Subprocessors
Skrib, Inc. - Subprocessors
Last updated: 4 June 2026
This page lists the sub-processors that Skrib, Inc. ("Skrib") engages to process Customer Content (as defined in Skrib's Data Processing Addendum) on behalf of Customers and to support the delivery of skrib.com and the related online services (collectively, the "Services"). The sub-processors relevant to a particular Customer depend on the specific Services they use.
Skrib requires each sub-processor to implement appropriate technical and organisational measures to protect Customer Content as required under applicable data-protection laws. Where the use of a sub-processor involves the cross-border transfer of Customer Content, Skrib relies on an appropriate transfer mechanism.
Customers may subscribe to receive notifications of new or replacement sub-processors using the sign-up form at the bottom of this page. The published list is the authoritative list referenced by the Data Processing Addendum.
Hosting, infrastructure, and content delivery
- Amazon Web Services, Inc.
- Used for: Hosting and storage for all Services; AI inference via Amazon Bedrock (see AI service providers below)
- Categories of personal data: Customer Content, account data, usage and log data
- Location: Frankfurt, Germany (eu-central-1) - primary; backup in EEA
- Transfer mechanism: EU-internal - no transfer; SCCs (2021) where any AWS support originates outside the EEA
- Cloudflare, Inc.
- Used for: CDN / edge delivery and geo-routing
- Categories of personal data: IP address, request metadata, online identifiers
- Location: Global edge network - content may be processed across Cloudflare's worldwide points of presence; primary storage in the US and EU
- Transfer mechanism: EU-U.S. DPF + SCCs (2021)
AI service providers
Skrib accesses AI models through enterprise or comparable API arrangements that contractually prohibit the provider from using content submitted through the Services to train the provider's own foundation models. Skrib does not use user prompts, uploaded files, document content, or AI outputs to train Skrib's own models.
- Amazon Web Services, Inc. (Amazon Bedrock - Anthropic Claude models)
- Used for: AI Features (drafting, long-context analysis) using Anthropic Claude models
- Categories of personal data: Prompts, selected text and files submitted for AI assistance, AI outputs
- Location: Processed within the configured Amazon Bedrock region (see note below)
- Transfer mechanism: Within AWS; SCCs (2021) where the configured region is outside the EEA. Bedrock does not share request content with Anthropic and does not use it for model training.
- Microsoft Corporation (Azure OpenAI Service - GPT models)
- Used for: AI Features (drafting, editing, summarisation) using GPT models
- Categories of personal data: Prompts, selected text and files submitted for AI assistance, AI outputs
- Location: Processed within the configured Azure region (see note below)
- Transfer mechanism: EU-U.S. DPF + SCCs (2021). Azure OpenAI does not share request content with OpenAI and does not use it for model training.
- Google LLC (Gemini API)
- Used for: AI Features (multimodal drafting)
- Categories of personal data: Prompts, selected text and files submitted for AI assistance, AI outputs
- Location: United States and EEA
- Transfer mechanism: EU-U.S. DPF + SCCs (2021); no-training contractual restriction
Note on AI processing regions. Skrib configures AI inference to process Customer Content within a defined cloud region per provider. Confirm the exact Amazon Bedrock and Azure OpenAI regions in use, as they determine whether a cross-border transfer occurs and which mechanism applies.
Payments and fraud prevention
- Stripe, Inc. (US); Stripe Payments Europe, Ltd. (EEA/UK)
- Used for: Billing and payment processing, fraud prevention, and tax calculation
- Categories of personal data: Billing name, billing address, payment-method type (card brand + last 4), transaction metadata, tax-residency country
- Location: United States; EU/UK for EEA/UK transactions
- Transfer mechanism: EU-U.S. DPF + SCCs (2021)
- Resend
- Used for: Transactional and account email
- Categories of personal data: Recipient name, email, message metadata
- Location: United States
- Transfer mechanism: SCCs (2021)
Analytics and product measurement
The following providers are used subject to consent (where required by applicable law). Consent is captured through Skrib's Consent Management Platform and respected on a per-category basis.
- Google LLC (Google Tag Manager + Google Analytics 4)
- Used for: Landing-page tag management and analytics (consent-gated)
- Categories of personal data: IP address (truncated), browser/device characteristics, usage events, online identifiers
- Location: United States and EEA
- Transfer mechanism: EU-U.S. DPF + SCCs (2021)
- PostHog Inc.
- Used for: Product analytics in logged-in areas (consent-gated)
- Categories of personal data: Usage events, feature engagement, pseudonymous identifiers
- Location: United States and EEA (EU Cloud hosting in Frankfurt available)
- Transfer mechanism: SCCs (2021)
Customer relationship management
- HubSpot, Inc.
- Used for: CRM and onboarding sync
- Categories of personal data: Contact name, email, company, onboarding and marketing engagement data
- Location: United States and EEA (EU data hosting in Frankfurt, Germany available on Enterprise plans)
- Transfer mechanism: EU-U.S. DPF + SCCs (2021)
Skrib affiliated entities (as sub-processors)
The following Skrib entities may also process Customer Content when providing technical and operational support.
- Skrib, Inc. - United States (parent entity); EEA processing for Customer-Content storage in Frankfurt
- Skrib Operations LLC - Georgia (operational headquarters in Tbilisi)
- VeraSafe Ireland Ltd (EU representative) - Cork, Ireland - acts as EU Article 27 representative; not a sub-processor of Customer Content
- VeraSafe United Kingdom Ltd (UK representative) - London, United Kingdom - acts as UK Article 27 representative; not a sub-processor of Customer Content
Where Skrib later establishes additional affiliated entities, those entities will be added to this list when they begin to process Customer Content.
How we engage sub-processors
Each sub-processor is engaged under a written contract that requires the sub-processor to: (a) process personal data only on Skrib's documented instructions; (b) maintain appropriate technical and organisational security measures; (c) impose confidentiality obligations on its personnel authorised to process the data; (d) notify Skrib of personal data breaches without undue delay; (e) assist Skrib in responding to data subject requests and other obligations under applicable law; (f) delete or return personal data on termination; and (g) accept obligations consistent with Article 28 of the GDPR (or analogous law). Where a sub-processor processes personal data outside the EEA, the United Kingdom, or Georgia in circumstances requiring a transfer mechanism, Skrib relies on the mechanism identified above.
Notification of changes
Skrib will provide enterprise customers with at least thirty (30) days' prior notice before authorising any new sub-processor that processes Customer Content. Notification is sent to the email address designated by the customer in its account or in its DPA, and is also published as a change to this list at https://skrib.com/legal/subprocessors. Customers may subscribe to a notification feed below.
Subscribe to change notifications
To receive an email each time Skrib adds or replaces a sub-processor, please use the form embedded on the published page at https://skrib.com/legal/subprocessors.
Contact
Privacy: contact@skrib.com | Data Protection Officer: contact@skrib.com | Vendor management: contact@skrib.com
Skrib, Inc. | Effective 4 June 2026
The current list of subprocessors will appear here once vendors are added.