Sub-processors
Third-party vendors that process data on behalf of Fronterio.
We engage the sub-processors listed below to help us deliver the platform. Each one is contractually bound to process your data only for the purposes we specify. Material changes are notified to organisation owners at least 30 days in advance.
Connecting Microsoft 365?
Microsoft tenant integrations (Copilot tracker, SharePoint sync, Teams agent, Copilot Studio, Azure AI Foundry) are not Fronterio sub-processors — they are your own tenant. For a per-integration view of what Fronterio reads, writes, and never accesses, see the Microsoft data access overview.
View Microsoft data access overview →- Purpose
- Primary database, authentication, file storage.
- Data processed
- Account data, organisation data, uploaded files.
- Processing region
- EU (Frankfurt, eu-central-1)
- Transfer mechanism
- Processing within EU
- Purpose
- Primary database, authentication, file storage.
- Data processed
- Account data, organisation data, uploaded files.
- Processing region
- EU (Frankfurt, eu-central-1)
- Transfer mechanism
- Processing within EU
- Purpose
- Primary database, authentication, file storage.
- Data processed
- Account data, organisation data, uploaded files.
- Processing region
- EU (Frankfurt, eu-central-1)
- Transfer mechanism
- Processing within EU
- Purpose
- Application hosting and serverless function execution.
- Data processed
- Request metadata (no persistent PII storage).
- Processing region
- EU (Stockholm, arn1)
- Transfer mechanism
- Processing within EU
- Purpose
- Application hosting and serverless function execution.
- Data processed
- Request metadata (no persistent PII storage).
- Processing region
- EU (Stockholm, arn1)
- Transfer mechanism
- Processing within EU
- Purpose
- Application hosting and serverless function execution.
- Data processed
- Request metadata (no persistent PII storage).
- Processing region
- EU (Stockholm, arn1)
- Transfer mechanism
- Processing within EU
- Purpose
- Large language model inference (GPT-4o, GPT-4o-mini) for AI Consultant, assessment scoring, and report generation. Used for organisations subscribing via Microsoft Marketplace.
- Data processed
- Organisation-level context, anonymised conversation content, assessment dimension scores
- Processing region
- EU (Sweden Central)
- Transfer mechanism
- EU-US Data Privacy Framework + Standard Contractual Clauses
- Purpose
- AI model inference for the AI Consultant, assessments, and content generation (Claude Sonnet/Haiku).
- Data processed
- Org-level aggregated context (never PII), conversation content submitted by the user.
- Processing region
- US
- Transfer mechanism
- EU Standard Contractual Clauses (SCCs) + EU-US Data Privacy Framework
- Purpose
- AI model inference for the AI Consultant, assessments, and content generation (Claude Sonnet/Haiku).
- Data processed
- Org-level aggregated context (never PII), conversation content submitted by the user.
- Processing region
- US
- Transfer mechanism
- EU Standard Contractual Clauses (SCCs) + EU-US Data Privacy Framework
- Purpose
- AI model inference for the AI Consultant, assessments, and content generation (Claude Sonnet/Haiku).
- Data processed
- Org-level aggregated context (never PII), conversation content submitted by the user.
- Processing region
- US
- Transfer mechanism
- EU Standard Contractual Clauses (SCCs) + EU-US Data Privacy Framework
- Purpose
- Subscription billing, payment processing, tax calculation.
- Data processed
- Billing contact, card token (never card number), invoice metadata.
- Processing region
- EU (Ireland) with global processing
- Transfer mechanism
- EU SCCs
- Purpose
- Subscription billing, payment processing, tax calculation.
- Data processed
- Billing contact, card token (never card number), invoice metadata.
- Processing region
- EU (Ireland) with global processing
- Transfer mechanism
- EU SCCs
- Purpose
- Subscription billing, payment processing, tax calculation.
- Data processed
- Billing contact, card token (never card number), invoice metadata.
- Processing region
- EU (Ireland) with global processing
- Transfer mechanism
- EU SCCs
- Purpose
- Transactional and lifecycle email delivery.
- Data processed
- Recipient email, email subject/body content.
- Processing region
- US
- Transfer mechanism
- EU SCCs
- Purpose
- Transactional and lifecycle email delivery.
- Data processed
- Recipient email, email subject/body content.
- Processing region
- US
- Transfer mechanism
- EU SCCs
- Purpose
- Transactional and lifecycle email delivery.
- Data processed
- Recipient email, email subject/body content.
- Processing region
- US
- Transfer mechanism
- EU SCCs
- Purpose
- Server-side product analytics events (event names + anonymous properties only).
- Data processed
- Event names, org-level properties, no PII.
- Processing region
- EU (eu.posthog.com)
- Transfer mechanism
- Processing within EU
- Purpose
- Server-side product analytics events (event names + anonymous properties only).
- Data processed
- Event names, org-level properties, no PII.
- Processing region
- EU (eu.posthog.com)
- Transfer mechanism
- Processing within EU
- Purpose
- Server-side product analytics events (event names + anonymous properties only).
- Data processed
- Event names, org-level properties, no PII.
- Processing region
- EU (eu.posthog.com)
- Transfer mechanism
- Processing within EU
- Purpose
- Error tracking and performance monitoring.
- Data processed
- Error stack traces, breadcrumbs, user id (if logged in).
- Processing region
- EU (de.sentry.io)
- Transfer mechanism
- Processing within EU
- Purpose
- Error tracking and performance monitoring.
- Data processed
- Error stack traces, breadcrumbs, user id (if logged in).
- Processing region
- EU (de.sentry.io)
- Transfer mechanism
- Processing within EU
- Purpose
- Error tracking and performance monitoring.
- Data processed
- Error stack traces, breadcrumbs, user id (if logged in).
- Processing region
- EU (de.sentry.io)
- Transfer mechanism
- Processing within EU
- Purpose
- Distributed rate limiting and request counters.
- Data processed
- Rate-limit keys (no PII), counters.
- Processing region
- EU
- Transfer mechanism
- Processing within EU
- Purpose
- Distributed rate limiting and request counters.
- Data processed
- Rate-limit keys (no PII), counters.
- Processing region
- EU
- Transfer mechanism
- Processing within EU
Object to a sub-processor
You have the right to object to a sub-processor change. Contact our Data Protection Officer during the objection window and we'll work with you on alternatives.