Sub-processors
Last updated: 2026-08-17 (draft — legal review pending)
1. What this page is
Organisations that use Cyril are the data controllers for the data they put into it. Cyril is the processor. To run the platform we use other companies — hosting, email delivery, payments, AI models and so on — and under UK GDPR and EU GDPR Article 28(2) we have to tell you who they are.
This page is that list. It is the authoritative version; there is no separate register held elsewhere.
The contracting party will be [Legal entity — to be confirmed]. Cyril is not yet a registered legal entity, so no company is named here yet. It will be, before commercial launch.
2. Cyril is pre-launch
Cyril has no paying customers yet. This list therefore describes the platform as built, not a live customer estate.
Where a provider appears below, it means Cyril is built to send data to that provider under the conditions described. It does not mean any customer data has been sent to them. We make no claim to certifications, audit reports or operating history, because we have none yet.
3. Always-on and optional
The list is split in two, because the two halves work differently.
Always-on sub-processors are part of how Cyril runs. Every organisation on the platform uses them, and there is no setting to turn them off. If you use Cyril, your data is processed by these providers.
Optional sub-processors are integrations. Each one is off until somebody at your organisation deliberately turns it on — usually an admin connecting an account or entering credentials in Settings, and in a couple of cases an individual staff member granting access to their own mailbox or calendar. If nobody turns an integration on, no data reaches that provider and it is not a sub-processor for your organisation. Several of them run on your own account with that provider, under your own contract with them.
4. Always-on sub-processors
| Provider | Purpose | Data transferred | Region | Data terms |
|---|---|---|---|---|
| Hostinger International, Ltd. (Cyprus) | VPS hosting for the Cyril API and database — the primary residence of customer data | All customer data held in Cyril: personal data, business records, and the file paths backed by object storage | EU (Lithuania and Netherlands data centres) | DPA |
| Cloudflare, Inc. (USA) | DNS, CDN and web application firewall in front of Cyril's domains; R2 object storage for customer file uploads and encrypted backups; Cloudflare Web Analytics on this website | Request metadata (IP address, headers); the contents of uploaded files; encrypted backup archives. Web Analytics receives page URL, referrer, and coarse device and browser information — no cookies, no identifiers, and no cross-site profile | Global edge network, with EU data localisation available | DPA |
| Twilio SendGrid, Inc. (USA) | Primary transactional email delivery for system messages — authentication, invitations and notifications | Recipient email address, recipient name, message subject and body | USA / EU | DPA |
| Resend, Inc. (USA) | Fallback transactional email delivery, used when SendGrid is not configured, and for organisation-sent email where no custom SMTP is set | Recipient email address, recipient name, message subject and body | USA / EU | DPA |
| Functional Software, Inc. d/b/a Sentry (USA) | Error monitoring and performance traces across the API and the front-end applications | Stack traces, request URLs, user IDs, organisation IDs and breadcrumb metadata. Configured to scrub personal data; no email addresses or names. | USA | DPA |
| Apollo Software, Inc. — Apollo.io (USA) | B2B prospect search and contact enrichment, on a Cyril-managed account | Business-contact details returned by Apollo — names, work email addresses, phone numbers, job titles and employer — for prospects a staff user searches or enriches | USA | DPA |
| Brandfetch BV (Netherlands) | Automatic logo and brand-colour lookup when a new account is created | The company domain name being looked up. No personal data. | EU (Netherlands) | Privacy notice |
| Google LLC (USA) — Google Maps Platform | Places API — address autocomplete on location fields, and company enrichment during onboarding. A third, separate Google flow, unrelated to Analytics above or to Gmail below. | The address fragment or business name a staff user types into the field | Global — Google routes per region | Processor terms |
| Anthropic, PBC (USA) | Primary large language model provider for Cyril's AI features | Any content a customer routes through the AI surface — prompts, retrieved context, agent inputs | USA | DPA |
| OpenAI, L.L.C. (USA) | Secondary large language model and embeddings provider — vector embeddings and fallback chat | The same scope as Anthropic, when invoked for embeddings or as the fallback model | USA | DPA |
| Stripe, Inc. (USA) | Subscription billing for Cyril itself. Stripe Connect is also used where an organisation connects its own Stripe account to collect card payments on Cyril invoices — in that case the organisation is the merchant of record and Cyril is the Connect platform. | Billing: organisation owner email, billing contact, payment-method metadata, transaction history. Connect: connected-account identifiers, the onboarding and identity data the organisation submits to Stripe, and payment metadata for invoices its clients pay through Cyril. | USA / EU / AU — Stripe routes per merchant region | DPA |
| ElevenLabs, Inc. (USA) | Text-to-speech and conversational voice for the AI Assistant's voice mode, the "read this page" accessibility reader, and guided tours — running on Cyril's own ElevenLabs account, not yours. Your organisation does not contract with ElevenLabs for this. | The text the platform reads aloud or that a user types into the AI Assistant, and, in conversational mode, the transcribed text of what the user says. No audio recording is kept — Cyril stores the transcript and a character count only. | USA. ElevenLabs offers EU residency on enterprise tiers. | DPA |
| Google LLC (USA) — Google Analytics | Google Analytics 4, as two separate properties: one on the public marketing site and one on the staff application. Not used on the client portal or platform administration. | Marketing site: page path without query string, referrer, coarse device and browser information, truncated IP address — loaded only after the visitor opts in through the consent banner. Staff application: a module name drawn from a fixed allowlist and nothing else — no full paths, query strings, page titles, referrers, user IDs, organisation IDs or record identifiers, and unrecognised paths send nothing at all. Cookieless, gated on the user's recorded consent, with enhanced measurement switched off. | USA / EU | Processor terms |
Four notes on that table.
