Last updated: 20 July 2026
This page lists the sub-processors CrowAgent currently engages to deliver the platform, in accordance with Article 28 of the UK GDPR and the EU GDPR. The list is part of our Data Processing Agreement and is updated here at least 30 days before any change takes effect. Customers may subscribe to updates at hello@crowagent.ai.
Each entry names the legal entity that contracts with us for UK and EU services, that entity’s registered address, a link to the provider’s own published Data Processing Agreement, and the mechanism relied on for any transfer outside the UK and EEA. Where a provider is described as certified under the EU-US Data Privacy Framework, that has been checked against the official register rather than taken from the provider’s own marketing.
Where a detail appears in italics as being confirmed, it is not published by the provider and we are establishing it from the signed contract or the relevant company register. We would rather show you the gap than a value we cannot stand behind, and we do not link to a Data Processing Agreement we have not verified. The presence of the sub-processor itself, and what it receives, is confirmed in every case.
| Sub-processor | Contracting entity | Registered address | Data Processing Agreement | Transfer mechanism |
|---|---|---|---|---|
| Supabase | Supabase, Inc, named in the Data Processing Addendum. Supabase's Terms of Service separately name SUPABASE PTE. LTD., a Singapore company. The contracting entity is being confirmed against our counter-signed DPA. | Being confirmed with the contracting entity. Supabase publishes 970 Toa Payoh North #07-04, Singapore 318992 in the DPA and 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 in the Terms. | Supabase DPA | Standard Contractual Clauses and the UK Addendum, per the DPA, which is governed by Irish law. Supabase is not certified under the EU-US Data Privacy Framework. |
| Railway | Railway Corporation. Railway publishes no separate EU or UK contracting entity. | 548 Market St PMB 68956, San Francisco, California 94104, USA | Railway DPA | Standard Contractual Clauses and the UK Addendum. Railway Corporation appears on the Data Privacy Framework register as active with re-certification under review, so we rely on the Clauses rather than the Framework. |
| Vercel | Vercel Inc., a Delaware corporation. Vercel publishes no separate EU or UK contracting entity. | 440 N Barranca Ave #4133, Covina, CA 91723, USA | Vercel DPA | Standard Contractual Clauses (2021) and the UK IDTA, per the DPA. Vercel Inc. is separately certified under the EU-US Data Privacy Framework and its UK Extension. |
| Cloudflare | Cloudflare, Inc. Cloudflare publishes no separate EU or UK contracting entity for self-serve customers. | 101 Townsend Street, San Francisco, CA 94107, USA | Cloudflare Customer DPA | EU-US Data Privacy Framework, its UK Extension and the Swiss-US Framework, all active on the register, with Standard Contractual Clauses in the DPA. |
| Brevo | Sendinblue SAS, trading as Brevo — registered with the Paris Trade and Companies Register under number 498 019 298 (VAT FR80498019298) | 9-17 rue Salneuve, 75017 Paris, France | Brevo DPA (Appendix 3 to the Terms of Use) | The contracting entity is established in France, so the core service involves no restricted transfer. Brevo's US affiliate is separately certified under the EU-US Data Privacy Framework. |
| Stripe | Stripe Payments Europe, Limited (Ireland) — the entity Stripe's Services Agreement assigns to United Kingdom customers, with Stripe Payments UK, Ltd. as an additional party for regulated payment services only | Not published on Stripe's legal pages. Being confirmed from the Irish Companies Registration Office. | Stripe DPA | The contracting entity is established in Ireland; onward transfers run under Stripe's own Standard Contractual Clauses. Stripe, LLC (US) is certified under the EU-US Data Privacy Framework and its UK Extension. |
| Anthropic | Anthropic Ireland, Limited — Anthropic's Commercial Terms assign customers in the EEA, Switzerland and the UK to this entity, and customers elsewhere to Anthropic, PBC | Not published. Anthropic's DPA states the data importer's contact details are disclosed to the customer on request. Being confirmed. | Anthropic DPA | Standard Contractual Clauses (Modules Two and Three) and the UK IDTA, automatically incorporated into Anthropic's Commercial Terms. Anthropic is not certified under the EU-US Data Privacy Framework. |
