Legal
Subprocessors
Last updated: August 22, 2026
This register lists the providers that may process Customer Personal Data on our behalf. It is referenced by section 5 of the Data Processing Terms, where the customer gives a general authorization to engage subprocessors.
Current subprocessors
| Provider | Role | Data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| SupabaseIn use | Managed database, authentication and file storage | All customer personal data held in the service | Stockholm project region; global provider operations | EU SCCs for restricted transfers |
| RenderIn use | Hosting for the screening and compliance API | Screening queries and payment messages in transit | Frankfurt deployment; United States/global provider operations | EU–US DPF where applicable; EU SCCs as fallback |
| VercelIn use | Hosting for the web application and cabinet | Data submitted through the web interface | Frankfurt deployment (fra1); United States/global provider operations | EU SCCs for restricted transfers |
| CloudflareIn use | DNS, content delivery, network protection and independent status-notification hosting | Network traffic; status-subscriber email address, language, notification preferences and delivery metadata | EU jurisdiction for the D1 subscription database; global edge network and provider operations | EU–US DPF where applicable; EU SCCs as fallback |
| AnthropicApproved, not in use | Model provider for the built-in AI assistant | Content a user submits to the assistant | United States/global provider operations | EU SCCs for restricted transfers if activated |
| OpenAIIn use | Model provider for the built-in AI assistant; used only when enabled for the relevant customer account | Content a user submits to the assistant | United States/global provider operations | EU SCCs for restricted transfers |
| ResendIn use | Transactional and notification email delivery | Recipient address and message content | Ireland sending region (eu-west-1); United States provider operations | EU–US DPF where applicable; EU SCCs as fallback |
| StripeIn use | Subscription billing and payment processing | Billing and payment details of the organization | EEA, United States and other jurisdictions; global payment network | Adequacy decision where applicable; EU SCCs as fallback |
The main database and configured application workloads are hosted in EU regions. Some processing may nevertheless occur outside the European Economic Area for global network delivery, support, operations, billing or the optional AI assistant. The table distinguishes the configured deployment region from other disclosed provider operations and states the transfer safeguard used where Chapter V GDPR applies.
How a model provider becomes involved
There are three separate situations. When the built-in assistant runs on the platform's own key, we choose the model provider from those listed above and it acts as our subprocessor; the row marked in use is the one processing today, and any switch to an approved alternative follows the 30-day notice below. When an organization configures its own provider and API key, that provider processes on the customer's instructions under the customer's own agreement and is not our subprocessor. When a customer drives the platform from their own AI client over the API or the MCP connector, we send nothing to any model provider at all — that vendor is entirely the customer's.
Reference lookups that are not subprocessors
Resolving a bank identifier may query external reference services such as the GLEIF BIC-to-LEI directory, and a company lookup may query a public business register directly, for example the Polish KRS. What leaves the platform in those cases is an institution or company identifier, not personal data about a screened individual. A public register also acts for its own statutory purposes rather than on our instructions, which makes it a source rather than a subprocessor. Sanctions, watchlist and other official lists are downloaded by us from their publishers, and no customer data is sent to them at all.
Changes to this register
We update this page when a provider that processes Customer Personal Data is added or replaced, and we give at least 30 days' notice before the new provider starts processing. Notice is published here and sent by email to the owners of affected workspaces. An urgent replacement — after a security incident, a provider outage or the discontinuation of a service — is announced as soon as we reasonably can. Customers may object on reasonable data-protection grounds within the notice period; section 5 of the Data Processing Terms sets out what happens then.