AI providers. Neither Anthropic nor OpenAI trains on Cyril's API traffic.
Some of these are dormant until Cyril switches them on. Apollo.io, Brandfetch, Google Places and ElevenLabs run on credentials Cyril holds, configured by Cyril rather than by your organisation. Until Cyril configures one, no data reaches that provider at all. They are listed here rather than in the optional section below because the switch is ours, not yours — you cannot turn them off, and you have no separate contract with the provider. That is the distinction that matters to you as a data controller, so it is the one this page is organised around.
ElevenLabs appears in both tables, and they are different things. Above, it is Cyril's own account powering the assistant's voice and the page reader. Below, it is your account, connected by your admin, powering the Voice Studio. The two never share credentials, billing or data paths.
Stripe. Subscription billing for Cyril is always on. Stripe Connect is not — it only comes into play if your organisation connects its own Stripe account to take card payments on invoices. If you never connect one, the Connect data described above is never created.
5. Optional sub-processors
Engaged only when somebody at your organisation turns the integration on. All are off, or unconfigured, by default.
| Provider | Purpose | Data transferred | Region | Data terms |
|---|---|---|---|---|
| Automattic, Inc. (USA) | Gravatar — profile photos resolved from a hashed email address. Turned on when an organisation admin enables the Gravatar toggle in Settings → Integrations. | A SHA-256 hash of each contact's and each staff user's email address. The plaintext email address is never transmitted. | Global CDN; Automattic is headquartered in San Francisco, USA | DPA |
| Twilio, Inc. (USA) | SMS marketing campaigns and transactional SMS. Turned on when an organisation admin adds their own Twilio credentials in Settings → Integrations. | Recipient phone numbers and message bodies | USA / EU / AU | DPA |
| Pipedrive OÜ (Estonia) | One-way import from Pipedrive into Cyril, used as a migration path. Turned on when an organisation admin adds their own Pipedrive API token in Settings → Integrations. | Organisation and person records, deal data, and activity history from the connected Pipedrive account | EU (Estonia) / USA | DPA |
| HubSpot, Inc. (USA) | One-way import from HubSpot into Cyril, used as a migration path. Turned on when an organisation admin grants OAuth consent in Settings → Integrations. | Company and contact records, deal data, and associated activity from the connected HubSpot account | USA / EU | DPA |
| Adobe Inc. (USA) | Adobe Experience Manager connector — one-way migration of AEM Sites content and AEM Assets into Cyril, authenticated through Adobe IMS. Turned on when an organisation admin supplies their own Adobe credentials. | Content and asset payloads from the connected AEM instance, together with the author metadata attached to them | USA / EU | Privacy notice |
| Google LLC (USA) — Gmail and Calendar | Gmail and Google Calendar OAuth — two-way mailbox and calendar sync. Turned on when a staff user grants OAuth consent for their own Google account. | Mailbox content (subject, body, attachments, headers) and calendar events, for connected mailboxes only | Global — Google routes per region | DPA |
| Microsoft Corporation (USA) | Outlook and Microsoft 365 OAuth — two-way mailbox and calendar sync. Turned on when a staff user grants OAuth consent for their own Microsoft 365 account. | Mailbox content (subject, body, attachments, headers) and calendar events, for connected mailboxes only | Global — Microsoft routes per region; EU Data Boundary available | DPA |
| Slack Technologies, LLC (USA) | Two-way connection to your own Slack workspace — outbound automation messages, slash commands, interactivity and App Home, plus inbound channel messages, mentions, reactions and thread replies linked to Sales records. Turned on when an organisation admin installs the Cyril for Slack app through OAuth in Settings → Integrations. | Slack channel messages, attachments, reactions, and channel and user metadata in the connected workspace. Cyril keeps an append-only ingest log for diagnostics and de-duplication; it does not retain Slack message history beyond that. | USA / EU (Slack EU residency is available to Enterprise Grid customers) | DPA |
