[
Legal
]
Sub-processors
Last updated September 30, 2026 · Effective September 30, 2026 · Version 1.0
Krede, Inc. provides its verification services on a platform operated by its technology provider, Right & Data, Ltd. (operating as Dataspike), and engages the third parties below to process personal data on behalf of our customers. This page forms part of each customer's Data Processing Agreement.
1. Current sub-processors
Sub-processor
Location
Purpose
Data processed
Right & Data, Ltd. (Dataspike), technology provider
Cyprus (operations)
Operates the verification platform, dashboard, API, AI features and support
All customer data processed through the services
Amazon Web Services
EU (Stockholm); region depends on customer configuration
Cloud infrastructure, storage and processing, including hosted models used by the services
All customer data processed through the services
Amazon Web Services (SageMaker)
EU (Stockholm)
Model training and validation, only for customers that have opted in
Pseudonymised verification data of opted-in customers only
Cloudflare
USA / EU
Content delivery, DDoS protection, traffic proxying
IP addresses, technical and device data
Postmark (ActiveCampaign)
USA
Transactional email (applicant and reviewer notifications, account emails)
Email address, name, notification content, technical metadata
Identity data validation providers (for example, government identifier verification sources) are engaged only where a customer has enabled the relevant check. They are not active by default.
2. Data providers
The services obtain data from business registries, taxpayer identification sources, and sanctions, watchlist, politically exposed person and adverse media sources, and, where a customer enables them, identity data sources. Each receives only the data elements needed for its check. The named list is available to a customer's security team on request under confidentiality.
3. Where data is processed
Personal data is stored in the region shown above for Amazon Web Services. Where a sub-processor or data provider processes personal data outside the country in which it was collected, appropriate transfer safeguards are in place, including Standard Contractual Clauses where required.
4. Changes
We may add or replace sub-processors. This page is updated at least 30 days before a change takes effect, and customers with a Data Processing Agreement are notified by email. A customer may object on reasonable data-protection grounds within 14 days of the notice, as its agreement provides.
Questions
privacy@krede.ai