Contact: privacy@atmoz.io
Atmoz AB (corp. reg. 559345-4001) is the data processor for customer data in the Atmoz platform; the customer is the data controller. This list covers that data only.
We engage the sub-processors below to deliver the service. We give at least 30 days' advance notice before adding or replacing a sub-processor, and customers may object on reasonable data-protection grounds.
This list is maintained to name every provider that processes customer personal data on our behalf today. Where we have contracted a provider that is not yet connected to the platform and receives no customer data, it is not listed here - and it will be added to this list, with its location and safeguards, before it receives any.
All customer data is stored within the EU/EEA. Sub-processors with global operations may access data from outside the EU/EEA for support, engineering, on-call or incident response; where that arises, the safeguards marked against that sub-processor apply. The Safeguards column shows what applies to each sub-processor:
- DPA - a data processing agreement governs the relationship.
- SCCs - EU Standard Contractual Clauses cover any transfer or access outside the EU/EEA. The marking is absent where no such transfer arises.
- DPF - the named receiving entity is itself covered by a certification under the EU-U.S. Data Privacy Framework. Where a certification is held by a parent or affiliate rather than the named entity, the marking is qualified in the row, because a certification held elsewhere in a corporate group does not by itself cover a given recipient.
Infrastructure and platform
| Sub-processor | Purpose | Personal data | Location | Safeguards |
|---|---|---|---|---|
| Google Cloud Platform - Google Cloud EMEA Ltd / Google LLC | Compute, storage, databases, networking, logging | User account identifiers, application and access logs, customer source documents | EU | DPA · SCCs · DPF |
| Snowflake - Snowflake Inc. | Data warehouse | Transactional and supplier data; contacts in source documents | EU (Frankfurt) | DPA · SCCs · DPF (non-HR data) |
| Zitadel Cloud - CAOS AG, Switzerland / ZITADEL Inc., USA | Identity and access management | Name, email address, role, login metadata, end-user IP addresses in authentication logs | EU (Frankfurt) | DPA · SCCs · DPF † |
| Scaleway - Scaleway SAS | Transactional email | Recipient email address, message content | France | DPA |
| Grafana Cloud - Raintank Inc. dba Grafana Labs | Observability - service metrics, traces and logs | End-user IP addresses in request logs; service telemetry | EU (Sweden) | DPA · SCCs · DPF |
† The contracting entity is the Swiss company CAOS AG, covered by the European Commission's adequacy decision for Switzerland. The Data Privacy Framework marking relates to its US parent, ZITADEL Inc., rather than to the contracting entity itself.
Supplier registries
To calculate emissions we look up a supplier's industry classification. We send company identifiers - company name, VAT number, organisation number and country code - and no contact details. For a sole trader, a company name and registration number may identify an individual.
| Recipient | Role | Purpose | Location | Transfer safeguard |
|---|---|---|---|---|
| Bolagsverket (Sweden) | Independent controller - public register | Industry classification lookup | Sweden | None required - within the EEA |
| Erhvervsstyrelsen (Denmark, CVR) | Independent controller - public register | Industry classification lookup | Denmark | None required - within the EEA |
| Brønnøysundregistrene (Norway) | Independent controller - public register | Industry classification lookup | Norway | None required - within the EEA |
| Dun & Bradstreet (Direct+) - Bisnode Dun & Bradstreet Sverige Aktiebolag | Independent controller - public register | Industry classification lookup where the national registers do not resolve the supplier | EU | DPA · SCCs · DPF |
The three national registers are public bodies operating statutory registers. They act as independent controllers of their own registers rather than as our processors, and each receives only an identifier it already holds.
Dun & Bradstreet operates a commercial business-information register. Like the national registers above, it receives only an identifier Atmoz already holds - a VAT or organisation number, or a company name and country - and returns an industry classification. Its Data Privacy Framework certification is active for the EU-U.S., UK Extension and Swiss-U.S. frameworks.
AI processing
| Sub-processor | Purpose | Personal data | Location | Safeguards |
|---|---|---|---|---|
| Google Vertex AI (serving Anthropic Claude models) - Google Cloud EMEA Ltd / Google LLC | AI models for document parsing, classification and enrichment | Any personal data incidentally present in customer source documents | EU multi-region (model inference may run in any EU region) | DPA · SCCs · DPF |
Anthropic PBC provides the models as Google's sub-processor under the Google Cloud DPA; Atmoz has no direct agreement with Anthropic. Customer data is never used to train or fine-tune AI models - a contractual commitment under the Google Cloud Service Specific Terms.
Questions, or details of our sub-processors' own sub-processors: privacy@atmoz.io
