Sub-processors

Last updated: September 2026

Entwine Limited uses the third-party services below to run the platform. Where your organization's data reaches one of them, that service acts as a sub-processor under our Privacy Policy and, where one is in place, your data processing agreement. Transfers outside the UK/EEA rely on standard contractual clauses with the UK Addendum. This page lists what is actually configured on the production platform today; we update it when the list changes.

1. Infrastructure & operations

ProviderPurposeLocationData
DigitalOceanHosting, managed PostgreSQL database, private object storage for documentsUnited StatesAll platform data
StripeSubscription billingUnited States / EUBilling contact and payment details (card numbers never touch Entwine)
ResendTransactional email (invitations, notifications, password resets)United StatesRecipient name, email address, notification content

2. AI & document processing

These providers are used only when you use Document Intelligence, agent proposals, or the in-app help assistant. Each one's published terms state that content sent through its API is not used to train its models; the retention column is the provider's own stated window for abuse monitoring or asynchronous processing, after which content is deleted.

ProviderPurposeData sentProvider retention
OpenAI (API) Language model for document classification, entity extraction, proposal drafting, and the help assistant Extracted document text, entity names, your help questions Abuse-monitoring logs up to 30 days; not used for training
Microsoft Azure AI Document Intelligence Text extraction (OCR) from uploaded documents — the default OCR service Document pages Processed in the resource's region; inputs and results deleted after 24 hours
Google Cloud Vision Alternative OCR service, where enabled for your organization Document pages Processed in memory, not persisted; not used for training

Enrichment lookups

When agents research a company that appears in your documents, they query public sources with names only — no document content is sent:

  • Brave Search API — web research on company and contact names
  • Companies House (UK) — company register lookups
  • Credly — verification of certification badges by badge identifier

Bring your own provider

Your organization can configure its own AI provider keys in the agents setup wizard. When you do, requests go to your account with that provider under your contract, and the provider is not an Entwine sub-processor for that data. Supported today: Anthropic, Azure OpenAI (your own Azure resource), Azure AI Document Intelligence and Google Cloud Vision. Anthropic and Azure OpenAI are reached only through a key you supply; Entwine holds no platform account with them.

3. What does not leave the platform

  • Your party, relationship, opportunity and engagement records stay in your tenant on our infrastructure; they are not sent to AI providers unless you upload a document or ask the help assistant a question containing them.
  • Nothing an AI service extracts is written into your workspace until a person in your organization reviews and approves it.
  • Provider credentials you supply are encrypted at rest and never appear in logs.

4. Questions

For a signed data processing agreement, our current list of sub-processors in writing, or to ask about a specific provider, contact privacy@entwineapp.io. See also our Security page.


Dark Mode NEW
Adjust the appearance to reduce glare and give your eyes a break.