| Google (Gemini API) | Google Cloud EMEA Limited — the entity Google's contracting-entity table assigns to EMEA customers for Gemini API paid services | 70 Sir John Rogerson's Quay, Dublin 2, Ireland | Google Data Processing Addendum (Google as processor) | The contracting entity is established in Ireland; onward transfers run under Google's Standard Contractual Clauses. Google LLC is certified under the EU-US Data Privacy Framework and its UK Extension. |
| Sentry | Functional Software, Inc. d/b/a Sentry. Sentry Software Netherlands B.V. is the appointed EU representative but is not the contracting party. | 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA | Sentry DPA | Standard Contractual Clauses and the UK Addendum, naming the Irish Data Protection Commission as competent supervisory authority. Sentry is also certified under the EU-US Data Privacy Framework and its UK Extension, for non-HR data. |
| PostHog | PostHog, Inc. The entity that operates the EU Cloud specifically is being confirmed with PostHog. | 2261 Market St., #4008, San Francisco, CA 94114, USA | PostHog DPA | Standard Contractual Clauses. PostHog Inc is certified under the EU-US Data Privacy Framework and its UK Extension. |
| Upstash | Upstash, Inc., a Delaware corporation | Not published in Upstash's DPA, Terms or privacy policy. Being confirmed with Upstash. | Upstash DPA (PDF) | Standard Contractual Clauses and the UK IDTA. Upstash, Inc. is also certified under the EU-US Data Privacy Framework and its UK Extension. |
| Tawk.to | tawk.to Inc., contracting on behalf of itself and its UK affiliate tawk.to Ltd. | 187 East Warm Springs Rd, SB298, Las Vegas, Nevada 89119, USA | Tawk.to DPA | Standard Contractual Clauses (Modules Two and Three) with the UK and Swiss addenda. tawk.to, Inc. is also certified under the EU-US Data Privacy Framework and its UK Extension. The DPA itself is governed by Nevada law. |
| Calendly | Calendly LLC. Its UK representative is The DPO Centre Ltd, 50 Liverpool Street, London EC2M 7PY. | 115 E Main St, Ste A1B, Buford, GA 30518, USA | Calendly DPA | EU-US Data Privacy Framework, its UK Extension and the Swiss-US Framework, for non-HR data, with Standard Contractual Clauses and the UK Addendum as fallback. |
| hCaptcha | Intuition Machines, Inc., a Delaware corporation (#6393793) | 1065 SW 8th St #704, Miami, FL 33130, USA | hCaptcha DPA (PDF) | Standard Contractual Clauses (Modules Two and Three). Intuition Machines Inc is also certified under the EU-US Data Privacy Framework and its UK Extension, for non-HR data. |
| Sub-processor | Purpose | Data processed | Where it is processed | Since |
|---|---|---|---|---|
| Supabase | Hosted Postgres database, authentication, object storage | All application data at rest — account and profile records, organisation data, uploaded tender and evidence documents, generated report PDFs, VAT validation logs | AWS eu-west-1 (Ireland) | September 2025 |
| Railway | Backend API compute (FastAPI), background workers, PDF generation | All API request and response content in transit through compute, including document text submitted for analysis. No independent persistent store. | Google Cloud europe-west4 (Amsterdam, Netherlands), on all three services. Railway's own DPA states that its primary processing operations take place in the United States, so this is still treated as a transfer. | September 2025 |
| Vercel | Frontend hosting, Next.js route handlers and scheduled jobs | All request content handled by server-side routes, including form submissions and authenticated session data. Edge routing and caching metadata. | Global edge. The function region for our projects is being confirmed; Vercel's DPA states its primary processing facilities are in the United States. | September 2025 |
| Cloudflare | DNS, DDoS protection, WAF, and Turnstile bot verification on public tools | Edge request metadata (IP address, URL, headers). Turnstile additionally receives the end-user IP address at challenge verification. | Global edge; no persistent storage of personal data. We do not currently subscribe to Cloudflare's Data Localization Suite. | September 2025 |