| DocuSign, Inc. (USA) | E-signature, as an alternative to Cyril's native signing. Turned on when an organisation admin adds their own DocuSign credentials. | Document content sent for signature, signer name and signer email address | USA / EU / AU | Agreements |
| Australian Business Register (Australian Government) | ABN and ACN lookup for Australian organisations. Turned on when an organisation admin adds their own ABR API GUID. | The business identifier or business name a staff user supplies (ABN, ACN or name) | Australia | Privacy notice |
| ElevenLabs, Inc. (USA) | Text-to-speech for marketing voiceovers, voice clones and multilingual dubs in the Voice Studio, running on your own ElevenLabs account. Cyril passes the API call through and stores the encrypted credential. Turned on when an organisation admin adds their own ElevenLabs API key in Settings → Integrations. | Source text submitted to the Voice Studio; voice IDs and tuning parameters; audio samples uploaded for voice cloning, together with a consent record. Audio output is returned to the browser for preview, and saved audio is retained in your own storage. | USA. ElevenLabs offers EU residency on enterprise tiers; your own contract with ElevenLabs governs. | DPA |
| Klaviyo, Inc. (USA) | Marketing automation sync — campaigns, events, flows, segments, profiles and lists — against your own Klaviyo account. Klaviyo is the controller of the resulting engagement data inside that account. Turned on when an organisation admin grants OAuth consent in Settings → Integrations. | Subscriber email addresses and names, marketing engagement events (opens, clicks, unsubscribes), list memberships, segment definitions and campaign performance metrics. Suppression-list changes flow back into Cyril by webhook. | USA / EU (Klaviyo EU data residency is available on enterprise contracts) | DPA |
| Salesforce.com, Inc. (USA) | One-way import from Salesforce into Cyril — CRM accounts, contacts, opportunities and activities — used as a migration path. Read-only; nothing is written back to Salesforce. Turned on when an organisation admin grants OAuth consent in Settings → Integrations. | Account names, addresses and industries; contact names, email addresses and phone numbers; opportunity stage data; activity history | USA / EU / AU — Salesforce honours your existing region | DPA |
| Revolut Ltd (UK) / Revolut Bank UAB (EU) | Merchant API hosted checkout — an alternative gateway for client invoice payments. Your organisation is merchant of record on its own Revolut Merchant account; Cyril creates the hosted checkout order and stores the encrypted credentials. Turned on when an organisation admin connects their own Revolut Merchant API key in Settings → Integrations. | Payer name and email address, invoice reference, and payment and transaction metadata for invoices your clients pay through Cyril | UK / EU — Revolut routes per merchant region | Privacy notice |
Where the last column says "Privacy notice" or "Agreements" rather than "DPA", that is deliberate: those providers publish their data terms in that form rather than as a standalone data processing addendum.
6. Changes to this list
This page is where changes appear first. When a sub-processor is added, removed or replaced, we update this page and the "Last updated" date at the top.
Adding or removing an always-on sub-processor gets you 60 days' notice. Section 3.2 of our Data Processing Agreement commits to at least sixty calendar days' written notice, sent to your organisation's owner contact, before any addition, removal or material change to a provider in the always-on table above. You may object in writing during that window.
Optional sub-processors carry no notice period, because you are the one switching them on. Nothing reaches an optional provider until somebody at your organisation connects it.
Two honest caveats. The DPA is still a draft pending legal review, so the 60-day commitment is as firm as a draft can be — we are publishing it here because it is already in the document you can download today, and we would rather be held to it than have it sit unread in a PDF. And "notice to your organisation owner contact" is currently a person sending an email, not an automated system.
If you want to be told when this list changes, contact us and ask.
7. Contact
Questions about a provider on this list, or about international transfers? Contact us.