Subprocessors
The third parties that process data on Verinten's behalf, what each one does, and where it operates.
- Version
- 1.0
- Effective
- Contact
- Privacy team
In counsel review — not yet binding. This document is published for transparency while Verinten prepares for launch. It is not yet the binding version of this policy.
Current subprocessors
| Subprocessor | What it does | Data reaching it | Region |
|---|---|---|---|
| Cloudflare | Application hosting, databases, object storage, queues, email delivery and routing, bot protection | All service data. This is the primary infrastructure provider. | Global edge network |
| Stripe | Payment processing, subscriptions, invoicing, tax | Billing contact, organisation name, country, transaction records. Card details go directly to Stripe and never reach Verinten. | United States / European Union |
| PostHog | Product analytics and session replay | Consented analytics events only, identified by an internal user identifier. No email, no name, no workspace slug, no URLs beyond route templates. IP discarded at ingestion. | United States |
| SocialCrawl | Public-source data collection | The public business identifiers you configure. No personal data about your staff or users is sent. | See provider terms |
| AI model provider | Classification, summarisation, response drafting | Public source material and prompts you define. Never patient data, credentials, billing data, or support correspondence. | United States / European Union |
Notification of changes
Workspace owners are notified before a new subprocessor begins processing, with enough notice to raise an objection. Every change is recorded in the change history below.
Objecting
If you object to a new subprocessor on reasonable data-protection grounds, contact the privacy address above. Where we cannot offer a workable alternative you may terminate the affected subscription without penalty for the remaining term.
Change history
- 1.0
First published version.