← Back to home

Sub-processors

Last updated: April 2026

1. About This List

A sub-processor is a third-party organisation that Core M8 Ltd (“Corem8”) engages to process personal data on behalf of our customers in order to deliver the Corem8 platform. Under Article 28 of the UK and EU General Data Protection Regulation we are required to maintain an up-to-date list of these parties and to notify our customers of any changes.

This page is the authoritative list. It is referenced by our Data Processing Agreement and our Privacy Policy.

We split the list into two groups. Core infrastructure sub-processors are engaged for every customer of the platform. Optional integration sub-processors only receive data if the customer explicitly connects them from within Corem8.

2. Core Infrastructure Sub-processors

Engaged for the operation of the Corem8 platform for every customer.

ProviderPurposeData CategoriesLocationTransfer Mechanism
Clerk
Clerk, Inc.
Privacy notice →
User authentication, session management, MFA, organisation membershipName, email, phone, hashed password, session tokens, IP, user-agentUnited StatesSCCs + UK IDTA Addendum
Supabase
Supabase Inc.
Privacy notice →
Primary Postgres database, Storage (file/photo uploads), Realtime subscriptionsAll tenant-entered data (customers, jobs, invoices, messages, photos)United StatesSCCs + UK IDTA Addendum
Vercel
Vercel Inc.
Privacy notice →
Application hosting, edge network, serverless compute, image optimisationRequest logs, IP addresses, routing metadata (no persistent tenant data)United States (edge PoPs global)SCCs + UK IDTA Addendum
Upstash
Upstash, Inc.
Privacy notice →
Rate limiting, short-lived cache, idempotency keysRate-limit identifiers (hashed IP / user ID), TTL-bound cache entriesIreland (EU)No transfer outside EU/UK
Stripe
Stripe Payments Europe, Ltd. / Stripe, Inc.
Privacy notice →
Subscription billing, card processing for the Corem8 SaaS itselfBilling contact, card token, payment history (card numbers never reach us)Ireland (EU) with US sub-processorsSCCs + UK IDTA Addendum
Anthropic
Anthropic PBC
Privacy notice →
Claude large-language-model inference for AI-assisted features (summaries, drafts, knowledge base)Prompts derived from tenant-supplied text (customer messages, job notes, KB content)United StatesSCCs + UK IDTA Addendum; Anthropic zero-retention enterprise terms
SendGrid (Twilio)
Twilio Inc.
Privacy notice →
Transactional and notification email deliveryRecipient email, email subject and body, delivery metadataUnited StatesSCCs + UK IDTA Addendum
Twilio
Twilio Inc.
Privacy notice →
SMS and WhatsApp message routingSender and recipient phone numbers, message content, delivery metadataUnited StatesSCCs + UK IDTA Addendum
Sentry
Functional Software, Inc. (trading as Sentry)
Privacy notice →
Error tracking and performance monitoring for platform reliabilityStack traces, request metadata, redacted user IDs (no PII or message bodies)Germany (EU)No transfer outside EU/UK

3. Optional Integration Sub-processors

Only engaged where the customer has explicitly connected the relevant integration from within Corem8 (for example, by completing an OAuth flow or entering API credentials). Disconnecting the integration stops the associated data transfer.

ProviderPurposeData CategoriesLocationTransfer Mechanism
Google (Maps Platform)
Google LLC / Google Ireland Ltd.
Privacy notice →
Address autocomplete, geocoding, distance matrix, map tilesAddresses and coordinates entered for jobs and leadsUnited States / IrelandSCCs + UK IDTA Addendum
Google (Ads API)
Google LLC / Google Ireland Ltd.
Privacy notice →
Uploading offline conversions to the tenant's Google Ads accountGoogle click ID (GCLID), conversion value, conversion time (no customer PII)United States / IrelandSCCs + UK IDTA Addendum
Google (Gmail API)
Google LLC / Google Ireland Ltd.
Privacy notice →
Sending and syncing email from the tenant's connected Gmail accountEmail subjects, bodies, and attachments the tenant chooses to syncUnited States / IrelandSCCs + UK IDTA Addendum
Meta (WhatsApp Cloud API)
Meta Platforms Ireland Ltd.
Privacy notice →
Sending and receiving WhatsApp messages on the tenant's business numberSender and recipient phone numbers, message content, delivery receiptsIreland (EU) with US sub-processorsSCCs + UK IDTA Addendum
Meta (Facebook Login / Graph API)
Meta Platforms Ireland Ltd.
Privacy notice →
Facebook Login for tenant accounts, posting to the tenant's Facebook PageFacebook user ID, name, email (from login), Page access tokensIreland (EU) with US sub-processorsSCCs + UK IDTA Addendum
Xero
Xero (UK) Ltd.
Privacy notice →
Accounting sync (invoices, customers, payments)Invoice and customer records the tenant chooses to syncUnited Kingdom / Australia / New ZealandUK IDTA for AU/NZ transfers
Intuit (QuickBooks Online)
Intuit Inc.
Privacy notice →
Accounting sync (invoices, customers, payments)Invoice and customer records the tenant chooses to syncUnited StatesSCCs + UK IDTA Addendum

4. Safeguards for International Transfers

Where personal data is transferred outside the United Kingdom or the European Economic Area we rely on one or more of the following transfer mechanisms, depending on the destination country and the sub-processor's own compliance posture:

  • The Standard Contractual Clauses (SCCs) adopted by the European Commission on 4 June 2021, incorporated into the sub-processor's Data Processing Addendum.
  • The UK International Data Transfer Addendum to the EU SCCs (IDTA Addendum) issued by the Information Commissioner's Office.
  • The EU–US and UK–US Data Privacy Frameworks where the receiving sub-processor has self-certified under the relevant scheme.
  • Supplementary technical measures including encryption in transit (TLS 1.2+), encryption at rest for credentials and tokens, access controls, and logging.

Copies of the executed Data Processing Addenda we hold with each sub-processor are available on request for customers who have signed our Data Processing Agreement.

5. Notice of New Sub-processors

Before we engage a new sub-processor, or replace an existing one, we will update this page and send advance notice to customers who have an active subscription and have requested notifications.

Notice is typically given at least 30 days in advance of the new sub-processor receiving any personal data, except where a shorter timeframe is required for platform security or legal compliance.

To receive notifications of changes to this list by email, send a request from the billing contact on your Corem8 account to privacy@corem8.com.

6. How to Object

A customer that has signed our Data Processing Agreement may object to a proposed new sub-processor on reasonable data-protection grounds by writing to privacy@corem8.com within 30 days of the notice.

We will work in good faith to propose an alternative approach. If an alternative is not reasonably available and the customer does not wish to proceed, the customer may terminate the affected service in accordance with the termination provisions of the Data Processing Agreement.

7. Contact

Email: privacy@corem8.com

Entity: Core M8 Ltd, registered in England & Wales

Regulator:Information Commissioner's Office, United Kingdom (ico.org.uk)