Snapshot 81071
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to navigationSkip to main content Critical Cloud Critical Cloud deliver modern, mission-critical cloud operations that give SMBs speed, scale, and confidence - while relentlessly lowering cost and complexity. team@criticalcloud.ai Privacy PolicyOpens in new tab Here you can find our compliance artifacts, request documentation, and view high-level details on controls we adhere to. To access sensitive documents, please click the "Request access" button at the top of the page and complete the request form. This access will also enable the Trust Center AI feature, allowing you to query our documentation. Compliance ISO 27001:2022 UK Cyber Essentials UK Cyber Essentials Plus GDPR Resources View all Cyber Essentials Plus Certificate ISO27001 Certificate NHS Data Security and Protection Toolkit Data Protection Registration Certificate Controls View all Infrastructure security Protecting against physical and environmental threats Data masking Data leakage prevention Organizational security Intellectual property rights Information security for use of cloud services Legal, statutory, regulatory and contractual requirements View 1 more Organizational security control Product security Information security for use of cloud services Internal security procedures Internal Audit - General Internal Audit Program Management review inputs Data and privacy Data masking Data leakage prevention Subprocessors View all Atlassian Corporation Plc • Collaboration European Union (Germany) HubSpot • Marketing European Union (Germany) Customer relationship management (CRM) and marketing automation Qwilr Pty Ltd • Proposals and Order forms EU Slack • Collaboration European Union (Germany) Updates View all Privacy Sub-processor list update Published September 23, 2026 We've updated our sub-processor list. The full list is at https://trust.criticalcloud.ai/subprocessorsOpens in new tab Added or Amended Sub-processor Purpose Location Anthropic AI assistant (Claude) USA OpenAI AI assistant (ChatGPT) USA Fathom Meeting recording and notes USA Confluence Document management EU Microsoft SharePoint Document storage and collaboration EU Supabase Application database hosting EU Vercel Application hosting EU Netlify Application hosting EU Squadcast Incident alerting and on-call EU Qwilr Proposals EU Ruddr Project and resource management EU SquaredUp Dashboards and reporting EU Removed AWS and Microsoft Azure. We don't hold customer personal data in our own AWS or Azure environments. Customer-owned AWS and Azure accounts that we manage remain covered by the customer's own terms with those providers. AI and meeting tools Anthropic and OpenAI help our engineers with troubleshooting, analysis and documentation. Customer data is used only where needed to deliver our services, in line with clause 6 of our Data Processing Agreement (DPA). Customer data is not used to train AI models. Safeguards Each sub-processor is bound by data protection terms that give customer data the same level of protection as our DPA. Transfers to the US are protected by the UK-US Data Bridge / UK IDTA / UK Addendum. Transfers to the EU are covered by UK adequacy regulations. Your rights Under clause 7 of our DPA, you can object to a new sub-processor on reasonable data protection grounds within 30 days of this notice. Email privacy@criticalcloud.ai. We'll work with you to resolve any objection. For example, we can agree not to record your meetings in Fathom, or not to use AI tools with your data. Existing agreements This update does not change any agreement we already have with you. Where we have agreed not to use particular tools with your data, that agreement stays in place and continues to apply. The list shows the services we may use across our customers, not necessarily the ones used for your account. If you're unsure what applies to you, email privacy@criticalcloud.ai.