Documentation développeur Demander une démo
Demander une démo

Subprocessors & Compliance

Version: 2.0 (Enterprise) Entrée en vigueur: September 1, 2026
Retour au résumé

Ces documents sont publiés en anglais. Le texte anglais fait foi dans toutes les juridictions.

1Regulatory Frameworks

Traffelo AI's obligations are set out in the Privacy Policy, Section 1.1. The platform and its corporate interfaces are architected against the following frameworks:

  • Regulation (EU) 2016/679 (GDPR) and the UK Data Protection Act 2018 — EU Standard Contractual Clauses and the UK IDTA (Modules 1 and 2), supplemented by Transfer Impact Assessments.
  • Turkish Law No. 6698 (KVKK) — Article 9 cross-border transfer provisions and standard contractual terms recognised by the Kişisel Verileri Koruma Kurumu.
  • UAE Federal Decree-Law No. 45/2021 (PDPL) and Qatar Law No. 13 of 2016 — localised sovereign cloud storage to preserve in-region residency.
  • Singapore PDPA 2012 and Malaysia PDPA 2010 (as amended) — cross-border transfer equivalence mandates.

2Edge Processing Architecture

The guarantees below are stated in the Privacy Policy, Sections 2.1 and 2.2, and are reproduced here for reference.

  • Quantized WASM/ONNX models detect, mask and tokenize PII locally at the customer's sovereign edge node in sub-5ms total execution time, before any payload is transmitted to an external inference model.
  • Memory buffers holding in-flight API payloads are cleared immediately post-execution (volatile RAM execution).
  • Enterprise client datasets, prompts and output payloads are never stored, retained, monetized, or used to train public foundation models or third-party algorithms.
Performance figures published on this Site, including the sub-5ms latency claim, are modeled projections from standardized benchmark workloads in controlled edge environments. They are not a contractual warranty or SLA — see Terms of Service, Section 2.2.

3Subprocessor Register

Traffelo AI engages vetted third-party service providers to support website hosting, security logging, and transactional communications. All are bound by contract to security standards equivalent to the Privacy Policy, and are restricted from using personal data for independent processing.

The current subprocessor register is available on request. It is not reproduced on this page. Use the privacy contact below to request the current register.

4Certifications and Disclosure

For inquiries regarding SOC 2 Type II controls, ISO/IEC compliance frameworks, or to report a technical vulnerability, use the security contact below. Security research conducted outside the bounds of the Coordinated Vulnerability Disclosure policy is not authorised — see Terms of Service, Section 5(b).

Haut de page