Constellation Gate AI / Sub-processors
Legal

Sub-processor Notice and Objection Policy

Effective Date: July 7, 2026

This Sub-processor Notice and Objection Policy (this “Policy”) describes how Constellation Network, Inc., a Delaware corporation, with its principal address at 2140 S Dupont Hwy, Camden, Delaware 19934 (“Constellation,” “we,” “us,” or “our”) engages third parties to process personal data in connection with Gate AI and related services.

This Policy is intended to supplement Constellation’s customer agreements, including any applicable Data Processing Agreement (“DPA”). In the event of a conflict between this Policy and an executed DPA, the DPA controls.

1. Purpose

Constellation uses third-party service providers to support hosting, infrastructure, storage, security operations, telemetry, customer support, payment processing, and AI model routing and inference. Where those service providers process personal data on behalf of customers, they act as Sub-processors for purposes of applicable data protection law.

Because supported model providers and supporting infrastructure may change over time, Constellation maintains a process for providing notice of Sub-processor changes and for receiving and evaluating customer objections based on documented data protection concerns.

2. Definitions

For purposes of this Policy:

“Customer” means the entity that has entered into an agreement with Constellation for the Services.

“Customer Personal Data” means personal data processed by Constellation on behalf of Customer in connection with the Services.

“Sub-processor” means a third party engaged by Constellation to process Customer Personal Data on behalf of Customer in connection with the Services.

“Supported Model Provider” means a third-party provider of model inference, embeddings, moderation, or related AI functionality that Constellation makes available for routing through the Services.

3. Categories of Sub-processors

Constellation may engage Sub-processors in the following categories:

(a) cloud hosting and infrastructure providers; (b) data storage and database providers; (c) logging, monitoring, and security operations providers; (d) customer support and communications providers; (e) payment processors and billing infrastructure providers; (f) analytics and telemetry providers; (g) Supported Model Providers; and (h) other service providers reasonably necessary to provide, maintain, secure, and support the Services.

4. Sub-processor List

Constellation maintains a current Sub-processor list and publishes it on its website at https://constellationgate.ai/legal/subprocessors. The list is also available to Customers upon written request.

The Sub-processor list identifies, to the extent reasonably practicable:

(a) the Sub-processor name; (b) the general nature of the services provided; (c) the country or countries from which the Sub-processor may process Customer Personal Data; and (d) where relevant, whether the Sub-processor is a Supported Model Provider.

5. General Authorization

Customers subject to a DPA grant Constellation general written authorization to engage Sub-processors in accordance with the applicable DPA.

Constellation will impose written contractual obligations on Sub-processors that are no less protective, in substance, than the obligations Constellation undertakes in its DPA with Customers, to the extent applicable to the services performed by the Sub-processor.

Constellation remains responsible for its Sub-processors to the extent required by applicable data protection law.

6. Notice of New or Replacement Sub-processors

Constellation may add or replace Sub-processors from time to time.

Except where a shorter period is reasonably necessary due to urgent legal, security, operational, or service-continuity requirements, Constellation will provide notice of a new or replacement Sub-processor at least 10 days before the Sub-processor begins processing Customer Personal Data.

Constellation may provide notice by any of the following means:

(a) updating the published Sub-processor list; (b) sending an email notice to Customer’s designated privacy or account contact; or (c) another commercially reasonable notice method.

For Supported Model Providers, Customer acknowledges that provider availability, supported models, commercial terms, and technical integrations may change over time. Enabling or selecting a Supported Model Provider in the Services constitutes Customer’s instruction to Constellation to use that provider for the relevant processing.

7. Customer Objection Process

If Customer reasonably objects to a new or replacement Sub-processor on documented grounds relating to data protection, Customer must submit its objection in writing within the applicable notice period to privacy@constellationgate.ai.

Customer’s objection must include:

(a) the name of the relevant Sub-processor; (b) the specific basis for the objection; (c) a description of the documented data protection concern; and (d) any measures Customer believes would address the concern.

An objection is not reasonable if it is based solely on general commercial preference, a desire not to use a particular vendor absent a specific data protection issue, or opposition to changes inherent in a multi-provider technology platform without a concrete compliance concern.

8. Review and Resolution of Objections

If Customer submits a timely and reasonable objection, the parties will work in good faith to address the concern through commercially reasonable steps, which may include:

(a) providing additional information about the Sub-processor’s safeguards; (b) limiting the scope of processing involving the Sub-processor; (c) offering a configuration option that avoids the Sub-processor where technically feasible; (d) implementing supplementary contractual, technical, or organizational measures; or (e) delaying use of the Sub-processor for Customer where reasonably practicable.

If Constellation cannot reasonably resolve Customer’s objection, Customer may discontinue use of the affected Services. If the unresolved objection relates to a paid subscription service and no reasonable alternative is available, Customer may terminate the affected portion of the Services and receive a refund of prepaid fees for the unused remainder of the terminated term.

9. Emergency Changes

In limited circumstances, Constellation may need to add or replace a Sub-processor on shorter notice, including to address a security incident, vulnerability, legal obligation, service outage, or material provider failure.

