Last updated: 20 July 2026
This page lists the sub-processors CrowAgent currently engages to deliver the platform, in accordance with Article 28 of the UK GDPR and the EU GDPR. The list is part of our Data Processing Agreement and is updated here at least 30 days before any change takes effect. Customers may subscribe to updates at hello@crowagent.ai.
Each entry names the legal entity that contracts with us for UK and EU services, that entity’s registered address, a link to the provider’s own published Data Processing Agreement, and the mechanism relied on for any transfer outside the UK and EEA. Where a provider is described as certified under the EU-US Data Privacy Framework, that has been checked against the official register rather than taken from the provider’s own marketing.
Where a detail appears in italics as being confirmed, it is not published by the provider and we are establishing it from the signed contract or the relevant company register. We would rather show you the gap than a value we cannot stand behind, and we do not link to a Data Processing Agreement we have not verified. The presence of the sub-processor itself, and what it receives, is confirmed in every case.
| Sub-processor | Contracting entity | Registered address | Data Processing Agreement | Transfer mechanism |
|---|---|---|---|---|
| Supabase | Supabase, Inc, named in the Data Processing Addendum. Supabase's Terms of Service separately name SUPABASE PTE. LTD., a Singapore company. The contracting entity is being confirmed against our counter-signed DPA. | Being confirmed with the contracting entity. Supabase publishes 970 Toa Payoh North #07-04, Singapore 318992 in the DPA and 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 in the Terms. | Supabase DPA | Standard Contractual Clauses and the UK Addendum, per the DPA, which is governed by Irish law. Supabase is not certified under the EU-US Data Privacy Framework. |
| Railway | Railway Corporation. Railway publishes no separate EU or UK contracting entity. | 548 Market St PMB 68956, San Francisco, California 94104, USA | Railway DPA | Standard Contractual Clauses and the UK Addendum. Railway Corporation appears on the Data Privacy Framework register as active with re-certification under review, so we rely on the Clauses rather than the Framework. |
| Vercel | Vercel Inc., a Delaware corporation. Vercel publishes no separate EU or UK contracting entity. | 440 N Barranca Ave #4133, Covina, CA 91723, USA | Vercel DPA | Standard Contractual Clauses (2021) and the UK IDTA, per the DPA. Vercel Inc. Is separately certified under the EU-US Data Privacy Framework and its UK Extension. |
| Cloudflare | Cloudflare, Inc. Cloudflare publishes no separate EU or UK contracting entity for self-serve customers. | 101 Townsend Street, San Francisco, CA 94107, USA | Cloudflare Customer DPA | EU-US Data Privacy Framework, its UK Extension and the Swiss-US Framework, all active on the register, with Standard Contractual Clauses in the DPA. |
| Brevo | Sendinblue SAS, trading as Brevo. Registered with the Paris Trade and Companies Register under number 498 019 298 (VAT FR80498019298) | 9-17 rue Salneuve, 75017 Paris, France | Brevo DPA (Appendix 3 to the Terms of Use) | The contracting entity is established in France, so the core service involves no restricted transfer. Brevo's US affiliate is separately certified under the EU-US Data Privacy Framework. |
| Stripe | Stripe Payments Europe, Limited (Ireland). The entity Stripe's Services Agreement assigns to United Kingdom customers, with Stripe Payments UK, Ltd. As an additional party for regulated payment services only | Not published on Stripe's legal pages. Being confirmed from the Irish Companies Registration Office. | Stripe DPA | The contracting entity is established in Ireland; onward transfers run under Stripe's own Standard Contractual Clauses. Stripe, LLC (US) is certified under the EU-US Data Privacy Framework and its UK Extension. |
| Anthropic | Anthropic Ireland, Limited. Anthropic's Commercial Terms assign customers in the EEA, Switzerland and the UK to this entity, and customers elsewhere to Anthropic, PBC | Not published. Anthropic's DPA states the data importer's contact details are disclosed to the customer on request. Being confirmed. | Anthropic DPA | Standard Contractual Clauses (Modules Two and Three) and the UK IDTA, automatically incorporated into Anthropic's Commercial Terms. Anthropic is not certified under the EU-US Data Privacy Framework. |
