Legal

Sub-processors

Last updated: 16 September 2026

Kronoscube engages the following third-party service providers (“sub-processors”) to assist in delivering the Service. As described in our Data Processing Addendum, all sub-processors are contractually bound to data protection obligations equivalent to GDPR Article 28 requirements.

Notice of Changes

We will update this page at least 30 days in advance of adding new sub-processors or changing existing ones. Customers may object to new sub-processors on reasonable data protection grounds within 14 days of notification by contacting martin.solutions.ltd@gmail.com.

Current Sub-processors

Purpose

Authentication, database hosting, and user management

Location

EU (eu-central-1, Frankfurt, Germany)

Data Types

Account data, debtor/invoice data, collection events

Transfer Safeguards

GDPR-compliant, EU-hosted

Purpose

Web application hosting, CDN, and edge functions

Location

Global CDN (may process in US)

Data Types

HTTP request data, session tokens (transient)

Transfer Safeguards

Standard Contractual Clauses where applicable

Fly.io (Fly Apps)

https://fly.io

Purpose

API and worker process hosting

Location

US (currently iad/US East region)

Data Types

Debtor/invoice data, collection processing

Transfer Safeguards

Standard Contractual Clauses (SCCs) apply

Stripe, Inc.

https://stripe.com

Purpose

Billing, payment processing, and Stripe Connect (optional)

Location

Global (US-based with EU data residency options)

Data Types

Billing data, payment methods, Connect account data

Transfer Safeguards

GDPR-compliant with DPA and SCCs

Resend Labs, Inc.

https://resend.com

Purpose

Transactional email delivery (collection emails)

Location

EU (eu-west-1, Ireland)

Data Types

Debtor email addresses, collection email content

Transfer Safeguards

GDPR-compliant, EU-hosted

Functional Software, Inc. (Sentry)

https://sentry.io

Purpose

Error monitoring and performance tracking

Location

EU ingest (Germany)

Data Types

Error logs, stack traces (PII automatically redacted)

Transfer Safeguards

GDPR-compliant with DPA

OpenRouter (Optional)

https://openrouter.ai

Purpose

AI tone adjustment for collection emails (if enabled by customer)

Location

US (OpenRouter proxies to various AI providers)

Data Types

Invoice content, email body text (only if AI tone enabled)

Transfer Safeguards

Only processes data when customer explicitly enables AI feature

Intuit Inc. (QuickBooks Online) (Optional)

https://quickbooks.intuit.com

Purpose

Invoice and customer import via QuickBooks sync (if connected)

Location

US (Intuit data centers)

Data Types

QBO customer data, invoice data (only if OAuth connected)

Transfer Safeguards

Only processes data when customer connects QBO account

International Transfers

Where personal data is transferred to sub-processors located outside the European Economic Area (EEA) in countries without an EU adequacy decision, Kronoscube ensures adequate safeguards through:

  • Standard Contractual Clauses (SCCs): EU Commission-approved SCCs incorporated into sub-processor agreements (Fly.io, Vercel where applicable)
  • Supplementary Measures: Encryption in transit and at rest, access controls, and contractual restrictions to ensure data protection equivalent to GDPR standards
  • Customer Consent: Optional integrations (QuickBooks, OpenRouter AI) only transfer data when explicitly enabled by the customer

Optional Sub-processors

The following sub-processors are only engaged when you explicitly enable optional features:

OpenRouter (AI Tone Adjustment)

Only processes invoice content when you enable AI tone adjustment in organization settings. You may disable this feature at any time.

Intuit QuickBooks Online

Only processes data when you connect your QuickBooks account via OAuth. You may disconnect at any time, and data synchronization will stop immediately.

Sub-processor Security

All sub-processors are contractually required to:

  • Process personal data only on documented instructions from Kronoscube
  • Maintain appropriate technical and organizational security measures
  • Ensure confidentiality of personnel with access to personal data
  • Assist with data subject rights requests and breach notifications
  • Delete or return personal data upon termination
  • Permit audits and provide information necessary to demonstrate compliance

Requesting More Information

For questions about our sub-processors, data transfer safeguards, or to request copies of Standard Contractual Clauses, please contact: martin.solutions.ltd@gmail.com

Disclaimer: This sub-processor list is accurate as of the last updated date. Kronoscube commits to maintaining this list current and providing advance notice of changes. For legal questions regarding data transfers, please consult a qualified attorney.