Sub-processors

Third parties engaged by Tinct to process personal data on behalf of its customers

Tinct SAS · Last updated September 2026

This page lists the Sub-processors that Tinct SAS engages to help deliver its service. It forms part of the Tinct Data Processing Agreement and is the authoritative, up-to-date list referenced therein.

Change notifications. Tinct will notify customers of any intended addition or replacement of a Sub-processor at least thirty (30) days in advance, giving customers the opportunity to object on reasonable data-protection grounds. To receive these notifications, contact contact@tinct.ai.

Each Sub-processor is engaged under a written agreement (a DPA and/or Standard Contractual Clauses where applicable) imposing data-protection obligations equivalent to those in the Tinct DPA.

Current Sub-processors

Core infrastructure & AI

Sub-processor

Role

Data processed

Location

Transfer mechanism

Amazon Web Services (AWS)

Cloud infrastructure (compute, storage, database, networking)

All platform data (encrypted at rest and in transit)

EU (eu-west-1, Ireland)

EU — no transfer

Amazon Bedrock (AWS)

AI content generation (LLM inference, Anthropic Claude models served by AWS)

Company-level prompt data (no personal data in standard use); not retained by AWS or the model provider, not used for training

EU (EU inference profiles)

EU — no transfer

Cloudflare

Edge compute, KV store, CDN, DNS

Visitor IP addresses, snippet requests

Global edge / EU at rest

SCCs / adequacy

Billing & communications

Sub-processor

Role

Data processed

Location

Transfer mechanism

Stripe

Payment processing, subscription management

Billing contact data, payment method tokens

USA / EU

SCCs + EU–US DPF

Brevo (brevo.com)

Transactional email delivery

Email address, email content

EU

EU — no transfer

Data enrichment & crawling

Sub-processor

Role

Data processed

Location

Transfer mechanism

Brightdata

Crawler infrastructure powering TinctBot

Public web page content (no personal data targeted)

USA / Global

SCCs

IPInfo

IP enrichment (company attribution)

IP addresses (company-level lookup)

USA

SCCs

LogoDev

Company logo retrieval

Company domain (no personal data)

USA

SCCs

Brandfetch (Brandfetch SA)

Company logo and brand asset retrieval

Company domain (no personal data)

Switzerland; hosted on AWS

Adequacy decision (Switzerland); SCCs for onward transfers

Analytics, security & internal tooling

Sub-processor

Role

Data processed

Location

Transfer mechanism

PostHog

Product analytics (platform usage)

Platform user behaviour (pseudonymous)

EU (EU Cloud)

EU — no transfer

Featurebase (CORDNET OÜ)

In-app feedback widget and public feedback portal (feedback.tinct.ai)

Feedback content submitted by platform users, browser and IP metadata; users are not identified to the widget unless they enter their email

EU (Estonia; hosted in the Netherlands, Germany and Ireland)

EU; SCCs for the vendor’s own US sub-processors

Google Cloud (reCAPTCHA)

Bot detection / form protection

Browser signals, IP

USA / Global

SCCs + EU–US DPF

Attio

Internal CRM (Tinct customer management)

Tinct’s own customer contact data

EU

EU — no transfer

Axeptio

Consent management

Consent preferences

EU

EU — no transfer

Google Tag Manager

Tag management / orchestration (marketing website only)

Browser signals, IP

USA

SCCs + EU–US DPF

Authentication (social login, user-initiated)

Sub-processor

Role

Data processed

Location

Transfer mechanism

Google (OAuth)

Social login provider

OAuth token, email, name

USA / Global

SCCs + EU–US DPF

Microsoft (OAuth)

Social login provider

OAuth token, email, name

USA / Global

SCCs + EU–US DPF

LinkedIn (OAuth)

Social login provider

OAuth token, LinkedIn ID

USA / Global

SCCs + EU–US DPF

Customer-enabled integrations

The services below are not engaged by Tinct on its own initiative. They are activated by the customer, on the customer’s own account with that provider, through an authorisation the customer can revoke at any time. Tinct exchanges data with them only on the customer’s instruction, and stores the associated access tokens encrypted. The customer’s contract with the provider governs that provider’s processing.

Integration

Role

Data exchanged

Location

Transfer mechanism

HubSpot

CRM synchronisation, lead forms

Company and contact records, campaign engagement events, lead-form submissions

USA / EU

SCCs + EU–US DPF

Salesforce

CRM synchronisation

Company and contact records, campaign engagement events

USA / EU

SCCs + EU–US DPF

Google Ads

Advertising campaign synchronisation (read-only)

Campaign names, landing URLs, ad copy, keywords

USA / Global

SCCs + EU–US DPF

LinkedIn Ads

Advertising campaign synchronisation and daily metrics (read-only)

Campaign names, landing URLs, ad copy, aggregated performance metrics

USA / Global

SCCs + EU–US DPF

RudderStack (customer’s own data plane)

Visitor event forwarding

Pseudonymous visitor events, sent to the endpoint the customer configures

Customer-defined

Customer’s own agreement

Several Sub-processors located in the United States (including Stripe, Google, Microsoft and LinkedIn) are additionally certified under the EU–US Data Privacy Framework, providing a further adequacy-based safeguard for transfers outside the EEA.

Change log

September 2026.Added Brandfetch (company logo retrieval) and Featurebase (in-app feedback). Added the “Customer-enabled integrations” section for transparency; these providers are activated by customers and are not Sub-processors engaged by Tinct. Clarified that Amazon Bedrock serves Anthropic Claude models within EU inference profiles without retention or training use.

June 2026.Initial publication.

Tinct SAS — 5 Rue Pleyel, Bureau 3, 93200 Saint-Denis, France · RCS 101 730 018 R.C.S. Bobigny · contact@tinct.ai