Skip to content

Subprocessors

The vendors listed below may process customer personal data on Nurion's behalf. Updates are made by commit; new subprocessors that process personal data trigger a customer notification per the internal subprocessor-notification process and a fourteen (14) day objection window per our DPA.

Platform-wide

VendorPurposeRegionTransfer mechanismVendor DPA
Hetzner Online GmbHApplication hosting (compute, network, primary databases)Germany (EEA)Intra-EEALink
Mollie B.V.Payment processing (SEPA, card, recurring billing)Netherlands (EEA)Intra-EEALink
Lettermint B.V.Transactional email delivery (SMTP relay) for confirmations, invitations, account notificationsNetherlands (EEA)Intra-EEALink
Plausible Insights OÜCookieless marketing-website analyticsEstonia (EEA)Intra-EEALink

Nurion Desk

VendorPurposeRegionTransfer mechanismVendor DPA
Verda Cloud (DataCrunch OÜ)AI inference (LLM and ASR) for Desk-managed flowsEstonia / Finland (EEA)Intra-EEALink

Nurion Meet

VendorPurposeRegionTransfer mechanismVendor DPA
Verda Cloud (DataCrunch OÜ)AI inference for transcription and summarisationEstonia / Finland (EEA)Intra-EEALink

Nurion Funnel

VendorPurposeRegionTransfer mechanismVendor DPA
Verda Cloud (DataCrunch OÜ)AI inference for lead enrichment and intent signalsEstonia / Finland (EEA)Intra-EEALink

Vendors that do not process personal data

The vendors below are listed for transparency only. They are contracted by Nurion but do not receive customer personal data from the products.

VendorPurposeRegionTransfer mechanismVendor DPA
DNSimple Corp.DNS, domain registration, and SSL issuance — no personal data flowUnited StatesNot applicable — no personal dataLink

Standard Contractual Clauses and adequacy

Adequacy jurisdictions

Where a subprocessor is established in a country covered by an active EU Commission adequacy decision (e.g. Switzerland, the United Kingdom, Japan), the transfer is treated as adequate without requiring SCCs.

Standard Contractual Clauses 2021/914

For non-EEA, non-adequate transfers that involve personal data, we rely on the EU Commission's 2021/914 Standard Contractual Clauses, in the relevant module, supplemented where necessary by additional safeguards informed by a transfer impact assessment.

EU-US Data Privacy Framework

Where a US-based subprocessor would be required, we prioritise DPF-certified vendors. At the time of writing no US-based subprocessor processes Nurion customer personal data.

Subprocessor change process

See our internal subprocessor-notification process for the details customer-facing teams follow when a vendor is added or replaced. The summary: notify customers by email at least fourteen (14) days before a new subprocessor begins processing personal data; record objections; resolve or terminate the affected processing.

Contact

Questions about this list: privacy@nurion.com.

Version 2026-04-25 · last updated 2026-04-25