This document is intended to be readable. Headings help navigation but do not limit the meaning of the sections beneath them.
How this list works
Oryxa can be deployed with different infrastructure, model, email, and integration providers. A provider is a subprocessor for a customer only when it is enabled for that customer’s environment and processes Customer Personal Data on Oryxa’s behalf.
The relevant order form, deployment description, and workspace configuration determine the actual provider set. We publish supported provider categories here without pretending every optional integration is always active.
Supported provider categories
| Provider or category | Purpose | Use |
|---|---|---|
| Google Cloud and Firebase | Authentication, cloud infrastructure, databases, secrets, logging, and agent runtime services. | Conditional on deployment configuration. |
| Amazon Web Services | Transactional email, cloud infrastructure, or model inference through configured AWS services. | Conditional on deployment configuration. |
| Customer-selected model providers | AI inference needed to interpret instructions, generate drafts, and coordinate requested actions. | Only providers enabled for the workspace or contracted environment. |
| Composio | OAuth connection and integration tooling for third-party business applications. | Only when the Composio integration layer is enabled. |
| Customer-selected connected services | Applications such as communication, document, project, developer, CRM, or commerce tools directed by Customer. | Selected and authorized by Customer; these services may also act as independent controllers. |
Locations and transfers
Processing locations depend on the selected provider, customer region, and service configuration. Where applicable law restricts international transfers, Oryxa and the customer will use appropriate contractual or other lawful safeguards.
Customers with data-residency requirements should document them in the order form before production processing begins.
Changes and objections
We may add or replace providers as the service changes. Where the agreement requires advance notice, customers can request subprocessor notifications through the contact address below.
A customer may object to a new subprocessor on reasonable data-protection grounds during the contractual notice period. We will work in good faith to offer a commercially reasonable alternative, configuration change, or termination of the affected feature.
Customer-directed integrations
When a customer instructs Oryxa to connect to a third-party application, that third party is not automatically an Oryxa subprocessor. It may process data directly under its agreement with Customer. Customer is responsible for reviewing the service, permissions, and legal terms before connecting it.
Talk to a person.
For privacy, contractual, security, or policy questions, contact hello@oryxa.in.