Sub-processors
Last updated: September 7, 2026
This page lists the third parties that process personal data on our behalf when you use AdverseMe. It is the list referred to in section 5 of the Privacy Policy. We will update this page at least 30 days before a new sub-processor starts handling customer data, except where a replacement is needed urgently to keep the Service running, in which case we will update it as soon as practicable.
Where a provider is outside the European Economic Area or the United Kingdom, transfers rely on the safeguards described in section 10 of the Privacy Policy.
1. Providers that handle your account data
These receive the data you give us to run your account: names, work email addresses, sign-in records, billing identity and the emails we send you.
| Provider | Role | Location | Data |
|---|---|---|---|
| Microsoft Azure | Hosting, database, secrets, file storage, logs | Netherlands (West Europe) | All account and screening data at rest |
| Microsoft Entra External ID | Identity and sign-in | European Union | Name, email, sign-in records |
| Azure Communication Services | Transactional email from mail.adverseme.com | European Union | Recipient address, email content |
| Stripe | Payments and invoicing | United States | Billing identity and payment details. Card numbers are held by Stripe only |
| Cloudflare | DNS and edge proxy for adverseme.com and api.adverseme.com | Global edge network | IP address, request metadata, API traffic in transit |
| Google Analytics 4 | Consent-based public funnel measurement, sanitized private-app page and action counts, and validated advertising click attribution | United States | Measurement cookies; canonical public page categories; controlled app route templates and action IDs; validated Google click IDs; server-verified transaction UUID, plan, currency, and amount. No screening, case, form, email, or card data |
| Microsoft Clarity | Consent-based heatmaps and masked interaction recordings on clean public pages only | United States | Public-page URL without query or fragment, masked public-page content, and interaction data. Never private application, authentication, invitation, admin, or checkout-success pages |
2. Providers that handle screening subject data
When you screen a person or a company, the subject’s name and the identifying details you enter are sent to the services below to find and assess matches. You are the controller of that data and we act as your processor, as set out in section 1.2 of the Privacy Policy. National identification and passport numbers are never sent to any web search or document service; they are used only to compare against list entries.
| Provider | Role | Location | Data |
|---|---|---|---|
| Azure OpenAI | AI assessment of findings; document extraction fallback | Netherlands (West Europe) | Subject details, evidence text, uploaded document images |
| OpenAI | AI assessment of findings; primary document extraction | United States | Subject details, evidence text, uploaded document images |
| Google (Gemini API) | AI assessment of findings | United States | Subject details, evidence text |
| NVIDIA (NIM) | AI assessment of findings | United States | Subject details, evidence text |
| OpenRouter, and through it Anthropic | AI assessment of findings | United States | Subject details, evidence text |
| Firecrawl | Web search and page retrieval | United States | Subject name in search queries, retrieved pages |
| Browserless | Browser rendering of sources that require it | United States | Subject name in page requests |
| Apollo.io | Company and officer enrichment | United States | Company domain, officer names |
| OpenSanctions | Sanctions and politically exposed person matching | Germany | Subject name and identifiers in queries |
| MediaCloud | News search | United States | Subject name in search queries |
3. Public sources we consult
In addition to the sub-processors above, a screening queries public registries, sanctions lists and news archives directly, including Companies House, the FCA register, GLEIF, SEC EDGAR, OFAC, the UN, OFSI, EU and Swiss sanctions lists, national terrorist lists, court records, procurement portals and threat intelligence feeds. Each receives the subject’s name, or a domain, in a query. These are independent publishers of public data, not processors acting on our behalf, and the full list of sources is on the coverage page.
4. Questions and objections
If you object to a sub-processor, or need a copy of our data processing terms, contact us at the address given in the Privacy Policy. We will work with you in good faith to find an alternative, and where none is reasonably available you may terminate the affected part of the Service as set out in the Terms.
