How to Read This List
A subprocessor is any third party that processes personal data on our behalf when we deliver the service. This list names all of them. It is grouped by whether a service is always in use or only runs once you switch something on, because that difference decides whether it belongs in your own record of processing.
- Always in use. Running Cloop at all means these process data.
- On when you enable it. Off until an administrator connects the integration or turns the feature on.
- Company data sources. Queried while we build and enrich company records. Most receive a business identifier or a domain name, not a person.
If a service is not on this list, we do not send it your data. See What We Do Not Use for the ones customers ask about most often.
Always in Use
| Subprocessor | Purpose | Data received | Location | Safeguards |
|---|---|---|---|---|
| Hetzner Online GmbH | Servers, database, object storage for uploaded documents, backups | All service data | Finland and Germany (EU) | Hetzner DPA, German company, EU data centres |
| Nebius B.V. | AI inference: chat replies, embeddings, reranking, classification, drafted messages | Message text, passages from your own content, system instructions | Netherlands (EU) | Nebius AI Studio terms; input and output not used for model training and not retained after the response |
| DB-IP | City-level IP database, downloaded to our servers once a month | Nothing. Lookups run locally against the downloaded file | Download only | No personal data leaves our infrastructure |
| Let's Encrypt (ISRG) | TLS certificates | Domain names only | Global | No personal data processed |
Nebius B.V.
- What we send: the message text, the relevant passages from your own content, and our system instructions.
- What we do not send: visitor email addresses, visitor identifiers, account credentials.
- Retention: transient processing only. Nebius does not store input or output after generating the response.
- Model training: Nebius does not use API data to train models.
- Why them: an EU company with EU data centres, so model calls do not leave the EU.
On When You Enable It
Each of these is off until someone in your organisation connects it. Connecting one is your decision, and you can disconnect it at any time.
Signing in
| Subprocessor | Purpose | Data received | Location |
|---|---|---|---|
| Sign in with Google (OpenID Connect) | Name, email address, profile picture | EU / US | |
| Microsoft (Entra ID) | Sign in with Microsoft | Name, email address | EU / US |
| GitHub | Sign in with GitHub | Name, email address | US |
You only meet these if your organisation chooses that sign-in method. Authentication happens at your existing identity provider; we never receive your password.
Calendar and booking
| Subprocessor | Purpose | Data received | Location |
|---|---|---|---|
| Google Calendar and Google Meet | Reading free and busy times, creating meetings and video links | Meeting time, participants, meeting subject | EU / US |
| Calendly | Booking through your own Calendly account | Meeting time, participant name and email address | US |
| Cal.com | Booking through your own Cal.com account | Meeting time, participant name and email address | EU or US, depending on your Cal.com account |
CRM
| Subprocessor | Purpose | Data received | Location |
|---|---|---|---|
| HubSpot | Two-way sync of contacts and companies | Contact name, email address, company details | EU / US |
HubSpot is the only CRM with a working sync today. Pipedrive, Salesforce and Dynamics are not connected.
Voice
| Subprocessor | Purpose | Data received | Location |
|---|---|---|---|
| ElevenLabs | Speech to text and text to speech in the voice widget | The visitor's audio and the assistant's reply text | US |
Voice is off by default on every site. If you turn it on, visitor audio leaves to ElevenLabs, and your own visitor notice needs to say so.
Identifying visiting companies
| Subprocessor | Purpose | Data received | Location |
|---|---|---|---|
| ipapi.is | Resolving a visitor's IP address to a company | The visitor's IP address | EU |
| iplocate.io | The same, used when the first lookup returns nothing | The visitor's IP address | US |
Visitor identification is off by default. It is set per site and requires you to choose a legal basis, either consent or legitimate interest. Global Privacy Control is honoured either way. While identification is off, no visitor IP address leaves our servers.
Sending email
Cloop uses no bulk email service. Mail leaves in one of two ways:
- Service email such as invitations and notifications goes through our own SMTP relay.
- Sales email goes from your own mailbox. Each seller connects their own account, and messages are sent and read directly through it. For most customers that mailbox is Google Workspace or Microsoft 365, in which case your existing provider carries the mail under your own agreement with them.
Company Data Sources
These are queried while building and enriching company records. They receive a business identifier, a company name or a domain, and most of them are public registers.
| Source | Purpose | Location |
|---|---|---|
| PRH and YTJ, avoindata.prh.fi | Finnish trade register: company details, addresses, financial statements | Finland (EU) |
| Traficom, odata.domain.fi | Register of .fi domains | Finland (EU) |
| Brønnøysundregistrene | Norwegian company register | Norway (EEA) |
| CVR, cvrapi.dk | Danish company register | Denmark (EU) |
| European Commission, VIES | VAT number validation | EU |
| GLEIF | Legal Entity Identifier records | Global |
| Wikidata | Headcount, logo, public social media accounts | Global |
| OpenCorporates | Registers for countries we have no direct connection to | United Kingdom |
| Brave Search | Web search for company information | EU / US |
| Clearout | Resolving a company name to a domain | EU / India |
| crt.sh | Finding domains from certificate transparency logs | Global |
These queries concern companies rather than named people. Where a sole trader's business details are also personal data, the same rights apply as to anything else we hold.
What We Do Not Use
To be explicit, we do not use:
- Google Analytics or any other visitor analytics service
- Advertising platforms such as Meta or Google Ads
- Bulk email services such as Mailchimp, SendGrid or Resend
- Error tracking services such as Sentry
- Customer support platforms such as Intercom or Zendesk
- A payment processor. Subscriptions are agreed and invoiced directly, and no card details are processed anywhere in the service
If we add any of these, this list is updated and customers are notified as described below.
Your Own AI Keys
You may supply your own OpenAI or Anthropic API key, in which case model calls for your workspace go to that provider under your own agreement with them. This stays off unless you add a key. Nothing goes to OpenAI or Anthropic otherwise.
Changes to This List
We notify customers at least 30 days before a new subprocessor begins processing data, by:
- email to account owners
- a notice in the dashboard
- an update to this document
If you object to a new subprocessor, you may terminate the affected service within 30 days of the notice, as set out in the DPA.
Change History
| Date | Change |
|---|---|
| 2026-08-03 | Rewritten against the shipping code. Added the identity providers, Calendly, Cal.com, HubSpot, ElevenLabs, the visitor identification services and the company data sources, all of which were in use but unlisted. Recorded that no payment processor is in use. |
| 2026-02-15 | Initial list published |
Contact
Questions about our subprocessors: privacy@cloop.io