Subprocessors
The third parties that may process personal data on our behalf, what they do, and where they do it.
The first table applies to every customer. The second applies only where you enable the capability that uses it.
Core subprocessors
Engaged for every customer. All process data within the EU.
| Company | Purpose | Region |
|---|---|---|
| Amazon Web Services EMEA SARL | Cloud hosting, compute, file storage, backups | EU — Sweden (eu-north-1) |
| Amazon Web Services EMEA SARL | Transactional email delivery | EU — Ireland (eu-west-1) |
Customer-enabled services
These engage only where the corresponding capability is enabled for your system. Leave it disabled and the provider processes nothing.
The AI providers are the reason the transfers section of the Privacy page exists: they are US companies, and enabling an AI capability is the ordinary case in which data leaves the EU.
| Company | Purpose | Region |
|---|---|---|
| Anthropic PBC | AI model inference, where an AI capability is enabled | United States |
| OpenAI, L.L.C. | AI model inference and embeddings, where an AI capability is enabled | United States |
| Together Computer, Inc. | AI model inference, where an AI capability is enabled | United States |
| Twilio Inc. | SMS delivery, where SMS notifications are enabled | United States / EU |
| Stripe, Inc. | Card payment processing, where payments are enabled | United States / EU |
| Getswish AB | Swish payment processing, where Swish is enabled | EU — Sweden |
| Finansiell ID-Teknik BID AB | BankID electronic identification, where BankID login is enabled | EU — Sweden |
About this list
What counts as a subprocessor here?
A third party that processes personal data on our behalf in order to deliver the service to you. That is what both tables above list.
It does not include a service you connect your own system to — your accounting system, your CRM, your calendar, your document storage. When your system sends an invoice to your own accounting provider, that is your data going to your own vendor under your own agreement with them. We are not introducing a processor into that relationship; we are carrying out your instruction.
Can we integrate with our existing systems without adding subprocessors?
Yes. The platform integrates with a wide range of business systems — accounting, CRM, communication, identity, document storage, industry-specific services — and those connections run into accounts you already own.
Those integrations are configured per system. If you want to know precisely which external services your own system reaches, ask and you will get the specific list rather than this general one.
Will you notify us before adding a subprocessor?
Yes. Where a new subprocessor would process personal data for your system, we notify you in advance so you have the opportunity to object before it is engaged. That commitment is in the DPA rather than only on this page.
This page is updated when the list changes. It is the public record, and it is meant to be checkable without asking us.
What safeguards cover the non-EU providers?
Standard Contractual Clauses with each provider, together with that provider's own supplementary measures. Where your organisation cannot accept a transfer outside the EU, the capabilities that depend on those providers can be left disabled.
Want the list for your own system?
Which subprocessors are actually engaged depends on which capabilities you run. Ask and we will confirm the specific set.