Effective 2 September 2026 · Version 1.1 ·
Sub-processors & Third-Party Data Source Categories
GARUNA GROUP — Enhanced Due Diligence ("EDD") — Early Access (invite-only pilot)
| Field | Value |
|---|---|
| Provider | Garuna Group ("Garuna", "Provider", "we") — Garuna Inc., a corporation incorporated under the laws of the Province of Ontario and operating as "Garuna Group", with registered office at 10 Thornmount Drive, Toronto, Ontario M1B 3J4, Canada |
| Governing law | Province of Ontario and the federal laws of Canada applicable therein |
| Effective date / Last updated | 2026-09-02 |
| Version | 1.1 |
| Privacy / data-protection contact | [email protected] |
This document is the published Sub-processor & Third-Party Data Source List referenced by, and forming part of, the EDD Privacy Policy and Data Processing Addendum (DPA), which are in turn incorporated into the EDD Terms of Service / Master Services Agreement (the "Terms"). Capitalised terms have the meanings given in the Terms.
This list reflects the actual data flows of the Service as implemented, described by category of provider and source. For sound commercial reasons — the specific composition and routing of the Service's intelligence sources is proprietary and confidential — this list identifies each recipient by its function, category, and the jurisdiction to which data is transferred, rather than by naming the individual vendor, product, or API. This is consistent with prevailing practice for intelligence, due-diligence, and screening services, and is sufficient for you, as controller, to assess the categories of recipients and cross-border transfers involved. The identities of specific sub-processors are available to a contracted Client on written request and subject to confidentiality, where reasonably required for the Client's own data-protection compliance.
How to read this list
The Service engages three categories of third party, which carry different legal status. They are kept separate below because that distinction matters for your data-protection obligations:
- (A) Sub-processors — third parties that process Personal Data on Garuna's behalf in delivering the Service (they receive a Subject name, query terms, target URLs, identifiers, and/or collected source text). These are sub-processors under Article 28 GDPR / UK GDPR and "service providers" for PIPEDA purposes, and are the parties for which the DPA's sub-processor change-notice and objection rights apply.
- (B) On-device / self-hosted components — components that run on the Garuna server (localhost) or on-device and that do not transfer Personal Data to any external third party.
- (C) Public-record, reference & open-source sources — third-party public-record, registry, reputation, and open-source services that the Service queries with Subject identifiers. Each acts as an independent controller of its own data. They are not Garuna's sub-processors; they are listed here, by category, for transparency and cross-border-transfer disclosure.
Cross-border note (applies throughout). Garuna operates from Ontario, Canada, and the Personal Data it processes is generally of Canadian origin or routed through Canada. Accordingly, any transfer to a recipient outside Canada — including any recipient in the United States — is a cross-border transfer. Only categories expressly marked "domestic — no cross-border transfer" keep the data within Canada.
The configuration is deployment-dependent. Not every component listed is engaged in every Sweep. Several categories require an API key to be configured, several can be disabled, the cloud-AI category applies in Deep Mode only, the authenticated-lookup and Investigation-Session categories operate only after an Authorised User signs in themselves, and an Investigation Session is engaged only when an Authorised User initiates one. In a fully-local configuration (self-hosted search + on-device models — Group B), a Sweep can run with minimal third-party transfer. Cross-border transfer occurs only when the relevant categories in Groups A and C are used. This list reflects a maximal configuration; a given deployment may use only a subset.
Group A — Sub-processor categories (process Personal Data for Garuna)
These categories of third party receive a Subject name, query terms, target URLs, identifiers, and/or collected source text in order to deliver the Service.
| Provider category | Purpose | Data received | Location / transfer | Optional? |
|---|---|---|---|---|
| Web-search providers | General open-web search across several independent search backends (resilient fan-out) | Subject name + query terms | US / EU / foreign — cross-border | Configurable; several are key-free, some keyed |
| Commercial web-retrieval / proxy provider | Fallback retrieval of public pages and search results that block direct server-to-server requests (e.g. anti-bot 403 pages, certain registry pages) | Query terms; target public-page URLs to retrieve (which may embed the Subject name) | Foreign — cross-border | Configurable; keyed |
| Cloud AI synthesis & verification provider | Higher-tier AI synthesis and independent claim verification of collected findings | Collected source text + Subject name | Foreign (US) — cross-border | Deep Mode only — off in default / fast mode (synthesis stays on-device, Group B) |
Group B — On-device / self-hosted (no external transfer)
These components run on the Garuna server (localhost) or on-device. They do not transfer Personal Data to any external third party. A Sweep configured to use only these components runs with minimal third-party transfer.