In those circumstances, Constellation will provide notice as soon as reasonably practicable and will continue to honor the objection process described in this Policy to the extent practicable under the circumstances.

10. International Transfers

Some Sub-processors may process Customer Personal Data outside the country in which Customer or the relevant data subjects are located, including in the United States.

Where required by applicable data protection law, Constellation will ensure that transfers to Sub-processors are subject to an appropriate transfer mechanism, such as the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, Swiss transfer terms, or another legally recognized mechanism.

11. Security and Due Diligence

Before engaging a Sub-processor, Constellation will conduct reasonable diligence appropriate to the nature of the services provided and the risks presented by the processing involved.

Constellation will consider, as appropriate, the Sub-processor’s security posture, confidentiality commitments, technical and organizational measures, location of processing, role in the service delivery chain, and ability to comply with applicable contractual obligations.

12. Contact

Questions or objections regarding this Policy or Constellation’s Sub-processors may be sent to:

Constellation Network, Inc. 2140 S Dupont Hwy Camden, Delaware 19934 Email: privacy@constellationgate.ai


Gate AI — Sub-processor List

Effective Date: July 7, 2026

This list identifies the third-party sub-processors that Constellation Network, Inc. (“Constellation,” “we,” “us,” or “our”) engages to process personal data on behalf of customers in connection with Gate AI, as described in our Sub-processor Notice and Objection Policy. Each entry identifies: (1) the sub-processor name, (2) the general nature of services, (3) the country or countries of processing, and (4) whether it is a Supported Model Provider.

Infrastructure and Platform Sub-processors

Sub-processorNature of servicesCountry of processingSupported Model Provider?
Amazon Web Services, Inc.Cloud hosting, compute, networking, object storage, managed databases, secrets managementUnited StatesNo
Cloudflare, Inc.DNS, edge network, DDoS mitigation, TLS termination, WAF, bot management, CDNUnited StatesNo
Twilio Inc. (SendGrid)Transactional email delivery (account verification, security alerts, billing receipts)United StatesNo
Stripe, Inc.Payment processing, billing, fraud detection, tax handlingUnited StatesNo
PostHog, Inc.Product analytics, feature-usage telemetry, session replay (with input masking)United StatesNo
SentryError monitoring, performance tracing, crash reportsUnited StatesNo
Linear (Linear Orbit, Inc.)Issue tracking, customer support workflow, feature requestsUnited StatesNo

Supported Model Providers

Sub-processorNature of servicesCountry of processingSupported Model Provider?
OpenAI, L.L.C.LLM inference, embeddings, moderationUnited StatesYes
Anthropic PBCLLM inferenceUnited StatesYes
Google LLC (Google Cloud / Vertex AI)LLM inference, embeddingsUnited StatesYes
Alibaba Cloud International — Model Studio / DashScope (Qwen)LLM inference (Qwen family)United StatesYes
OpenRouter (OpenRouter Inc.)LLM aggregator / router — routes prompts to one of several underlying model providers (e.g., OpenAI, Anthropic, Google, Mistral, Meta)United States (underlying providers may vary)Yes

Notes on Supported Model Providers

OpenRouter. OpenRouter is a routing layer that forwards prompts to one of several underlying model providers. The specific downstream provider depends on the model selected by the customer at request time and may change as OpenRouter’s catalogue evolves. Constellation does not enumerate OpenRouter’s downstream providers here; the current list is maintained at OpenRouter’s website. Customers concerned about a specific downstream provider should avoid selecting models routed through OpenRouter or contact us for current routing information.

Provider region. By default, model providers process prompts in their United States regions, including Alibaba (DashScope), which is configured to route through US-based endpoints. Customers electing bring-your-own-key (BYOK) are responsible for configuring the region and data-residency settings of their own provider accounts. Where Constellation bills for usage through its own provider keys, the region is determined by Constellation’s configuration and is currently United States.

Transparency Notes

The following operations are performed by Constellation Network, Inc. (first-party) and do not involve third-party sub-processors, but are disclosed here for completeness:

Audit-trail integrity anchoring (Constellation Digital Evidence ledger). The Services may anchor cryptographic fingerprints (hashes) of audit records to the Constellation Digital Evidence ledger, which is operated by Constellation Network, Inc. as a first-party system. These fingerprints are designed to be non-reversible and do not contain personal data in intelligible form. The ledger processes only hash values; no Customer Personal Data is transmitted to or processed by the ledger.

Self-hosted security models. Certain prompt-injection detection, PII scanning, and content classification models run on Constellation’s own infrastructure within AWS and do not transmit Customer Content to any third party for these functions.

Changes

Constellation may update this list from time to time in accordance with the notice and objection process described in the Sub-processor Notice and Objection Policy. The effective date above reflects the most recent update.

Contact

Questions regarding this list or Constellation’s sub-processors may be sent to:

Constellation Network, Inc. 2140 S Dupont Hwy Camden, Delaware 19934 Email: privacy@constellationgate.ai