Legal

Subprocessors

Last updated: July 25, 2026

This register lists the providers that may process Customer Personal Data on our behalf. It is referenced by section 5 of the Data Processing Terms, where the customer gives a general authorization to engage subprocessors.

Current subprocessors

ProviderRoleData involvedLocation
SupabaseIn useManaged database, authentication and file storageAll customer personal data held in the serviceEU North (Stockholm)
RenderIn useHosting for the screening and compliance APIScreening queries and payment messages in transitEU Central (Frankfurt)
VercelIn useHosting for the web application and cabinetData submitted through the web interfaceEU Central (Frankfurt, fra1)
CloudflareIn useDNS, content delivery and network protectionTraffic in transit; no durable storage of recordsGlobal edge network
AnthropicIn useModel provider for the built-in AI assistantContent a user submits to the assistantUnited States
OpenAIApproved, not in useModel provider for the built-in AI assistant, as an approved alternativeContent a user submits to the assistant, if the platform selects this providerUnited States
ResendIn useTransactional and notification email deliveryRecipient address and message contentEU West (Ireland, eu-west-1)
StripeIn useSubscription billing and payment processingBilling and payment details of the organizationUnited States and other jurisdictions

The service itself runs in the European Union: the database, the screening API, the web application and email delivery are hosted in EU regions. Transfers outside the European Economic Area arise only for billing and the optional AI assistant, and rely on the safeguards described in section 5 of the Data Processing Terms. Where a location is still being confirmed, we publish it here once verified rather than state one we cannot evidence.

How a model provider becomes involved

There are three separate situations. When the built-in assistant runs on the platform's own key, we choose the model provider from those listed above and it acts as our subprocessor; the row marked in use is the one processing today, and any switch to an approved alternative follows the 30-day notice below. When an organization configures its own provider and API key, that provider processes on the customer's instructions under the customer's own agreement and is not our subprocessor. When a customer drives the platform from their own AI client over the API or the MCP connector, we send nothing to any model provider at all — that vendor is entirely the customer's.

Reference lookups that are not subprocessors

Resolving a bank identifier may query external reference services such as the GLEIF BIC-to-LEI directory, and a company lookup may query a public business register directly, for example the Polish KRS. What leaves the platform in those cases is an institution or company identifier, not personal data about a screened individual. A public register also acts for its own statutory purposes rather than on our instructions, which makes it a source rather than a subprocessor. Sanctions, watchlist and other official lists are downloaded by us from their publishers, and no customer data is sent to them at all.

Changes to this register

We update this page when a provider that processes Customer Personal Data is added or replaced, and we give at least 30 days' notice before the new provider starts processing. Notice is published here and sent by email to the owners of affected workspaces. An urgent replacement — after a security incident, a provider outage or the discontinuation of a service — is announced as soon as we reasonably can. Customers may object on reasonable data-protection grounds within the notice period; section 5 of the Data Processing Terms sets out what happens then.