Legal
Subprocessors
Last updated: July 25, 2026
This register lists the providers that may process Customer Personal Data on our behalf. It is referenced by section 5 of the Data Processing Terms, where the customer gives a general authorization to engage subprocessors.
Current subprocessors
| Provider | Role | Data involved | Location |
|---|---|---|---|
| SupabaseIn use | Managed database, authentication and file storage | All customer personal data held in the service | EU North (Stockholm) |
| RenderIn use | Hosting for the screening and compliance API | Screening queries and payment messages in transit | EU Central (Frankfurt) |
| VercelIn use | Hosting for the web application and cabinet | Data submitted through the web interface | EU Central (Frankfurt, fra1) |
| CloudflareIn use | DNS, content delivery and network protection | Traffic in transit; no durable storage of records | Global edge network |
| AnthropicIn use | Model provider for the built-in AI assistant | Content a user submits to the assistant | United States |
| OpenAIApproved, not in use | Model provider for the built-in AI assistant, as an approved alternative | Content a user submits to the assistant, if the platform selects this provider | United States |
| ResendIn use | Transactional and notification email delivery | Recipient address and message content | EU West (Ireland, eu-west-1) |
| StripeIn use | Subscription billing and payment processing | Billing and payment details of the organization | United States and other jurisdictions |
The service itself runs in the European Union: the database, the screening API, the web application and email delivery are hosted in EU regions. Transfers outside the European Economic Area arise only for billing and the optional AI assistant, and rely on the safeguards described in section 5 of the Data Processing Terms. Where a location is still being confirmed, we publish it here once verified rather than state one we cannot evidence.
How a model provider becomes involved
There are three separate situations. When the built-in assistant runs on the platform's own key, we choose the model provider from those listed above and it acts as our subprocessor; the row marked in use is the one processing today, and any switch to an approved alternative follows the 30-day notice below. When an organization configures its own provider and API key, that provider processes on the customer's instructions under the customer's own agreement and is not our subprocessor. When a customer drives the platform from their own AI client over the API or the MCP connector, we send nothing to any model provider at all — that vendor is entirely the customer's.
Reference lookups that are not subprocessors
Resolving a bank identifier may query external reference services such as the GLEIF BIC-to-LEI directory, and a company lookup may query a public business register directly, for example the Polish KRS. What leaves the platform in those cases is an institution or company identifier, not personal data about a screened individual. A public register also acts for its own statutory purposes rather than on our instructions, which makes it a source rather than a subprocessor. Sanctions, watchlist and other official lists are downloaded by us from their publishers, and no customer data is sent to them at all.
Changes to this register
We update this page when a provider that processes Customer Personal Data is added or replaced, and we give at least 30 days' notice before the new provider starts processing. Notice is published here and sent by email to the owners of affected workspaces. An urgent replacement — after a security incident, a provider outage or the discontinuation of a service — is announced as soon as we reasonably can. Customers may object on reasonable data-protection grounds within the notice period; section 5 of the Data Processing Terms sets out what happens then.