Article 1 — Scope of the list
1.1The reference technical and contractual register is version 2026-10-11. The information below presents the provider categories, their functions, the data categories, and the declared processing regions. The register is versioned: any change to the list changes its version.
1.2Each provider receives only the data necessary for the functions it performs. A voice provider processes the stream needed for the conversation and transcription; a messaging provider processes the information needed to send messages. Neither role automatically entails access to all Organization data.
1.3The processing relationships are governed by the DPA. Processing carried out by the Publisher for its own purposes is described in the Privacy Policy.
Article 2 — Categories of providers
2.1Each row indicates the category, function, data, location, transfer safeguard, and status. Locations relate to the declared scope; they should not be interpreted as a guarantee that the Service as a whole is hosted exclusively in Europe.
| Category of providers | Function | Data processed | Location and safeguards | Status |
|---|---|---|---|---|
| Website and application hosting | Hosting of the website, application, and files required for the service (documents, export archives, certificates). | accounts and permissions, service use and consumption, documents provided by the customer, export archives, technical and audit logs | France. Hosted in the European Union by a provider established in the European Union. | While in service, depending on the features used |
| Database hosting | Hosting of the service database. | accounts and permissions, text transcripts, call reports and learning outcomes, service use and consumption, technical and audit logs | European Union (storage). Data Privacy Framework for covered transfers and Standard Contractual Clauses, under the conditions set out in Article 11 of the DPA, including for remote access from a third country. | While in service, depending on the features used |
| Encrypted backups | Off-server backup storage: encrypted copies of the database, containing the data categories present in the database, and copies of application files. | accounts and permissions, text transcripts, call reports and learning outcomes, service use and consumption, technical and audit logs, documents provided by the customer, export archives | European Union (storage). Data Privacy Framework for covered transfers and Standard Contractual Clauses, under the conditions set out in Article 11 of the DPA, including for remote access from a third country. | While in service, depending on the features used |
| AI model providers | Processing of practice conversations (voice and transcript) and production of the service's AI-generated content, including call reports; they also receive document excerpts that the Organization makes visible to the simulated customer. | audio streams of conversations and transcripts, text transcripts, documents provided by the customer | Primarily the United States; locations are not guaranteed for all providers. Data Privacy Framework for covered transfers and Standard Contractual Clauses, under the conditions set out in Article 11 of the DPA, including for remote access from a third country. | While in service, depending on the features used |
| Email delivery | Delivery of service emails, including account verification, invitations, and notifications. | Email addresses and service messages | European Union or United States, depending on the sending region configured with the provider. Data Privacy Framework for covered transfers and Standard Contractual Clauses, under the conditions set out in Article 11 of the DPA, including for remote access from a third country. | While in service, depending on the features used |
| Online payment | Management of subscriptions and payments when online payment is enabled. This processing is not available under the current quote-and-invoice offering. | Billing identity and payment data | European Union. Data Privacy Framework for covered transfers and Standard Contractual Clauses, subject to the conditions of Article 11 of the DPA, including for remote access from a third country. | Conditional on online payments being enabled; not used for current payments |
2.2The named list forms part of Annex 3 of the DPA and has the same version as this register.
Article 3 — Hosting and backups
3.1The application server is located in France and the database in the European Union. Encrypted database backups are stored under European storage jurisdiction. A backup contains the categories of data in the database it protects, in addition to files or exports hosted through the storage feature.
3.2Database backups are retained for thirty days in remote storage, file copies for thirty days after deletion or replacement, and local copies for seven days. Retention periods and deletion procedures are specified in the DPA and the Privacy Policy. The fact that a medium is backed up does not authorize its use for another purpose.
Article 4 — Artificial intelligence providers
4.1The Service’s AI features (practice conversations, transcription, call reports, and coaching) rely on specialized artificial intelligence model providers. They process data outside the European Union, including in the United States. These transfers are covered by the Data Privacy Framework or Standard Contractual Clauses, under the conditions set out in Article 11 of the DPA. It is therefore not accurate to state that calls and analyses are processed exclusively in Europe.
4.2The Service does not retain any audio recordings. The audio stream is transmitted to the provider only during the call (and, for a message left on simulated voicemail, immediately after it is recorded) to enable the conversation and transcription. Transcripts and documents may be transmitted for content generation or for the educational analysis of the exercise. The AI Notice explains how these operations work.
4.3Providers process this data under their contractual commitments and may retain some of it for a limited period, particularly for security and abuse prevention. The Provider does not instruct them to use this data for any purpose of their own; the actual retention and use terms are those set out in each provider’s contracts, which may be disclosed to the Customer under the conditions of Article 5.3. The Provider limits the data transmitted to what is strictly necessary. The detailed list of providers is available to the Customer in their account and upon request at privacy@clozing.example.
Article 5 — Safeguards for international transfers
5.1Transfers to the United States are governed by the Data Privacy Framework within the scope of the adequacy decision and applicable certification, as well as by the standard contractual clauses under the relevant contractual terms. Simply referring to these mechanisms does not remove the need to verify their scope.
5.2For a transfer not covered by an adequacy decision, standard contractual clauses and, where necessary, supplementary measures provide the required framework. If a safeguard ceases to apply, the Publisher adopts another valid mechanism or suspends the transfer concerned.
5.3Customers may request information about these safeguards at privacy@clozing.example. Documents provided may be redacted to protect trade secrets or third-party data that is not necessary for verification.
5.4When a provider established outside the European Union hosts data in the European Union, any remote access from a third country is covered by the Standard Contractual Clauses or the Data Privacy Framework.
Article 6 — Conditional providers and Customer choice
6.1The online payment provider is listed in the register with a status conditional on online payments being enabled. The Service is currently subscribed to by quote and invoice. This statement does not mean that card payments are available or that a card is required for the free trial.
6.2The identity provider configured by the Customer for its SSO is chosen by the Customer and is subject to the Customer's relationship with that provider. The Customer must account for its processing when informing users. Merely configuring it does not make it a sub-processor selected by the Provider.
Article 7 — Changes, notification, and objection
7.1Adding or replacing a provider, or making a significant change to a location or safeguard, results in an update to the register and prior notification to the Customer in accordance with Article 10 of the DPA. The notice period is 30 days; the Customer has 15 days after notification to submit an objection based on data protection.
7.2The parties will consider possible safeguards or alternative solutions. If no solution is available, the Customer may terminate the affected part of the Service without penalty and receive a credit for the corresponding prepaid fees. The DPA specifies how an unresolved objection is handled.
7.3Address for objections or questions about a provider: privacy@clozing.example. The Customer should specify its Organization, the change concerned, and the reason to enable a meaningful review.
Article 8 — Versions and history
Register in force: version 2026-10-11. This edition publicly lists providers by category (the list by name is disclosed to customers) and corrects the transfer safeguard for providers established in the United States that store data in the European Union: any remote access is covered as a transfer; no providers have been added or removed. Subsequent changes are communicated in accordance with the DPA. A version applicable to an earlier period may be requested at privacy@clozing.example.
| Version date | Nature of change | Version recorded in the Service |
|---|---|---|
| October 10, 2026 | Detailed description of providers, distinction between statuses, clarification of transfers, backup data categories and artificial intelligence providers, and backup retention periods. | 2026-10-10 |
| October 11, 2026 | Public listing by category, with the list by name reserved for customers and provided upon request; transfer safeguards for remote access by providers established in the United States that store data in the European Union. | 2026-10-11 |