About this page
Graphor is operated by SYNAPSE INOVAÇÃO E TECNOLOGIA LTDA., a company organized under the laws of the Federative Republic of Brazil (“Synapse” or “we”). When you use the Graphor Service, Synapse acts as a data processor on your behalf. To deliver the Service, Synapse engages a limited set of third-party providers (“subprocessors”) that may process customer data. This page is the canonical, versioned record of every active subprocessor in the Graphor production environment. It is intended for procurement, security, privacy, and compliance teams evaluating Graphor for use under LGPD, GDPR, and equivalent regimes. What this page is- A complete inventory of subprocessors that process Customer Content or Account Information in the Graphor production environment.
- Updated whenever a subprocessor is added, removed, or changes the categories of data it processes, the region in which it processes, or its retention posture.
- The reference cited by the Graphor Data Processing Addendum, the Privacy Policy, and every other Trust Center page.
- A list of every software dependency or open-source library Graphor uses. Only third parties that receive customer data are listed.
- A list of historical or deprecated subprocessors. Retired providers are removed from the table once their last data is purged; the change history at the bottom records when they were removed.
Subprocessor onboarding diligence
Before a new subprocessor is added to the inventory below, Synapse performs documented diligence to demonstrate that the provider offers “sufficient guarantees” within the meaning of LGPD art. 39 / GDPR art. 28(1). The diligence covers, at minimum:- Certification review. Current SOC 2 Type II, ISO/IEC 27001 (and, where relevant, 27017/27018/27701), PCI DSS, or FedRAMP authorization; provider’s most recent audit report obtained where available.
- DPA review. A Data Processing Addendum (or equivalent) is in place before any production traffic; the DPA must incorporate Standard Contractual Clauses (or ANPD-approved Cláusulas-Padrão Contratuais) for international transfer, and must commit the provider to not training models on Customer Content where the provider operates AI services.
- Region and residency. The provider’s region of processing must be compatible with Graphor’s residency commitments in Data Residency; deviation requires a documented exception.
- Security posture review. Encryption-at-rest and in-transit defaults, incident-response SLA, deletion mechanism, and data-segregation model are assessed against the controls inventoried in Compliance §3.
- Internal approval. A new subprocessor is added only after the founder signs off; the decision (with rationale) is recorded in a Subprocessor Onboarding Register that is available to enterprise customers under NDA via privacy@graphorlm.com.
- 30-day prior notification to existing customers (as committed above) before the new subprocessor takes production traffic, except for incident-remediation additions.
1. How to read these tables
Each subprocessor is listed with the following attributes:
Customer data categories used throughout the tables:
- Customer Content — documents, web URLs, code repositories, audio, video, transcripts, and other materials you upload, ingest, or transmit to the Service.
- Derived Content — chunks, embeddings, structured extractions, and conversation messages produced by the Service from Customer Content.
- Account Information — name, email, organization name, account credentials, and account-level metadata.
- Billing Information — billing address, partial payment data (last 4 digits of card, card brand), and payment-processor customer / subscription identifiers. Graphor does not store full payment-card data.
- Operational Telemetry — request paths, response codes, latencies, error stacks, and similar diagnostic data that may incidentally include identifiers but is not the primary purpose of the processing.
2. Cloud infrastructure (production)
The Graphor production environment runs on a single cloud project pinned tous-central1 (Iowa, USA), with one external regional dependency (AWS Bedrock for LLM serving) and one managed graph store hosted by its vendor.
3. AI model providers
Graphor uses multiple AI providers, segmented by role. None of the providers below uses customer content to train models. Verbatim citations are reproduced in the Model Use and Training page.4. Observability (tier-dependent)
Graphor uses a single observability platform for application tracing. Whether your project’s traces reach it is tier-dependent:- Enterprise tier — observability tracing is off by default. Customer prompts, completions, and retrieved context are not sent to the observability store unless the project owner explicitly enables tracing.
- Free and Pro tiers — observability tracing is on by default with the Brazilian PII mask described below. The project owner can disable tracing at any time from the project settings.
Trace retention: Enterprise default OFF — no traces produced. If the project owner explicitly opts in, Enterprise traces have a 30-day TTL. Free/Pro default ON with a 90-day TTL. Traces can also be deleted on demand via the customer-controlled DSR API. Full detail in Data Retention.
5. Payment and billing
Stripe processes payments for Graphor subscriptions. Customer Content does not transit Stripe.6. Authentication
Firebase Authentication is used for Graphor account sign-in (Google OAuth). Synapse does not directly handle Google account credentials — Firebase Auth issues an ID token after the user completes Google’s sign-in flow.7. Marketing site only
The following subprocessors are loaded only on the public marketing surfaces (graphorlm.com and the Graphor documentation site). They do not have access to Customer Content, Derived Content, or Account Information.
8. Related-party disclosure
SYNAPSE INOVAÇÃO E TECNOLOGIA LTDA. operates two distinct lines of business under the same legal entity:- Graphor — the self-service Software-as-a-Service product documented on this site.
- Synapse Consultoria — a consultancy practice that builds custom software systems for end clients.
9. Inherited certifications
Synapse does not yet hold its own SOC 2 Type II or ISO 27001 certifications (see Compliance for current status and roadmap). The subprocessors listed above carry certifications that Synapse inherits as part of the contractual relationship:
These reports are made available to Graphor enterprise customers under NDA on request to privacy@graphorlm.com.
10. Change history
When this page changes materially, this table is updated and subscribers to subprocessors@graphorlm.com receive an email.
Contact
- General privacy and DPA inquiries: privacy@graphorlm.com
- Subprocessor change notifications: subprocessors@graphorlm.com
- Customer support: support@graphorlm.com

