CultureAI uses a limited number of carefully selected sub-processors to help operate, maintain, and improve our platform and related services. Each sub-processor processes data only to the extent necessary to deliver their service and in accordance with our Data Processing Agreement.
The platform is hosted on Microsoft Azure and Amazon Web Services cloud servers in the UK and EU.
DataBricks (also hosted on AWS EU and synchronised to our production environment) provides dashboarding and analytics to administer, maintain, and improve the platform.
We use Anthropic (US-hosted) to process limited client data when required for analytics, to administer, maintain, and improve the platform, to support development activities, diagnose issues, and improve day-to-day business operations.
We also use OpenAI (with data stored in the EEA or Switzerland) to process a limited subset of data for pattern recognition, supporting ongoing improvement of the platform's detection and classification functions.
A limited number of other providers are used to track, diagnose, and resolve certain issues clients experience with our platform. The only personal data provided to such sub-processors is the corporate email and sometimes the IP address of the user experiencing the issue. These platforms are HotJar (AWS EU) and Sentry (US), which (i) enable us to record end-user sessions to understand user interactions with the platform and (ii) provide crash/error logs to facilitate diagnosis.
We use SendGrid (EU/US) to send general emails to clients' permitted users from the platform (e.g. reminders, welcome emails).
The following sub-processor arrangements apply to the Human Risk Management platform only.
To send simulated phishing emails to Client's permitted users from the platform — sent from various providers to enhance resilience — we make each such user's company email address available as follows: (i) for clients with Gmail Direct Injection enabled, via Microsoft Azure only; and (ii) otherwise, via Microsoft Azure, Linode, and IONOS.