Subprocessor Change Log
Last updated: 2026-06-11
This page is the audit record of every change to dicted's published Subprocessor List. It exists because the DPA and Subprocessor List commit us to notifying customers by email at least 30 days before a new subprocessor gains access to customer data — and that commitment is only meaningful if there is a paper trail. Each entry below records what changed, when, and how notice was given (or why notice was not required, e.g. for the initial pre-launch snapshot).
Entries are append-only and dated. The most recent change is at the top. Material edits to an entry after publication (e.g. fixing a typo) are made with a strike-through and a dated note rather than by overwriting history.
How to read this log
| Column | Meaning |
|---|---|
| Date | The date the change took effect — i.e. the day the subprocessor was added/removed/replaced from a data-flow perspective, not the day this log was edited |
| Change | What changed — Added, Removed, Replaced, or No change for a periodic confirmation entry |
| Subprocessor + role | The provider and what they do for us (mirrors the Subprocessor List) |
| Notice given | When and how affected customers were notified (email, in-product banner, this log page), or N/A — pre-launch for entries that pre-date public availability |
If you are a customer who wants to be notified by email of future subprocessor changes, you are already on that list by default — every dicted account email is subscribed to subprocessor-change notices. Unsubscribing is not possible while you have an active subscription because the notice is a contractual obligation; you can close the account if you no longer wish to receive them.
Log entries
| Date | Change | Subprocessor + role | Notice given |
|---|---|---|---|
| 2026-06-11 | Added (disclosure-completeness reconciliation) — these providers were already configured as speech-to-text / language-model fallback adapters; this entry brings the published list into line with every provider capable of processing user data | Groq (speech-to-text + language-model inference fallback), Deepgram (speech-to-text fallback), AssemblyAI (speech-to-text + diarization fallback), Gladia (speech-to-text fallback; established in the European Union) | Pre-launch — published before general availability; list reconciled to disclose all configured fallback providers. Where any of these begins receiving production data for an existing customer, the 30-day email-notice commitment applies. |
| 2026-05-13 | No change — first publication of this log; subprocessor list unchanged | Initial snapshot: OpenAI (STT fallback), Soniox (meeting STT + diarization), Google Gemini (LLM on transcripts), Cloudflare R2 (meeting file storage), RunPod Secure Cloud (GPU compute for meeting transcription), Stripe (payments), Oracle Cloud (hosting + dictation GPU compute), AWS SES (transactional email), Sentry (crash reporting) | N/A — pre-launch publication; no existing customers to notify |
| 2026-04-22 | Last update to the Subprocessor List prior to this log existing | Same list as the 2026-05-13 snapshot above | N/A — pre-launch |
| 2026-04-19 | Initial published Subprocessor List | OpenAI, Soniox, Google Gemini, Cloudflare R2, RunPod Secure Cloud, Stripe, Oracle Cloud, AWS SES, Sentry | N/A — pre-launch |
Future entries
Each future addition, removal, or replacement will appear here as a new row at the top of the log table. The row will record:
- For added subprocessors: date of email notice, the 30-day objection window, and the date the new subprocessor begins receiving data
- For removed subprocessors: the cutover date and a one-line reason (e.g. "replaced by [X]", "no longer used by any product path", "vendor sunsetted the relevant API")
- For replaced subprocessors: both the removal and the addition, cross-referenced
Customers can object to any new subprocessor by emailing [email protected] during the objection window. Objections are addressed under the Data Processing Agreement §5.
Related documents
- Subprocessor List — the current, authoritative list of active subprocessors
- Data Processing Agreement — the contractual basis for the 30-day notice commitment
- Privacy Policy — how each subprocessor relates to your personal information
dicted