Sub-processors
Annex IV to the Data Processing Agreement
Last Updated: 16.09.2026
Version: 1.0
Effective Date: 16.09.2026
This page is the authoritative list of sub-processors engaged by cronio FlexCo for the timelit service. It forms Annex IV to our Data Processing Agreement, under which our customers give a general written authorisation for these engagements in accordance with Clause 7.7 of the Standard Contractual Clauses.
A sub-processor is a third party that processes personal data on our behalf in order for us to provide the Service. Every sub-processor listed here is bound by a contract imposing, in substance, the same data protection obligations that apply to us.
1. Sub-processors that process Customer Content
1.1 Microsoft
Entity: Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Primary processing location: Azure region Sweden Central (EU)
What Microsoft does for us:
- Azure App Service: runs the application
- Azure Cosmos DB: stores email and calendar content, contacts, transcripts, summaries, embeddings and chat history
- Azure Blob Storage: stores uploaded and browser-recorded meeting audio
- Microsoft Graph: retrieves data from the customer's own Microsoft 365 environment
- Azure OpenAI: generates drafts, summaries, categorisations and embeddings, using the model deployments
gpt-4o-mini,gpt-5,gpt-5-mini,gpt-5.6-terraandtext-embedding-3-small - Azure AI Speech: transcribes uploaded and recorded meeting audio
- Azure Application Insights and Log Analytics: telemetry and application logs
Data categories: all categories of Customer Content described in Annex II of the Data Processing Agreement.
Points a reviewer should know:
- Microsoft is contractually bound not to use prompts, completions or embeddings to train its foundation models.
- All five Azure OpenAI model deployments currently use the
GlobalStandarddeployment type. For that deployment type, Microsoft states that prompts and responses may be processed in any geography where the model is deployed, while data stored at rest stays in the designated geography. Any resulting third-country transfer is covered by the standard contractual clauses in the Microsoft Products and Services Data Protection Addendum. - Azure OpenAI's default abuse monitoring stores a sample of prompts and completions for up to 30 days where its automated systems flag possible abuse. Review is automated by default; authorised Microsoft employees may review flagged data where necessary. For models deployed in the EEA, those reviewers are located in the EEA and the store is in our Azure geography.
Documentation: Microsoft Products and Services Data Protection Addendum; Microsoft's ISO/IEC 27001 certificate and SOC 2 reports for Azure. We provide the current versions on request under Tier 1 of the audit process in Annex III.
2. Sub-processors that do not process Customer Content
2.1 Stripe
Entity: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland
What Stripe does for us: payment processing, subscription and invoice management
Data categories: name, email address, billing address, subscription and payment data
Customer Content: none. Stripe receives no email, calendar, contact or meeting data.
3. Components that are not sub-processors
Apache Tika extracts text from email attachments. It runs as a container alongside our application inside the same Azure App Service, under our sole control, and sends no data to any third party. It is a component of the Service, not a sub-processor.
4. Changes to this list
We notify customers of any intended addition or replacement of a sub-processor in writing at least 30 days in advance, by email to the administrative or billing contact registered for the account and by a notice in the Service. Publication on this page alone is not treated as notification.
Where a sub-processor fails, ceases operations, becomes insolvent or has to be replaced for security reasons, we may engage a replacement immediately and notify as soon as possible; the right to object then applies after the fact.
Customers may object on reasonable grounds relating to data protection within the notice period. The procedure and its consequences are set out in Annex IV of the Data Processing Agreement.
5. Contact
Questions about this list: support@timelit.ai