Neobiz Subprocessors
Version: 2026-07-1
Neobiz engages the following subprocessors to provide the Service. Each is bound by data-protection terms substantially as protective as our DPA.
| Subprocessor | Service provided | Data processed | Processing region | DPA status |
|---|---|---|---|---|
| Microsoft Azure (host) | Cloud hosting / database / storage | All tenant + account data | Indonesia (primary) | Microsoft Online Services DPA |
| Anthropic | AI model inference (primary) | Prompt context for AI features (no member identifiers beyond what the feature requires) | Singapore (ap-southeast-1) |
Required pre-launch — zero-retention/no-training (checklist §4.1) |
| Microsoft Azure OpenAI | AI model inference (failover) | As above | Singapore / Indonesia per availability | Microsoft Online Services DPA (checklist §4.1) |
| Resend | Transactional + campaign email | Recipient email, message content, delivery events | per provider | Confirm DPA |
| Qiscus (BSP) | WhatsApp / SMS dispatch (default IDR) | Recipient phone, message content, delivery receipts | Indonesia / per provider | Confirm DPA |
| Twilio (BSP, alt) | WhatsApp / SMS dispatch | As above | per provider | Confirm DPA |
| Stripe | Subscription billing / payments | Billing contact, payment metadata | per provider | Stripe DPA |
| Firebase Cloud Messaging / APNs | Mobile push delivery | Device tokens, notification content | per provider | Confirm terms |
Notes. (1) iSeller payment rails (where used for member-facing commerce) operate under their own licensing/compliance (BI PJP/PJSP) — confirm whether they are a subprocessor or an independent controller for payment data. (2) Update this table whenever a BSP or AI provider is added or swapped, and give merchants notice per DPA §7.3.