| Component category | Purpose | Data handled | Location | External transfer? |
|---|---|---|---|---|
| Self-hosted private meta-search | Default open-web search layer; anonymises and fans out queries to public engines without exposing the Service's IP or any account | Subject name + query terms | Garuna server (localhost) | None — self-hosted, no third party receives an identifiable session |
| On-device AI synthesis | Default / fast-mode AI synthesis of collected findings | Collected source text + Subject name | Garuna server (on-device) | None — on-device inference |
| On-device identity adjudication | Assist-only adjudication of ambiguous same-name clusters | Ambiguous same-name cluster data | Garuna server (on-device) | None — on-device inference |
Group C — Public-record, reference & open-source source categories (independent controllers)
These are categories of third-party public-record, registry, reputation, and open-source services that the Service queries with Subject identifiers to collect publicly available information. Each is an independent controller of its own data and is not a sub-processor of Garuna. They are listed by category for transparency and cross-border-transfer disclosure. Where marked "keyed", the category is engaged only if an API key is configured.
| Source category | Data sent (Subject identifiers) | Location / transfer | Configuration |
|---|---|---|---|
| Government sanctions & watchlists (Canada / UN / UK / US) | None sent per query — the consolidated public lists are downloaded in bulk and cached on the Garuna server (~24h); screening is performed locally by fuzzy match. Public reference data, not Subject-specific. | Bulk download (no per-Subject query) | Key-free; default |
| Aggregated international sanctions / PEP reference | Subject name | Foreign — cross-border | Keyed-optional |
| Court, tribunal & case-law repositories — Canada | Subject name | Canada — domestic; no cross-border transfer | Default search; keyed enrichment optional |
| Court, tribunal & case-law repositories — United States | Subject name | US — cross-border | Default |
| Securities & corporate-disclosure filings — United States | Subject name | US — cross-border | Default |
| Corporate / business registries & legal-entity identifiers — UK / Australia / global | Entity name / officers | Foreign / UK / AU — cross-border | Some default, some keyed-optional |
| Patent & trademark registries — US / international | Subject name (owner / applicant of record); a top registry page may be retrieved through the commercial web-retrieval provider (Group A) | US / foreign — cross-border | Key-free; default |
| Structured public knowledge graph (nonprofit reference) | Subject name | Foreign — cross-border | Default |
| Global news & media archives | Subject name / keyword | US / foreign — cross-border | Default |
| Web archive & historical snapshots (nonprofit) | URLs / domain | US — cross-border | Default |
| Domain registration & certificate-transparency records | Domain (no personal identifiers) | Foreign — cross-border | Default |
| Cross-border investigative research database (nonprofit) | Subject name | Foreign — cross-border | Keyed-optional |
| Email / identity reputation | Email (sent as a one-way hash where the service supports it) | US / foreign — cross-border | Default / keyed-optional |
| Data-breach & credential-exposure intelligence | Email and/or phone and/or username | Foreign — cross-border | Mix of default and keyed-optional |
| Public code / developer-platform presence | Username / Subject name | US — cross-border | Default |
| Account-existence discovery tooling | See the Account-discovery note below | Many foreign sites — cross-border | Default (each tool gated on its dependency) |
| Extended social-presence checks (commercial marketplace providers) | Username / identifier | Foreign — cross-border | Keyed-optional |
| Mainstream social platforms (via an Investigation Session) | Reads the Subject's public profile / engagement data through the analyst's own logged-in session — see the Authenticated read surfaces note below | US-based / US-foreign — cross-border | Optional; analyst-initiated |
| Major email/account provider (via an authenticated lookup) | Email — see the Authenticated read surfaces note below | US — cross-border | Optional; analyst-authenticated; ships dark until enabled |
Account-existence discovery tooling
This category uses open-source techniques that query many third-party websites directly to detect whether accounts associated with a Subject identifier exist. Each queried site is an independent controller of its own data. The sites queried are numerous, foreign, and tool-determined; cross-border transfer to those sites occurs when this tooling is used. Depending on the identifier supplied, the Subject email, phone number, and/or username is sent to the relevant target sites to detect account existence. All checks in this category are key-free and enabled by default, but each is gated on its software dependency being installed; where a tool is absent the Service records a gap rather than transferring data.
