Sub-Processor List
CrossCode — Sub-Processor List
Version 1.1 · Effective 2026-06-22
Capitalized terms not defined in this document have the meanings given in our Terms of Service.
CrossCode, Inc. — Sub-Processor List
Effective Date: 2026-06-22 (Version 1.1)
Public location: crosscode.pro/subprocessors
The following Sub-processors process Personal Data on CrossCode's behalf in connection with the Services. This list is updated as Sub-processors are added or removed. Customers may subscribe to update notifications by emailing privacy@crosscode.pro.
| Sub-processor | Purpose | Data Categories | Processing Location | Contractual Basis & Cross-Border Mechanism (for EEA/UK personal data) | Date Added |
|---|---|---|---|---|---|
| Anthropic, PBC | LLM inference (primary) — generation of classification reasoning, ruling retrieval, and Output | Submissions (invoice line-item descriptions, supplier and importer identifiers as appearing in Submissions), prompts derived therefrom | United States | Sub-processor DPA executed; API settings configured to minimize data retention and prohibit training use; for EEA/UK personal data transfers, SCCs Module 3 flow-down applies | 2026-06-22 |
| OpenAI, L.L.C. | LLM inference (failover / alternative) — same scope as Anthropic | Same as Anthropic | United States | Sub-processor DPA executed; API settings configured to minimize data retention and prohibit training use; for EEA/UK personal data transfers, SCCs Module 3 flow-down applies | 2026-06-22 |
| Render Services, Inc. | Hosting, compute, managed databases, object storage | All platform data, including Customer Data and Personal Data | United States | Sub-processor DPA executed; for EEA/UK personal data transfers, SCCs Module 3 flow-down applies | 2026-06-22 |
| Stripe, Inc. | Payment processing, subscription management | Billing data, business contact data, transaction metadata | United States | Stripe DPA executed; PCI DSS Level 1 service provider; for EEA/UK personal data transfers, Stripe's published SCC framework applies | 2026-06-22 |
Note on cross-border transfers. The SCCs (Modules 2 and 3) and the UK IDTA govern the export of Personal Data from the EEA/UK to the United States. The customer→CrossCode leg is governed by the DPA between Customer and CrossCode (typically Module 2). The CrossCode→Sub-processor leg is governed by the Sub-processor DPA above (Module 3 flow-down where applicable). Onward US-to-US processing between Sub-processors does not invoke the SCCs.
CrossCode, Inc. (a Delaware corporation in formation) — operating as CrossCode.
Terms of Service · Privacy Policy · Data Processing Addendum · Acceptable Use Policy · SLA · Sub-processors · Trust