| Google (Gemini API) | Google Cloud EMEA Limited. The entity Google's contracting-entity table assigns to EMEA customers for Gemini API paid services | 70 Sir John Rogerson's Quay, Dublin 2, Ireland | Google Data Processing Addendum (Google as processor) | The contracting entity is established in Ireland; onward transfers run under Google's Standard Contractual Clauses. Google LLC is certified under the EU-US Data Privacy Framework and its UK Extension. |
| Sentry | Functional Software, Inc. D/b/a Sentry. Sentry Software Netherlands B.V. Is the appointed EU representative but is not the contracting party. | 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA | Sentry DPA | Standard Contractual Clauses and the UK Addendum, naming the Irish Data Protection Commission as competent supervisory authority. Sentry is also certified under the EU-US Data Privacy Framework and its UK Extension, for non-HR data. |
| PostHog | PostHog, Inc. The entity that operates the EU Cloud specifically is being confirmed with PostHog. | 2261 Market St., #4008, San Francisco, CA 94114, USA | PostHog DPA | Standard Contractual Clauses. PostHog Inc is certified under the EU-US Data Privacy Framework and its UK Extension. |
| Upstash | Upstash, Inc., a Delaware corporation | Not published in Upstash's DPA, Terms or privacy policy. Being confirmed with Upstash. | Upstash DPA (PDF) | Standard Contractual Clauses and the UK IDTA. Upstash, Inc. Is also certified under the EU-US Data Privacy Framework and its UK Extension. |
| Tawk.to | tawk.to Inc., contracting on behalf of itself and its UK affiliate tawk.to Ltd. | 187 East Warm Springs Rd, SB298, Las Vegas, Nevada 89119, USA | Tawk.to DPA | Standard Contractual Clauses (Modules Two and Three) with the UK and Swiss addenda. Tawk.to, Inc. Is also certified under the EU-US Data Privacy Framework and its UK Extension. The DPA itself is governed by Nevada law. |
| Calendly | Calendly LLC. Its UK representative is The DPO Centre Ltd, 50 Liverpool Street, London EC2M 7PY. | 115 E Main St, Ste A1B, Buford, GA 30518, USA | Calendly DPA | EU-US Data Privacy Framework, its UK Extension and the Swiss-US Framework, for non-HR data, with Standard Contractual Clauses and the UK Addendum as fallback. |
| hCaptcha | Intuition Machines, Inc., a Delaware corporation (#6393793) | 1065 SW 8th St #704, Miami, FL 33130, USA | hCaptcha DPA (PDF) | Standard Contractual Clauses (Modules Two and Three). Intuition Machines Inc is also certified under the EU-US Data Privacy Framework and its UK Extension, for non-HR data. |
| Sub-processor | Purpose | Data processed | Where it is processed | Since |
|---|---|---|---|---|
| Supabase | Hosted Postgres database, authentication, object storage | All application data at rest. Account and profile records, organisation data, uploaded tender and evidence documents, generated report PDFs, VAT validation logs | AWS eu-west-1 (Ireland) | September 2025 |
| Railway | Backend API compute (FastAPI), background workers, PDF generation | All API request and response content in transit through compute, including document text submitted for analysis. No independent persistent store. | Google Cloud europe-west4 (Amsterdam, Netherlands), on all three services. Railway's own DPA states that its primary processing operations take place in the United States, so this is still treated as a transfer. | September 2025 |
| Vercel | Frontend hosting, Next.js route handlers and scheduled jobs | All request content handled by server-side routes, including form submissions and authenticated session data. Edge routing and caching metadata. | Function region iad1 (Washington DC, United States). Measured from the X-Vercel-Id response header on production, 2026-08-17. Requests from the UK are routed via the London edge (lhr1), which performs routing and caching only; server-side route handlers execute in the United States. Consistent with Vercel's DPA, which states its primary processing facilities are in the United States. | September 2025 |
| Cloudflare | DNS, DDoS protection, WAF, and Turnstile bot verification on public tools | Edge request metadata (IP address, URL, headers). Turnstile additionally receives the end-user IP address at challenge verification. | Global edge; no persistent storage of personal data. We do not currently subscribe to Cloudflare's Data Localization Suite. | September 2025 |
| Brevo | All transactional and lifecycle email delivery, and marketing contact lists | Recipient name and email address, full message content (which may include billing details, trial status, collections correspondence and links to reports), delivery and open events, and lifecycle list membership | France (OVH) and Belgium (Google Cloud), per Brevo's published infrastructure sub-processor list | March 2026 |