| Brevo | All transactional and lifecycle email delivery, and marketing contact lists | Recipient name and email address, full message content (which may include billing details, trial status, collections correspondence and links to reports), delivery and open events, and lifecycle list membership | France (OVH) and Belgium (Google Cloud), per Brevo's published infrastructure sub-processor list | March 2026 |
| Stripe | Billing, payments, VAT handling, invoice delivery, and Stripe Connect for customer payment collection | Billing contact, VAT ID, payment method tokens, invoice and subscription history | Stripe publishes that the majority of its service providers are located in the European Union, the United States and India. Stripe offers no EU-only residency commitment. | September 2025 |
| Anthropic | AI generation on customer-facing surfaces: Cyber Essentials answer suggestions, buyer-side tender pre-reads, receivables scoring and assistant intent classification. Also internal founders-portal reasoning. | Organisation profile and IT-estate description (Cyber Essentials); the supplier's full tender or bid response text, which routinely contains named personnel, CVs, referees and subcontractors (tender pre-read); receivables context. | The processing region cannot be pinned on the Anthropic API. Anthropic publishes that it deletes inputs and outputs from its backend within 30 days, and its DPA restricts use of customer personal data to the agreed business purposes. | March 2026 |
| Google (Gemini API) | AI generation across CrowMark, CrowCyber, CrowCash, CrowESG and the assistant surfaces — bid narratives, RFP extraction, remediation and policy drafting, collections letters, ESG autofill, and chat | Uploaded tender, RFP, evidence and ESG documents; the organisation's own answer library; debtor-facing correspondence drafts; free-text messages entered into the assistant and the public chatbot | The Gemini Developer API carries no residency guarantee: Google states data may be stored transiently or cached in any country where Google or its agents maintain facilities. | January 2026 |
| Sentry | Application error telemetry | Scrubbed stack traces and event metadata. Personally-identifying data is disabled at source, email is hashed, IP is nulled, and session replay is not enabled. | Sentry EU storage location (Frankfurt) | October 2025 |
| PostHog | Product analytics (consent-gated) | Page views, feature events, pseudonymous distinct ID, hashed email, plan and organisation ID. No event is sent without recorded consent. | PostHog EU Cloud — AWS eu-central-1 (Frankfurt) | October 2025 |
| Upstash | Redis rate-limit counters, asynchronous job queue, idempotency keys | Rate-limit counters keyed by user ID or IP hash, and queued job payloads for report, export and narrative jobs (organisation ID and job parameters), retained approximately 24 hours | AWS eu-west-1 (Ireland), single region | Being confirmed from billing records |
| Tawk.to | Live chat support widget on the marketing site and the dashboard | Free-text support conversation content, name and email address where supplied, IP address, and page context | Primarily the United States. Tawk.to's sub-processors span the US, Ireland and the Netherlands; no EU-residency option is offered. | Being confirmed from billing records |
| Calendly | Embedded meeting booking | Name, email address, meeting details, IP address | United States. No EU-residency option is published. | Being confirmed from billing records |
| hCaptcha | Bot verification on public free tools | Challenge token and end-user IP address | United States. hCaptcha publishes no sub-processor list; we have asked for one in writing. | Being confirmed from billing records |
Two AI providers are engaged as sub-processors, and both may receive customer content. Google’s Gemini models generate customer-facing output across CrowMark, CrowCyber, CrowCash and CrowESG, including from documents you upload. Anthropic’s Claude models are used for Cyber Essentials answer suggestions, buyer-side tender pre-reads, receivables scoring and assistant intent classification, as well as for our internal founders portal. Content you submit to these surfaces — including uploaded tender documents and bid responses, which may contain personal data about your staff, referees and subcontractors — is transmitted to the relevant provider to produce the output you requested. Every call is recorded in an internal cost and audit ledger.
