Legal
Sub-Processor List
Transparency about the third-party processors we use to deliver our services, in accordance with GDPR Article 28.
Last updated: February 15, 2026
01Sub-Processors
The following table lists all third-party sub-processors that process personal data on behalf of TrustNexus. Each sub-processor operates under a Data Processing Agreement (DPA) that ensures compliance with GDPR requirements. We notify users of any changes to this list.
SumSub
PurposeKYC/KYB identity verification, document verification, biometric liveness checks, AML/sanctions screening
Data CategoriesIdentity data, identity documents, biometric data (liveness), AML screening results
CountryUK / EU
SafeguardsStandard Contractual Clauses (SCCs), SOC 2 Type II, ISO 27001
SendGrid (Twilio)
PurposeTransactional email delivery for notifications, verification emails, and system alerts
Data CategoriesEmail addresses, notification content
CountryUnited States
SafeguardsStandard Contractual Clauses (SCCs), SOC 2 Type II
AWS S3
PurposeSecure storage of identity documents and business documents
Data CategoriesIdentity documents, business documents
CountryEU (eu-west-1)
SafeguardsStandard Contractual Clauses (SCCs), ISO 27001, SOC 2
Keycloak
PurposeAuthentication and identity management including session management and role-based access control
Data CategoriesUser credentials (hashed), session tokens, roles and permissions
CountrySelf-hosted (EU)
SafeguardsInternal infrastructure, no third-party data transfer
02Changes to Sub-Processors
We will notify existing customers at least 30 days before adding or replacing a sub-processor. If you object to a new sub-processor, you may terminate your agreement with us in accordance with our Terms of Service.
03Questions
For questions about our sub-processors or data processing practices, contact our Data Protection Officer at dpo@trustnexus.eu.