Legal

Subprocessors

Last updated: 20 September 2026

Draft — not yet reviewed. Vendor list matches what the platform integrates with today; the “transfer basis” column is a standard-practice placeholder and should be confirmed against each vendor's actual current DPA/SCC documentation before this is published as binding.

Corinthian Venture Partners AS (“Corinthian”) uses the following subprocessors to provide the CRM/growth platform at app.corinthianvp.com. Each is bound by a data processing agreement imposing obligations equivalent to Corinthian's own, as described in our Data Processing Agreement.

VendorPurposeLocationTransfer basis
SupabaseDatabase, authentication, file storageEU (Frankfurt)EEA — no transfer
Vercel Inc.Application hosting, edge networkUSASCC + DPA
ResendTransactional email deliveryUSASCC + DPA
Google LLCGmail integration (only for customers who connect it)USA / globalSCC + DPA
Microsoft CorporationOutlook integration (only for customers who connect it)USA / globalSCC + DPA
Cloudflare, Inc.Bot protection (Turnstile) on the platform login page and the corinthianvp.com contact formUSA / globalSCC + DPA
Anthropic PBCClaude AI assistant — only for the individual employees who connect it, and only to the projects they already have access to (see note below)USASCC + DPA

How the Claude connection is scoped

Corinthian's platform can connect Claude to an individual project, not to the platform as a whole. The distinction matters, so it is worth stating precisely:

  • Off unless an employee turns it on. Each employee connects their own account; nothing is shared on anyone else's behalf, and an administrator can revoke any connection at any time.
  • Never wider than the employee's own access. The connection inherits that person's existing project permissions — it cannot reach a project they could not already open themselves.
  • Excludable per project. An administrator can mark an individual project as off-limits to the connection, and it is then excluded for everyone, regardless of their other permissions.
  • Read-only today. The connection can read CRM activity on the projects in scope. It cannot create, change or delete anything, and it has no access to email content, files or account credentials.

In practice this means a customer's data is only ever in scope if that customer's own project is, and only for the employees already working on it.

We will give notice on this page (and to customers directly) before adding a new subprocessor or replacing an existing one, per clause 6 of our Data Processing Agreement.

Questions about this list can be sent to aek@corinthianvp.com.