Sub-processors
Last updated: 31 August 2026
This page is the canonical, always-current list of the third parties that process personal data on CrossTenant’s behalf. It is referenced by the Data Processing Agreement and by our privacy policy, and it is the list that governs if those documents ever fall out of step with it.
The short version. CrossTenant deliberately limits what it stores. The console reads live from Google’s APIs, shows the result to your engineer, and does not retain Google Workspace content in its own server-side stores. Features that intentionally send selected information outside the console use either the named providers below or a destination that the operator configures and contracts for, such as its own SMTP provider or webhook. Each row describes the most that a CrossTenant sub-processor can receive. See the security page for what is and is not kept.
Current sub-processors
These are in use today or, where a row says so expressly, approved for a bounded use that has not yet sent data. “Personal data reached” describes the most that this sub-processor can see — not what it necessarily does see in your deployment.
| Sub-processor | Purpose | Personal data reached | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Google LLC / Google Ireland Limited | The source system. CrossTenant administers Google Workspace through Google’s APIs. Also provides Google sign-in for MSP operators. | All Workspace data the customer administrator authorises — but this data already lives with Google under the customer organisation’s own agreement with Google. CrossTenant sends nothing new to Google beyond the administrative changes your engineers make. | Per the customer organisation’s own Google Workspace data-region settings | The customer organisation’s existing agreement with Google |
| Microsoft Ireland Operations Limited (and Microsoft affiliates engaged under its DPA) | Microsoft Azure hosts the private CrossTenant console in the United Kingdom. Microsoft can also be selected as the identity provider for MSP operator sign-in. | Stored console data — authorisation credentials, operator accounts and access policy, write-audit logs, and operator-authored configuration, including joiner role templates that may contain a delegate address or signature HTML — plus live Google Workspace API data while the hosted instance handles a request. Workspace content is not retained. If Microsoft sign-in is selected, Microsoft also receives the operator’s name, email address and directory identifier. | United Kingdom (Azure UK West for customer data at rest); other locations only as permitted by Microsoft’s DPA | Microsoft Products and Services Data Protection Addendum, including the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum where an international transfer occurs |
| Microsoft Ireland Operations Limited (and Microsoft affiliates engaged under its DPA) — Azure Communication Services Email | Email delivery for CrossTenant-hosted invitations, scheduled reports with PDF attachments, threshold alerts and approval notifications. The service and sending identity are provisioned. Its initial use is limited to CrossTenant Ltd’s own controller-side internal/operator canary; no Managed Organisation data may be sent without its separate documented authorisation. SMTP credentials have not yet been loaded into the hosted console, and no email of any class has yet been sent through it. | Recipient distribution lists, subject lines, message bodies, attachments and delivery metadata. Messages use one To header, so ACS and each recipient receive the full distribution list. Depending on the email, this can include operator or requester email addresses; managed-organisation names and identifiers — including, in a cross-tenant digest, every managed organisation in the operator’s account whether it has matching events, is clean or is unreachable — security-posture counts; Workspace end-user email addresses and audit-event summaries; and scheduled-report PDFs containing Google-returned person and Workspace metadata such as per-user names and email addresses, delegate and forwarding addresses, Shared Drive names and document titles. Attachment filenames include the tenant identifier, report type and date. An invitation includes a single-use acceptance link, the permitted identity provider and its expiry time; the invitation itself contains no Google Workspace content. | UK data location; other locations only as permitted by Microsoft’s DPA | Microsoft Products and Services Data Protection Addendum, including the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum where an international transfer occurs |
| Anthropic PBC | Optional AI features only: report executive summaries and the in-console assistant. Off unless enabled. | The operator’s typed question plus sanitised configuration and posture context — settings values, counts, and summary statistics. A server-side redaction guard removes mailbox and file content before anything is sent, and a test fails the build if raw content can reach this boundary. | United States | EU Standard Contractual Clauses as supplemented by the UK International Data Transfer Addendum, via Anthropic’s Data Processing Addendum |
| Cloudflare, Inc. | Hosting, DNS and edge network for the crosstenant.com website; authenticated access control and network routing for the private CrossTenant console. | Website visitors’ IP addresses, user agents and requested pages. For the console: request metadata, the identity used at the access gate, and console request and response data while Cloudflare proxies it. Console API responses are marked non-cacheable and are not stored in Cloudflare’s content cache. | United States (global edge) | UK Extension to the EU–US Data Privacy Framework; EU SCCs with the UK Addendum under Cloudflare’s DPA |
Email delivery
Invitations, scheduled reports, threshold alerts and approval notifications are sent through an SMTP service configured for your instance. On an instance you run yourself, that is your own mail provider and it is not a CrossTenant sub-processor — you choose it and you contract with it. On a CrossTenant-hosted instance we choose it, and it will be named in the table above before it processes anything. Email delivery is optional: with no SMTP configured, every class of hosted outbound email is off.
Announced — not yet in use
We publish sub-processors before they start processing, so the notice period in the DPA runs ahead of the change rather than after it. Nothing in this section processes any data today: the backup storage below is selected but not yet provisioned. Notice of each row runs from the date this page is first published naming it. Each row moves into the table above on the date it goes live, and we will email each existing Customer’s billing contact when it does.
| Sub-processor | Purpose | Personal data reached | Location | Notice given |
|---|---|---|---|---|
| Microsoft Ireland Operations Limited (and Microsoft affiliates engaged under its DPA) — Azure Blob backup storage | Encrypted off-host backups for the hosted console. A separate Azure subscription is reserved for this purpose, but no storage account exists and no backup data has been uploaded. Before use we will fix and publish the UK region and retention controls, encrypt backup contents before upload, prove a restore, and move this row into the current table. | Encrypted backup contents plus the limited object metadata Azure needs to store and retrieve them, such as opaque object identifiers, sizes and timestamps. Workspace content would not be readable by the storage service. | United Kingdom (specific Azure region to be fixed before use) | From first publication of this page |
How we notify you of changes
- For an existing Customer, we give at least 30 days’ notice before an addition or replacement to the authorised list begins processing personal data under that Customer’s DPA. Notice is given by updating this page and emailing the Customer’s billing contact.
- A provider already listed as Current when a Customer contracts is part of the disclosed list authorised at signing; it is not a later change subject to a new waiting period.
- Within that period you may object on reasonable, documented data-protection grounds. We will work with you in good faith to find an alternative — for example, disabling the optional feature the sub-processor supports. If we cannot resolve it, you may terminate the affected part of the subscription without penalty and receive a pro-rata refund of prepaid fees.
- Where a change is needed urgently to protect the security or availability of the service, we may make it sooner and tell you as soon as we can, with the reason.
- Every sub-processor is engaged under a written contract imposing data-protection obligations no less protective than those in our own DPA, and we remain fully liable to you for its performance.
What is deliberately not on this list
There is no analytics provider, no advertising or marketing platform, no session-replay or error-tracking service that receives console data, no customer-data warehouse, and no third-party support desk with access to your console. There is no breach-exposure lookup service: that feature is designed but not built, and if it is built it will appear here first.
Questions
Data-protection questions, including sub-processor objections: privacy@crosstenant.com. Related documents: Data Processing Agreement · Privacy policy · Security · Terms of Service.