Legal
Sub-processors
Last updated: 16 September 2026
Kronoscube engages the following third-party service providers (“sub-processors”) to assist in delivering the Service. As described in our Data Processing Addendum, all sub-processors are contractually bound to data protection obligations equivalent to GDPR Article 28 requirements.
Notice of Changes
We will update this page at least 30 days in advance of adding new sub-processors or changing existing ones. Customers may object to new sub-processors on reasonable data protection grounds within 14 days of notification by contacting martin.solutions.ltd@gmail.com.
Current Sub-processors
Supabase Inc.
https://supabase.comPurpose
Authentication, database hosting, and user management
Location
EU (eu-central-1, Frankfurt, Germany)
Data Types
Account data, debtor/invoice data, collection events
Transfer Safeguards
GDPR-compliant, EU-hosted
Vercel Inc.
https://vercel.comPurpose
Web application hosting, CDN, and edge functions
Location
Global CDN (may process in US)
Data Types
HTTP request data, session tokens (transient)
Transfer Safeguards
Standard Contractual Clauses where applicable
Fly.io (Fly Apps)
https://fly.ioPurpose
API and worker process hosting
Location
US (currently iad/US East region)
Data Types
Debtor/invoice data, collection processing
Transfer Safeguards
Standard Contractual Clauses (SCCs) apply
Stripe, Inc.
https://stripe.comPurpose
Billing, payment processing, and Stripe Connect (optional)
Location
Global (US-based with EU data residency options)
Data Types
Billing data, payment methods, Connect account data
Transfer Safeguards
GDPR-compliant with DPA and SCCs
Resend Labs, Inc.
https://resend.comPurpose
Transactional email delivery (collection emails)
Location
EU (eu-west-1, Ireland)
Data Types
Debtor email addresses, collection email content
Transfer Safeguards
GDPR-compliant, EU-hosted
Functional Software, Inc. (Sentry)
https://sentry.ioPurpose
Error monitoring and performance tracking
Location
EU ingest (Germany)
Data Types
Error logs, stack traces (PII automatically redacted)
Transfer Safeguards
GDPR-compliant with DPA
OpenRouter (Optional)
https://openrouter.aiPurpose
AI tone adjustment for collection emails (if enabled by customer)
Location
US (OpenRouter proxies to various AI providers)
Data Types
Invoice content, email body text (only if AI tone enabled)
Transfer Safeguards
Only processes data when customer explicitly enables AI feature
Intuit Inc. (QuickBooks Online) (Optional)
https://quickbooks.intuit.comPurpose
Invoice and customer import via QuickBooks sync (if connected)
Location
US (Intuit data centers)
Data Types
QBO customer data, invoice data (only if OAuth connected)
Transfer Safeguards
Only processes data when customer connects QBO account
International Transfers
Where personal data is transferred to sub-processors located outside the European Economic Area (EEA) in countries without an EU adequacy decision, Kronoscube ensures adequate safeguards through:
- Standard Contractual Clauses (SCCs): EU Commission-approved SCCs incorporated into sub-processor agreements (Fly.io, Vercel where applicable)
- Supplementary Measures: Encryption in transit and at rest, access controls, and contractual restrictions to ensure data protection equivalent to GDPR standards
- Customer Consent: Optional integrations (QuickBooks, OpenRouter AI) only transfer data when explicitly enabled by the customer
Optional Sub-processors
The following sub-processors are only engaged when you explicitly enable optional features:
OpenRouter (AI Tone Adjustment)
Only processes invoice content when you enable AI tone adjustment in organization settings. You may disable this feature at any time.
Intuit QuickBooks Online
Only processes data when you connect your QuickBooks account via OAuth. You may disconnect at any time, and data synchronization will stop immediately.
Sub-processor Security
All sub-processors are contractually required to:
- Process personal data only on documented instructions from Kronoscube
- Maintain appropriate technical and organizational security measures
- Ensure confidentiality of personnel with access to personal data
- Assist with data subject rights requests and breach notifications
- Delete or return personal data upon termination
- Permit audits and provide information necessary to demonstrate compliance
Requesting More Information
For questions about our sub-processors, data transfer safeguards, or to request copies of Standard Contractual Clauses, please contact: martin.solutions.ltd@gmail.com
Disclaimer: This sub-processor list is accurate as of the last updated date. Kronoscube commits to maintaining this list current and providing advance notice of changes. For legal questions regarding data transfers, please consult a qualified attorney.