Sub-processor Inventory
Version 1.0 · Last updated 11 August 2026
Scope
Rwk Group Holding AB, Swedish company registration number 559544-6450, with registered address Törnrosvägen 74A, 181 61 Lidingö, Sweden, operates Lane Labs. This inventory separates core service paths from optional features and customer-authorised connectors. The Customer's Order Form and processing specification must identify which services apply to that Customer.
A provider's public terms describe its general service; they do not prove Lane's selected plan, project region, retention setting, zero-retention approval, accepted DPA or transfer assessment. Those account-level records must be completed before this inventory is incorporated into a customer agreement.
Core product and website paths
| Provider / legal entity | Service and purpose | Data categories | Location and retention position | Current qualification |
|---|---|---|---|---|
| Vercel Inc. | Marketing-site and product-interface delivery, deployment, edge request handling and related logs. | Public site assets; request and device metadata; contact/demo payloads may pass through the Site runtime; product-interface traffic metadata. | Vercel's DPA describes US primary processing and global service paths. Lane's exact project, build, function, cache and log settings must be verified. | Core hosting path. Confirm Lane's plan is covered by the Vercel DPA. |
| Railway Corporation | Lane API and application-service hosting. | Customer Data transiting the API; application metadata; logs, traces, queues and temporary runtime data where configured. | Railway's public DPA identifies US primary processing; local storage may be available for certain paid services but Lane's selected region is not yet account-verified. | Core backend path. Railway's DPA requires completion and execution. |
| Supabase Pte. Ltd. | Database, authentication and S3-compatible object-storage paths used by Lane. | Account and authentication data; Customer Data; files; database records; indexes; audit and security records. | Project data is primarily handled in the selected project region, with possible global support, control-plane and sub-processor access. Project region, backups, logs and deletion tails must be verified in Lane's account. | Core data path. DPA acceptance, project ownership and configuration remain account-level evidence. |
| Upstash, Inc. — provider identity to be confirmed from Lane's Redis account | Redis-compatible caching, rate limiting, coordination and selected short-lived vector or URL metadata. | Hashed cache keys, selected vectors or metadata, user/account control keys and coordination messages; scope depends on the calling feature. | Upstash may process globally and uses US processing paths. Backup and termination deletion follow provider routines; Lane's region and account provider must be confirmed. | Source indicates an Upstash-compatible path, but the live REDIS_URL provider is not proven. |
| Anthropic Ireland, Limited or Anthropic, PBC — account entity to be confirmed | Primary AI chat, agent workflows, document extraction and selected PDF-page vision processing. | Prompts, instructions, conversation history, project context, document excerpts or images, tool calls/results, output and account pseudonyms. | Commercial API data is not used for training by default. Standard API deletion is generally within 30 days, subject to product, feedback, safety and legal exceptions. Stored data is US-based by default; zero retention requires separate approval and eligible services. | Core model path. Lane's contracting entity, settings, DPA and any zero-retention approval are not yet evidenced. |
| OpenAI Ireland Ltd. or OpenAI OpCo, LLC — account entity to be confirmed | Embeddings for document and search pipelines and, when selected, AI chat through the Responses API. | Document chunks, search queries, prompts, conversation and tool data, model outputs and project metadata required by the enabled feature. | API data is not used for training by default unless the account opts in. Default abuse-monitoring logs may contain content for up to 30 days; endpoint state and approved zero-retention controls are separate. EU residency requires eligible project configuration. | Core retrieval path and selectable model path. Lane's project settings, DPA and zero-retention status are not yet evidenced. |
| Plus Five Five, Inc. d/b/a Resend | Website enquiries, demo confirmations and product transactional, authentication, invitation and security email. | Recipient and sender data, subject, message content, template variables and delivery metadata. | Primary processing is in the United States. Provider materials state deletion within 90 days after account termination, subject to legal retention; message and log settings for Lane require account verification. | Core email path. DPA acceptance, domain region, templates and retention must be verified. |
| Inngest Inc. | Durable and background product jobs when the production integration is configured. | Event payloads, job/user/document identifiers, job configuration and durable step results or execution history. | Cloud run and trace history is plan-dependent; a public contractual purge period and Lane's selected region are not established here. | Load-bearing for configured jobs. Obtain the signed DPA, sub-processor list and dashboard retention evidence. |
Feature- and configuration-dependent providers
| Provider / legal entity | Enabled feature | Data categories | Material limitation |
|---|---|---|---|
| Functional Software, Inc. d/b/a Sentry | Error, trace, profile and structured-log observability when a Sentry project is configured. | Errors, diagnostics, request or account identifiers and structured business fields included in application logs. | US or Germany storage depends on Lane's organisation configuration. Scrubbing exists but is not a guarantee that every arbitrary business field is removed; project region, retention, DPA and alerts require verification. |
| DeepL SE | Document translation. | Rendered document HTML, target language and translation options. | Confidential/personal-data processing requires the paid service and an applicable DPA. DeepL no longer represents all processing as Europe-only. Lane's paid tier and account terms must be confirmed. |
| Linkup Technologies SAS | User-enabled web search. | Search query, depth, output type and returned web-search content. | Default query processing can occur across multiple global regions. Zero retention is not enabled by default; Enterprise configuration and an executed DPA are required for narrower commitments. |
Customer-authorised connectors and inactive paths
Google Workspace/Drive and Microsoft 365/Graph/SharePoint are customer-authorised source systems. Their exact contracting entity, tenant region, source-system retention and access terms are generally controlled by the Customer's own tenant agreement. They are not automatically Lane-appointed Sub-processors. When a Customer directs Lane to copy or index connected content, the resulting Lane copy is processed by the applicable Lane providers listed above and must be deleted under the Customer's Lane agreement.
Lane source contains an inert Stripe integration that requires a secret key before it can operate. Stripe is not listed as an active Sub-processor in this version. If billing processing is enabled, the Order Form and this inventory must first identify Stripe's applicable EEA entities, processor/controller roles, data, retention and transfer treatment.
Transfers, training and retention
Lane does not make an EU-only, Frankfurt-only or single-region commitment. Where personal data is transferred outside the EEA, the applicable agreement must record the legal transfer mechanism, such as an adequacy decision or completed Standard Contractual Clauses, together with any required supplementary assessment.
No-training and zero retention are separate controls. Anthropic and OpenAI publish that commercial API data is not used for model training by default, subject to account opt-in, feedback and policy exceptions. Neither statement proves that Lane has an approved zero-retention configuration. Provider and Lane retention periods, logs, caches, queues, support access and backup tails must be stated in the completed processing specification.
Changes
New Sub-processors and material changes are handled under section 10 of the DPA. Lane will use the notice channel and objection period stated in the Order Form. A later update to this page does not amend a previously executed Agreement unless the Agreement expressly provides otherwise.
Notices may be sent using the contract contact in the Order Form or by post to Rwk Group Holding AB, Törnrosvägen 74A, 181 61 Lidingö, Sweden.
