Legal
Sub-processors
The companies that process data on our behalf so this product can run, what each of them does, and where.
- Effective
- 6 September 2026
- Last updated
- 6 September 2026
What this list is
A sub-processor is a company we use to run the product, which therefore handles some of the information you or your customers put into it. This page names all of them.
The list is held in the product's own source code beside the code that talks to each one, and a test refuses to build the application if a provider adapter is added anywhere in the product's provider folders without a row here. That is how this page stays true rather than how it gets remembered.
Changes to this list
If we add a sub-processor we update this page and tell account owners. Where a signed data processing addendum is in place, the notice period in that document is the one that applies.
The list
| Company | What they do | What reaches them | Where | Status | Their terms |
|---|---|---|---|---|---|
| Microsoft Azure | Runs the application and holds its data. App Service runs the web application, Azure SQL Database holds every workspace's records, Key Vault holds the application's secrets and a storage account holds the key ring that protects sign-in cookies. | Everything stored in the product: account details, workspace records, the AI usage ledger and the application's own diagnostic records. | United States. The application runs in West US 2; the database and the key vault are in Central US. | In use | Data terms |
| Azure Communication Services (Microsoft) | Sends the product's own mail: the address confirmation, the password reset and the other messages the service has to send you to work. | The recipient address, the subject and the body of each message, and the delivery result. Addresses that hard bounce are held by the service for a limited period so it does not keep mailing them. | United States. The resource's data location is set to the United States, which is where message content is processed. | In use | Data terms |
| Anthropic | Answers the product's AI calls: prospect research, draft outreach, record summaries and the dashboard's written insights. | The prompt sent for each call, which carries the records you asked the feature to work on, and the response it returns. Under this provider's commercial terms your content is not used to train their models. | United States. | In use | Data termsTheir own sub-processors |
| OpenAI | A second AI provider, built into the product and switched off. No request is routed to it while that provider is switched off, which is how it ships. | Nothing today. Were an operator to enable it, the same prompt content the AI row above describes. | United States. | Built in, switched off | Data terms |
| Stripe | Takes payment for plans and for prepaid AI credit, and holds the subscription record behind your billing page. | Your billing email address, the plan and seat count you bought, and the payment result. Card details are entered on this party's own checkout page and never reach this product. | United States, and this party's own global infrastructure. | In use | Data terms |
| OpenFreeMap | Supplies the street-level basemap shown underneath your companies on the map page, where the interactive map is switched on for the service you are using. This one works differently from every other company on this page: our servers never call it, your own browser fetches the map imagery from it directly. | Which map tiles your browser asks for, which is the part of the world you are looking at and how closely. When the map first opens, that is the wide region your own records sit in, because it opens fitted around them - or around the one company a link named, at that same minimum width, when you came from a link to a single company; after that it is wherever you have moved to. Either opening is a region rather than a street. It also receives your internet address, which any site your browser fetches from receives. Nothing about your workspace is sent: no company, no contact, no address, no note and no marker. This party states that it needs no account or key, sets no cookie, and keeps no internet addresses in its regular server logs. | The service is operated from Hungary, in the European Union. It does not publish where its servers are. | Only where that feature is on | Data terms |
| Microsoft Graph (your own mailbox) | Sends your outreach from your own mailbox, when you connect one. We appoint nobody here: the mailbox is yours, the terms covering it are the ones you already have with your mail provider, and disconnecting it in the product ends the access. | The messages you send through the product, and the access token the connection issues. The token is encrypted before it is stored. | Wherever your own mail tenant is hosted, which is your choice rather than ours. | Only if you connect it | Data terms |