Sub-processors
Last changed [not yet set]
When Corresso processes personal data for our customers, these companies help us do it. Each one we use works under a written data processing agreement with us (GDPR art. 28(4)).
Hetzner Online GmbH
Active- Purpose
- Hosting: the servers that run Corresso and hold its database
- Personal data
- Everything Corresso stores: accounts, conversations, notes and drafts
- Where
- Germany (EU)
- Address
- Industriestr. 25, 91710 Gunzenhausen, Germany
- Transfer safeguard
- None needed: the data stays in the EU
AC PM, LLC (Postmark)
Active- Purpose
- Delivering the email a person sends from Corresso, and reporting back what happened to it
- Personal data
- Outgoing messages (sender, recipients, subject and text) and whether each was delivered, bounced or marked as spam
- Where
- USA (Deft’s data centre outside Chicago, and Amazon Web Services)
- Address
- 1 N Dearborn Street, Suite 500, Chicago, IL 60602, USA
- Transfer safeguard
- EU-U.S. Data Privacy Framework (AC PM LLC is covered by ActiveCampaign, LLC’s certification), with the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as the alternative
- Keeps data
- Keeps sent messages for up to 45 days (its default), and addresses that bounced, complained or unsubscribed on a suppression list until they are removed
Anthropic Ireland, Limited, and Anthropic, PBC
Not yet activeEngaged only when this service is switched on, and not before every customer has had 30 days’ notice.
- Purpose
- Writing draft replies for a person to review, edit and send
- Personal data
- The text of the conversation a draft is written for, and the draft it returns
- Where
- USA (Anthropic, PBC)
- Address
- Anthropic Ireland, Limited: 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland. Anthropic, PBC: 548 Market St, PMB 90375, San Francisco, CA 94104, USA
- Transfer safeguard
- EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). Anthropic is not certified under the EU-U.S. Data Privacy Framework.
How we tell you about changes
We tell every customer by email at least 30 days before we add or replace a sub-processor, and update this page; customers may object, as our data processing agreement describes. When a sub-processor tells us, with less notice, that it is changing its own sub-processors, we pass that on as soon as we receive it.
Not a sub-processor: your own shop
If you connect your Shopify store, Corresso reads from it on your instruction, through your own account with Shopify. Shopify is your provider, under your agreement with it — not ours — so it is not on this list. Pictures of the products in an order load in your staff’s browsers straight from Shopify’s servers (cdn.shopify.com); our privacy notice tells them what Shopify receives.