| Stripe | Billing, payments, VAT handling, invoice delivery, and Stripe Connect for customer payment collection | Billing contact, VAT ID, payment method tokens, invoice and subscription history | Stripe publishes that the majority of its service providers are located in the European Union, the United States and India. Stripe offers no EU-only residency commitment. | September 2025 |
| Anthropic | AI generation on customer-facing surfaces: buyer-side tender pre-reads and assistant intent classification. Also internal founders-portal reasoning. | The supplier's full tender or bid response text, which routinely contains named personnel, CVs, referees and subcontractors (tender pre-read); free-text assistant messages. | The processing region cannot be pinned on the Anthropic API. Anthropic publishes that it deletes inputs and outputs from its backend within 30 days, and its DPA restricts use of customer personal data to the agreed business purposes. | March 2026 |
| Google (Gemini API) | AI generation across CrowMark and the assistant surfaces. Bid narratives, tender and RFP extraction, and chat | Uploaded tender, RFP and evidence documents; the organisation's own answer library; free-text messages entered into the assistant and the public chatbot | The Gemini Developer API carries no residency guarantee: Google states data may be stored transiently or cached in any country where Google or its agents maintain facilities. | January 2026 |
| Sentry | Application error telemetry | Scrubbed stack traces and event metadata. Personally-identifying data is disabled at source, email is hashed, IP is nulled, and session replay is not enabled. | Sentry EU storage location (Frankfurt) | October 2025 |
| PostHog | Product analytics (consent-gated) | Page views, feature events, pseudonymous distinct ID, hashed email, plan and organisation ID. No event is sent without recorded consent. | PostHog EU Cloud: AWS eu-central-1 (Frankfurt) | October 2025 |
| Upstash | Redis rate-limit counters, asynchronous job queue, idempotency keys | Rate-limit counters keyed by user ID or IP hash, and queued job payloads for report, export and narrative jobs (organisation ID and job parameters), retained approximately 24 hours | AWS eu-west-1 (Ireland), single region | Being confirmed from billing records |
| Tawk.to | Live chat support widget on the marketing site and the dashboard | Free-text support conversation content, name and email address where supplied, IP address, and page context | Primarily the United States. Tawk.to's sub-processors span the US, Ireland and the Netherlands; no EU-residency option is offered. | Being confirmed from billing records |
| Calendly | Embedded meeting booking | Name, email address, meeting details, IP address | United States. No EU-residency option is published. | Being confirmed from billing records |
| hCaptcha | Bot verification on public free tools | Challenge token and end-user IP address | United States. HCaptcha publishes no sub-processor list; we have asked for one in writing. | Being confirmed from billing records |
Two AI providers are engaged as sub-processors, and both may receive customer content. Google’s Gemini models generate customer-facing output across CrowMark, including from documents you upload. Anthropic’s Claude models are used for buyer-side tender pre-reads and assistant intent classification, as well as for our internal founders portal. Content you submit to these surfaces (including uploaded tender documents and bid responses, which may contain personal data about your staff, referees and subcontractors) is transmitted to the relevant provider to produce the output you requested. Every call is recorded in an internal cost and audit ledger.
Neither provider trains its models on the content we send. Anthropic’s Data Processing Addendum limits use of customer personal data to the agreed business purposes, and Anthropic publishes that it deletes inputs and outputs from its backend within 30 days. Google’s paid Gemini terms state that Google does not use prompts or responses to improve its products, and Google applies those paid terms to all users in the United Kingdom, the EEA and Switzerland. Neither the Anthropic API nor the Gemini Developer API allows a processing region to be pinned, so both are treated as transfers and are covered by the mechanisms set out above.