Neither provider trains its models on the content we send. Anthropic’s Data Processing Addendum limits use of customer personal data to the agreed business purposes, and Anthropic publishes that it deletes inputs and outputs from its backend within 30 days. Google’s paid Gemini terms state that Google does not use prompts or responses to improve its products, and Google applies those paid terms to all users in the United Kingdom, the EEA and Switzerland. Neither the Anthropic API nor the Gemini Developer API allows a processing region to be pinned, so both are treated as transfers and are covered by the mechanisms set out above.
These providers are engaged only when you connect your own account. We hold the access token and make the calls, so we disclose them here on the same footing as our other sub-processors — but the underlying account, and your contract for it, are yours.
| Sub-processor | Contracting entity | Registered address | Data Processing Agreement | Transfer mechanism |
|---|---|---|---|---|
| Xero | Xero (UK) Limited, company number 06071722. Xero operates no EU entity: customers in the EU contract with Xero (NZ) Limited. | 5th Floor, 100 Avebury Boulevard, Milton Keynes MK9 1FH, United Kingdom | Xero Data Processing Addendum | Standard Contractual Clauses, the UK Addendum, and the New Zealand adequacy decision, per the Xero DPA. Xero does not appear on the Data Privacy Framework register. |
| Intuit (QuickBooks Online) | Being confirmed from Intuit's own UK legal notice. Intuit's published position appears to be that outside payroll it acts as an independent controller rather than our processor, which would change how this entry is classified. | Being confirmed from Intuit's own UK legal notice. | Being confirmed — no verified DPA URL | Intuit is certified under the EU-US Data Privacy Framework and its UK Extension. The contractual route for QuickBooks Online specifically is being confirmed. |
| Sage | Sage (UK) Ltd, company number 01045967. Sage's DPA defines the processor as whichever Sage entity signs the agreement, so the exact entity is being confirmed against our signed contract. | C23 – 5 & 6 Cobalt Park Way, Cobalt Park, Newcastle upon Tyne NE28 9EJ, United Kingdom | Sage Personal Data Processing Agreement | The UK and Irish Sage entities are established in the UK and the EEA respectively. Sage's Data Privacy Framework position is being re-verified against the official register. |
| Microsoft (Microsoft 365 / Graph) | Being confirmed from the contracting-entity section of Microsoft's current Data Protection Addendum. | Being confirmed with the contracting entity. | Microsoft Products and Services Data Protection Addendum | Microsoft Corporation is certified under the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Framework. |
| Google (Workspace Admin SDK) | Google Cloud EMEA Limited, for customers in EMEA | 70 Sir John Rogerson's Quay, Dublin 2, Ireland | Cloud Data Processing Addendum | The contracting entity is established in Ireland; onward transfers run under Google's Standard Contractual Clauses. Google LLC is certified under the EU-US Data Privacy Framework and its UK Extension. |
| Sub-processor | Purpose | Data processed | Where it is processed | Since |
|---|---|---|---|---|
| Xero | Accounting ledger sync for CrowCash, where the customer authorises the connection | Invoices, debtor and customer names, contact email addresses, amounts and payment history from the customer's ledger | Xero publishes that data may be transferred to and processed in Australia, New Zealand and the United States | Being confirmed from billing records |
| Intuit (QuickBooks Online) | Accounting ledger sync for CrowCash, where the customer authorises the connection | Invoices, debtor and customer names, contact email addresses, amounts and payment history from the customer's ledger | Being confirmed. | Being confirmed from billing records |
| Sage | Accounting ledger sync for CrowCash, where the customer authorises the connection | Invoices, debtor and customer names, contact email addresses, amounts and payment history from the customer's ledger | Sage publishes a per-product hosting location table; its UK and Irish cloud products are hosted predominantly in Ireland and the United Kingdom | Being confirmed from billing records |