Authenticated read surfaces (analyst-authenticated; sign-in by the Authorised User)
Two parts of the Service read data through a session that the Authorised User establishes by signing in themselves to their own or a duly authorised account. The Service never cracks, guesses, or bypasses authentication.
(1) Investigation Sessions — mainstream social platforms. When an Authorised User connects an Investigation Session on a supported platform (mainstream social networks such as X, Instagram, Reddit, LinkedIn, and Facebook), the captured browser authentication state may be reused by the Service to (a) read a Subject's public engagement-graph data on platforms that expose it, and (b) retrieve a Subject's publicly displayed profile image during identity disambiguation. The relevant platform acts as an independent controller; transfer is cross-border. Some platforms — notably LinkedIn and the Meta properties (Instagram, Facebook) — prohibit automated or authenticated programmatic access and the use of investigation / "burner" accounts in their Terms of Service; use may breach those terms, and the Authorised User is solely responsible for ensuring any account used is their own or duly authorised and for compliance with the relevant platform's Terms of Service. The Session State (authentication cookies) is held in process memory only, is never written to disk, is never logged (only a cookie count is recorded), and is never serialised into a Report or export. Optional; analyst-initiated.
(2) Authenticated account lookup — major email/account provider. An optional capability sends the Subject's email to a major email/account provider to resolve the public account surface associated with it (e.g. public profile name and photo, associated services). It runs only after the Authorised User has signed into an account of that provider themselves and ships dark until then. The provider is an independent controller; transfer is cross-border. Unlike Investigation Session cookies, this provider's credentials are persisted on disk in the analyst's local profile (a named exception to the in-memory-only posture); the Privacy Policy and DPA security measures carve this out expressly. This is the analyst's own credential, not Subject data. Use of an investigation / "burner" account may breach the provider's Terms of Service, and the Authorised User is solely responsible for using only their own or a duly authorised account.
On-disk persistence (clarification)
The Service keeps no standing, searchable database of Subjects; completed Reports are retained for a limited period (currently thirty days) and then deleted, monitoring entries hold the identifiers needed to re-run a search, and paid record-check inputs are held until fulfilment or cancellation (see the Privacy Policy). Two further on-disk artefacts exist and are disclosed here for accuracy:
- Public sanctions/watchlist reference lists — public reference data, not Subject-specific, cached ~24h for local screening.
- Authenticated-lookup credentials — the analyst's own authenticated session for the major email/account provider (Authenticated read surfaces, item 2), persisted on disk in the analyst's local profile when that capability is enabled. This is the analyst's own credential, not Subject data, and is never serialised into a Report or export.
No Subject-specific data is written to disk. Subject queries are not logged; web-search results are held in process memory only and discarded when the Sweep ends; on-server tools' temporary working files are deleted immediately after parsing; and Investigation Session State is held in process memory only.
Changes to this list & how to receive notice
This is a living list and may change as Garuna adds, removes, or replaces a sub-processor or source category. It is maintained to match the Service as implemented. Material changes to the Group A sub-processor categories are notified to Clients in accordance with the sub-processor change-notice and objection provisions of the DPA.
To receive advance notice of changes to this list, or to raise an objection to a new sub-processor, contact [email protected] and ask to be added to the sub-processor change-notification list. Garuna gives Clients at least thirty (30) days' advance notice of the addition or replacement of a Group A sub-processor category by email to the Client's designated administrative / privacy contact and/or by updating this page, and the Client may object on reasonable data-protection grounds as set out in the DPA. Where a Client reasonably requires the identity of a specific sub-processor for its own compliance, Garuna will provide it on written request under confidentiality.
This Sub-processor & Third-Party Data Source List is version 1.1, effective 2026-09-02, and forms part of the EDD Privacy Policy and DPA under the EDD Terms of Service / Master Services Agreement. Governing law: Province of Ontario and the federal laws of Canada applicable therein.