Legal

Subprocessors

Last updated: August 22, 2026

This register lists the providers that may process Customer Personal Data on our behalf. It is referenced by section 5 of the Data Processing Terms, where the customer gives a general authorization to engage subprocessors.

Current subprocessors

ProviderRoleData involvedLocationTransfer safeguard
SupabaseIn useManaged database, authentication and file storageAll customer personal data held in the serviceStockholm project region; global provider operationsEU SCCs for restricted transfers
RenderIn useHosting for the screening and compliance APIScreening queries and payment messages in transitFrankfurt deployment; United States/global provider operationsEU–US DPF where applicable; EU SCCs as fallback
VercelIn useHosting for the web application and cabinetData submitted through the web interfaceFrankfurt deployment (fra1); United States/global provider operationsEU SCCs for restricted transfers
CloudflareIn useDNS, content delivery, network protection and independent status-notification hostingNetwork traffic; status-subscriber email address, language, notification preferences and delivery metadataEU jurisdiction for the D1 subscription database; global edge network and provider operationsEU–US DPF where applicable; EU SCCs as fallback
AnthropicApproved, not in useModel provider for the built-in AI assistantContent a user submits to the assistantUnited States/global provider operationsEU SCCs for restricted transfers if activated
OpenAIIn useModel provider for the built-in AI assistant; used only when enabled for the relevant customer accountContent a user submits to the assistantUnited States/global provider operationsEU SCCs for restricted transfers
ResendIn useTransactional and notification email deliveryRecipient address and message contentIreland sending region (eu-west-1); United States provider operationsEU–US DPF where applicable; EU SCCs as fallback
StripeIn useSubscription billing and payment processingBilling and payment details of the organizationEEA, United States and other jurisdictions; global payment networkAdequacy decision where applicable; EU SCCs as fallback

The main database and configured application workloads are hosted in EU regions. Some processing may nevertheless occur outside the European Economic Area for global network delivery, support, operations, billing or the optional AI assistant. The table distinguishes the configured deployment region from other disclosed provider operations and states the transfer safeguard used where Chapter V GDPR applies.

How a model provider becomes involved

There are three separate situations. When the built-in assistant runs on the platform's own key, we choose the model provider from those listed above and it acts as our subprocessor; the row marked in use is the one processing today, and any switch to an approved alternative follows the 30-day notice below. When an organization configures its own provider and API key, that provider processes on the customer's instructions under the customer's own agreement and is not our subprocessor. When a customer drives the platform from their own AI client over the API or the MCP connector, we send nothing to any model provider at all — that vendor is entirely the customer's.

Reference lookups that are not subprocessors

Resolving a bank identifier may query external reference services such as the GLEIF BIC-to-LEI directory, and a company lookup may query a public business register directly, for example the Polish KRS. What leaves the platform in those cases is an institution or company identifier, not personal data about a screened individual. A public register also acts for its own statutory purposes rather than on our instructions, which makes it a source rather than a subprocessor. Sanctions, watchlist and other official lists are downloaded by us from their publishers, and no customer data is sent to them at all.

Changes to this register

We update this page when a provider that processes Customer Personal Data is added or replaced, and we give at least 30 days' notice before the new provider starts processing. Notice is published here and sent by email to the owners of affected workspaces. An urgent replacement — after a security incident, a provider outage or the discontinuation of a service — is announced as soon as we reasonably can. Customers may object on reasonable data-protection grounds within the notice period; section 5 of the Data Processing Terms sets out what happens then.