_residency` setting is `cloud_us` or `cloud_any` AND diarization is not required. Dados: Uploaded audio/video media, Resulting transcripts |
United States | EU SCCs + DPA. |
Payments and donations
| Provedor | Finalidade | Região | Mecanismo de transferência |
|---|---|---|---|
| Stripe Payments Europe, Ltd. |
Payment processing for subscriptions, donations, and Connect-based tenant payouts.
Dados: Donor / customer name and email, Payment card information (handled by Stripe; never received by Loracta), Donation amount and currency, Transaction metadata |
European Union (Ireland) with US-based group entities | Intra-group SCCs; Stripe DPA. |
Transactional email delivery
| Provedor | Finalidade | Região | Mecanismo de transferência |
|---|---|---|---|
| SMTP delivery provider (configured per environment) |
Transactional email delivery (verification codes, password resets, magic-link rights requests, system notifications).
Specific provider depends on the deployment environment; the active provider is disclosed on request. Dados: Recipient email address, Message subject and body |
European Union (preferred); falls back per operator configuration | Operator selects a provider with SCCs/DPA in place. |
Object storage (media, transcripts, derived artifacts)
| Provedor | Finalidade | Região | Mecanismo de transferência |
|---|---|---|---|
| S3-compatible object storage (MinIO or hosted equivalent) |
Persistent storage for uploaded media (audio, video, images, PDFs), transcripts, generated TTS audio, and thumbnails.
Dados: Uploaded media files, Derived artifacts (transcripts, thumbnails, TTS) |
European Union (preferred); per operator configuration | Operator selects a storage provider with SCCs/DPA in place. |
User-initiated content import
| Provedor | Finalidade | Região | Mecanismo de transferência |
|---|---|---|---|
|
Google Ireland Limited (Google Drive)
Condicional |
Assisted document import from a user-connected Google Drive account via OAuth.
Engaged only when a user explicitly connects their Google Drive account to assist with imports. Dados: Google account email and basic profile, Drive file listings and the specific file contents imported by the user |
European Union (Ireland) | Google Workspace DPA; SCCs for any onward US transfer. |
Error reporting and logging
| Provedor | Finalidade | Região | Mecanismo de transferência |
|---|---|---|---|
| Functional Software, Inc. (Sentry) |
Application error reporting, performance monitoring, and profiling.
Dados: Application errors and stack traces, Request URL (path), HTTP method, status code, Aggregated performance traces |
United States | EU SCCs + DPA; Loracta configures Sentry with `send_default_pii=False` and redacts cookies, POST bodies, and sensitive headers before send. |
| Grafana Labs / self-hosted Loki |
Structured application log aggregation.
Dados: Structured log lines (request id, tenant id, log level, message), IP addresses are truncated before logging (see `app/utils/observability.py`) |
European Union (preferred); per operator configuration | Self-hosted or operator-selected hosted Loki with DPA. |
Aviso de alterações
Adições ou substituições materiais são anunciadas através da caixa de entrada do espaço de trabalho ou outro canal durável com pelo menos 14 dias de antecedência, quando viável. Clientes podem se opor por motivos razoáveis de proteção de dados sob o DPA.
Histórico de versões
Atualizamos esta página quando o processamento subjacente, os termos do serviço ou as referências legais mudam materialmente.