Subprocessor List
Effective Date: August 3, 2026
Last Updated: August 30, 2026
Ultimate, Inc. provides the Services under the Attribute brand ("Attribute"). This Subprocessor List identifies third parties that Attribute may use to process Customer Personal Data on Attribute's behalf in connection with the Enterprise Services.
This list forms part of the Data Processing Addendum ("DPA") where incorporated by the DPA, an Order Form, or another agreement with Customer. Capitalized terms not defined here have the meanings given in the DPA.
A listed provider does not necessarily receive data from every Customer or every Attribute Service. The providers actually involved depend on the Services and features used, Customer configuration, deployment and region, integrations, and any AI model or provider policies selected for the applicable workflow.
1. How this list works
Attribute-managed Subprocessors
An Attribute-managed Subprocessor is a third party that Attribute selects to process Customer Personal Data on Attribute's behalf in providing the Enterprise Services. Attribute requires its Subprocessors to process Customer Personal Data under written data-protection, confidentiality, and security obligations appropriate to the services they provide.
Customer-directed services
A third-party service selected, contracted, configured, or controlled by Customer is generally a Customer-directed service rather than an Attribute-managed Subprocessor. This may include a Customer's ERP, accounting system, identity provider, data warehouse, storage destination, model-provider account, cloud project, API credential, private model endpoint, or model-routing service.
The fact that Attribute connects to or transmits Customer Data to a Customer-directed service does not by itself make that service an Attribute-managed Subprocessor. The Customer's relationship with that provider governs the provider's independent processing unless the parties expressly agree otherwise.
Software and self-hosted components
Software, libraries, open-source components, locally operated models, and other technology that runs within infrastructure controlled by Attribute or Customer are not themselves Subprocessors merely because they are used to provide the Services. Where a third-party infrastructure, hosting, managed-service, model, or other provider processes Customer Personal Data on Attribute's behalf, that provider is treated and disclosed in accordance with this list and the DPA.
2. Attribute-managed Subprocessors that may be used
The following providers may process Customer Personal Data when the corresponding Attribute-managed Service, deployment, integration, AI provider, or feature is enabled.
| Provider | Purpose | Data that may be processed | When applicable |
|---|---|---|---|
| Google Cloud / Google | Cloud infrastructure, hosting, storage, compute, networking, logging and monitoring, document processing, and Google AI services such as Gemini where configured. | Customer records and metadata; documents and images; extracted text and fields; application and security logs; prompts, authorized context, Inputs, and Outputs where a Google AI service is used. | Attribute workloads and features configured to use Google Cloud, Google document-processing services, or Google AI services. |
| Auth0 by Okta | Authentication, identity management, session support, token validation, and related security functions. | User identifiers, business contact details, authentication and session metadata, tenant/application identifiers, and identity or security events. | User populations and Services for which Auth0 is enabled. |
| Anthropic (Claude) | AI model inference and related language, reasoning, coding, retrieval-support, generation, and agent/tool capabilities. | Prompts, authorized context, documents or extracts, Inputs, Outputs, tool schemas or results, and limited operational or security metadata. | Attribute-managed workflows, tools, agents, or workspaces configured to use Anthropic models. |
| OpenAI | AI model inference and related text, code, image, audio, transcription, embedding, retrieval-support, generation, and agent/tool capabilities. | Prompts, authorized context, documents or extracts, Inputs, Outputs, embeddings, supported media, tool schemas or results, and limited operational or security metadata. | Attribute-managed workflows, tools, agents, or workspaces configured to use OpenAI services. |
| xAI (Grok) | AI model inference and related reasoning, text, code, image, voice, retrieval-support, generation, and agent/tool capabilities. | Prompts, authorized context, documents or extracts, Inputs, Outputs, supported media, tool schemas or results, and limited operational or security metadata. | Attribute-managed workflows, tools, agents, or workspaces configured to use Grok models. |
| OpenRouter | Model routing and gateway services, including routing requests to eligible downstream AI model providers. | Prompts, authorized context, documents or extracts, Inputs, Outputs, tool schemas or results, routing metadata, and limited usage or security metadata. | Attribute-managed workflows, tools, agents, or workspaces configured to use OpenRouter. Applicable downstream model providers may also process the request. |
Provider names in this list refer to the relevant provider brand or provider group. Where a provider uses different contracting entities by product, account, region, or billing location, the entity governing Attribute's applicable production service is the relevant Subprocessor entity.