These providers are engaged only when you connect your own account. We hold the access token and make the calls, so we disclose them here on the same footing as our other sub-processors. The underlying account, and your contract for it, are yours.
| Sub-processor | Contracting entity | Registered address | Data Processing Agreement | Transfer mechanism |
|---|---|---|---|---|
| Microsoft (Microsoft 365 / Graph) | Being confirmed from the contracting-entity section of Microsoft's current Data Protection Addendum. | Being confirmed with the contracting entity. | Microsoft Products and Services Data Protection Addendum | Microsoft Corporation is certified under the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Framework. |
| Google (Drive) | Google Cloud EMEA Limited, for customers in EMEA | 70 Sir John Rogerson's Quay, Dublin 2, Ireland | Cloud Data Processing Addendum | The contracting entity is established in Ireland; onward transfers run under Google's Standard Contractual Clauses. Google LLC is certified under the EU-US Data Privacy Framework and its UK Extension. |
| Sub-processor | Purpose | Data processed | Where it is processed | Since |
|---|---|---|---|---|
| Microsoft (Microsoft 365 / Graph) | Microsoft Teams notification delivery, where the customer authorises the connection | Tenant identifier, the connecting administrator's identity, the names of the teams and channels offered as a delivery target, and the notification messages we post | Determined by the customer's own Microsoft tenant configuration, including Microsoft's EU Data Boundary where the customer has it. | Being confirmed from billing records |
| Google (Drive) | Delivering exported documents to the customer's own Google Drive, where the customer authorises the connection | The connecting user's identity and email, and the exported files we create in their Drive | Determined by the customer's own Workspace configuration, including Google's Data Regions where the customer has it. | Being confirmed from billing records |
If you choose “Sign in with Google”, Google is not acting as our sub-processor. Google’s API Terms of Service apply the Google Controller-Controller Data Protection Terms to this arrangement, which makes Google an independent controller of the sign-in rather than a processor acting on our instructions. We receive your Google account identifier, name and email address; Google’s own privacy policy governs what Google does with the sign-in on its side. Google LLC is certified under the EU-US Data Privacy Framework and its UK Extension. This is stated here because Google sign-in was previously, and incorrectly, listed in the sub-processor table.
The services below are queried to retrieve public or statutory information. Each is an independent controller of its own register. Companies House states in terms that the registrar is not acting as a data processor when maintaining a public register. They are disclosed here for transparency under Article 30; they are not Article 28 sub-processors.
| Service | Controller | Purpose | What we send |
|---|---|---|---|
| Companies House | The registrar of companies, an executive agency of the Department for Business and Trade. An independent controller under the Companies Act 2006 | Company lookup and verification | A company number or search term entered by the user. No account data is disclosed. |
| European Commission: VIES | The European Commission, under Regulation (EU) 2018/1725. VIES queries the national VAT databases of the Member States, each an independent controller. | EU VAT number validation for billing | The VAT identification number being validated, which is personal data where it belongs to a sole trader or partnership. The returned trader name and address are logged against the account. UK VAT numbers are validated by format only and are never sent. |
| Find a Tender, Contracts Finder, Public Contracts Scotland, Sell2Wales, eTendersNI | The respective UK and devolved public procurement authorities | Public procurement notice ingest and opportunity matching | Search filters only (sector, CPV code, region, date). No personal data is sent. |
| Bank of England, ONS NOMIS, legislation.gov.uk, GOV.UK | The respective public bodies | Reference data. Base rate, local area statistics, regulatory monitoring | No personal data is sent. |
Some features send data to a service that you choose and control with your own credentials. For these, you are the controller of the onward transfer and we do not engage the provider as our sub-processor:
Where you connect your own Twilio, Vonage or MessageBird account, message content and recipient numbers go to that account under your contract with the provider.
Where you connect your own Creditsafe account, the company identifiers you check are sent under your contract with the provider.
Where you configure a webhook URL (for example an automation platform endpoint), the event payload is delivered to the destination you nominated.
We notify customers by in-app banner and email to the billing contact at least 30 days before adding a new sub-processor or moving an existing sub-processor to a new region. Customers may object on reasonable grounds; where an objection cannot be resolved, the Customer may terminate the affected services.
| Sub-processor | Former purpose | Stopped processing |
|---|---|---|
| Resend | Transactional email delivery | May 2026, replaced by Brevo |