| Microsoft (Microsoft 365 / Graph) | Read-only security posture discovery for CrowCyber, where the customer authorises the connection | Tenant identifier, organisation display name, administrator identity, and security configuration signals such as MFA coverage | Determined by the customer's own Microsoft tenant configuration, including Microsoft's EU Data Boundary where the customer has it. | Being confirmed from billing records |
| Google (Workspace Admin SDK) | Read-only security posture discovery for CrowCyber, where the customer authorises the connection | Customer/tenant identifier, administrator identity, and security configuration signals | Determined by the customer's own Workspace configuration, including Google's Data Regions where the customer has it. | Being confirmed from billing records |
If you choose “Sign in with Google”, Google is notacting as our sub-processor. Google’s API Terms of Service apply the Google Controller-Controller Data Protection Terms to this arrangement, which makes Google an independent controller of the sign-in rather than a processor acting on our instructions. We receive your Google account identifier, name and email address; Google’s own privacy policy governs what Google does with the sign-in on its side. Google LLC is certified under the EU-US Data Privacy Framework and its UK Extension. This is stated here because Google sign-in was previously, and incorrectly, listed in the sub-processor table.
The services below are queried to retrieve public or statutory information. Each is an independent controller of its own register — Companies House states in terms that the registrar is not acting as a data processor when maintaining a public register, and the Energy Performance of Buildings Register is maintained by MHCLG on a public-task basis. They are disclosed here for transparency under Article 30; they are not Article 28 sub-processors.
| Service | Controller | Purpose | What we send |
|---|---|---|---|
| Companies House | The registrar of companies, an executive agency of the Department for Business and Trade — an independent controller under the Companies Act 2006 | Company lookup and verification | A company number or search term entered by the user. No account data is disclosed. |
| European Commission — VIES | The European Commission, under Regulation (EU) 2018/1725. VIES queries the national VAT databases of the Member States, each an independent controller. | EU VAT number validation for billing | The VAT identification number being validated, which is personal data where it belongs to a sole trader or partnership. The returned trader name and address are logged against the account. UK VAT numbers are validated by format only and are never sent. |
| Energy Performance of Buildings Register | The Ministry of Housing, Communities and Local Government, under the Energy Performance of Buildings (England and Wales) Regulations 2012, on a public-task basis | EPC lookup for property assessments | Postcode, address or UPRN of a property, which is personal data where the property is domestic or the customer is a sole trader |
| Find a Tender, Contracts Finder, Public Contracts Scotland, Sell2Wales, eTendersNI | The respective UK and devolved public procurement authorities | Public procurement notice ingest and opportunity matching | Search filters only (sector, CPV code, region, date). No personal data is sent. |
| Bank of England, ONS NOMIS, legislation.gov.uk, GOV.UK | The respective public bodies | Reference data — base rate, local area statistics, regulatory monitoring | No personal data is sent. |
Some features send data to a service that you choose and control with your own credentials. For these, you are the controller of the onward transfer and we do not engage the provider as our sub-processor:
Where you connect your own Twilio, Vonage or MessageBird account, message content and recipient numbers go to that account under your contract with the provider.
Where you connect your own Creditsafe account, the company identifiers you check are sent under your contract with the provider.
Where you configure a webhook URL (for example an automation platform endpoint), the event payload is delivered to the destination you nominated.
We notify customers by in-app banner and email to the billing contact at least 30 days before adding a new sub-processor or moving an existing sub-processor to a new region. Customers may object on reasonable grounds; where an objection cannot be resolved, the Customer may terminate the affected services.
| Sub-processor | Former purpose | Stopped processing |
|---|---|---|
| Resend | Transactional email delivery | May 2026 — replaced by Brevo |