3. AI providers, model routing, and model assignment
Attribute supports a provider-neutral AI architecture. Depending on the Service and configuration, AI functionality may use direct provider APIs, cloud AI platforms, model-routing services, private endpoints, or local, self-hosted, customer-hosted, or open-weight models.
Where supported, Customers may configure or assign approved models, providers, routes, regions, or Customer-supplied credentials for particular workspaces, internal workflows, agents, tools, tasks, purposes, or data classifications. Attribute may separately select approved models and providers for Attribute-managed features.
When Attribute selects and operates an external AI provider or routing service that receives Customer Personal Data, the applicable provider is treated as an Attribute-managed Subprocessor. When Customer supplies or controls the provider account, API key, cloud project, endpoint, router, or private deployment, that provider is generally treated as a Customer-directed service.
When a routing service such as OpenRouter is used, both the router and any downstream model provider that processes the request may form part of the processing chain. Attribute-managed routing is limited to provider and model routes approved for the applicable workflow and configured data-use requirements. Attribute does not intentionally use an unapproved provider as a fallback where doing so would bypass applicable restrictions concerning purpose, model, provider, retention, training, region, security, or data egress.
Attribute does not use Customer Personal Data to train generalized AI models without the separate affirmative Customer authorization described in the DPA and Terms of Service.
4. Customer-directed services and integrations
Customer-directed services may include:
- ERP, accounting, warehouse, commerce, CRM, payment, or financial systems;
- Customer identity providers, communications platforms, content-management systems, analytics services, data warehouses, or storage destinations;
- Customer-controlled AI provider accounts, API keys, cloud projects, private endpoints, local or private model deployments, or routing services; and
- other third parties to which Customer instructs Attribute to export, publish, synchronize, or disclose Customer Data.
Attribute remains responsible for securely carrying out the authorized transmission within the Attribute Services. Customer is responsible for the recipient's independent processing, contractual terms, permissions, security settings, retention, and data-use settings unless the parties expressly agree otherwise.
A provider selected and operated by Attribute does not become Customer-directed merely because Customer selects among provider or model options made available through an Attribute-managed service.
5. Processing locations and international transfers
Processing locations vary by provider, service, deployment, region, support model, and Customer configuration. A provider's primary hosting region may not be the location of every support, maintenance, security, or downstream processing activity.
Customer-specific data-residency commitments apply only where expressly stated in an Order Form or other written agreement with Customer.
Where Customer Personal Data is transferred from a jurisdiction that restricts international transfers, Attribute uses the transfer safeguards required by the DPA and applicable law, which may include an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, or another lawful transfer mechanism.
Additional information about a provider's processing locations and transfer mechanisms may be made available on request where reasonably necessary for Customer's compliance obligations.
6. Changes to this list
Advance notice
Attribute will provide at least 30 days' advance notice before authorizing a new material Subprocessor to process Customer Personal Data, ordinarily by updating this list and providing notice to the Customer contact designated for Subprocessor notices.
Attribute may use a shorter notice period where an urgent replacement is reasonably necessary to protect security, service availability, or legal compliance. In that case, Attribute will provide notice as soon as reasonably practicable.
Customer objections
Customer may object to a new material Subprocessor within 15 days after notice on reasonable and documented data-protection grounds. The process for addressing the objection, including any applicable alternative, affected-Service termination right, or refund, is governed by the DPA.
An objection does not suspend unaffected Services or excuse payment obligations for those Services.
Non-material changes
Attribute may update a provider's name, ownership information, description, address, or other non-material information without treating the update as the addition of a new Subprocessor where the change does not materially increase the data-protection risk, unless applicable law or the Agreement requires otherwise.
7. Contact and Subprocessor notices
Questions about this Subprocessor List, the DPA, or Subprocessor notices may be sent to privacy@ultimate.dev.
Legal notices may be sent to the Legal email or mailing address below.
- Legal
- legal@ultimate.dev
- Security
- security@ultimate.dev
- Privacy
- privacy@ultimate.dev