§ 01What this list is
1.1
This page lists third parties that process personal data on behalf of CommonBench in connection with the Service. It is published for transparency under UK/EU GDPR Articles 13/14 and to support Art. 28 processor diligence. It is not a claim of ISO 27001 or SOC 2 certification.
1.2
Controller contact: privacy@commonbench.ai. Primary hosting region: Singapore (Hetzner). Some subprocessors process data in the UK, EEA, or United States under their own transfer mechanisms (SCCs / adequacy).
§ 02Core subprocessors
2.1
| Provider | Purpose | Typical location | Data categories |
|---|---|---|---|
| Hetzner Online GmbH | Application hosting, storage, backups | Singapore (primary) | Account, queries, usage, logs |
| Anthropic, PBC | Large-language-model inference for chat analysis | United States | Query text, uploaded document excerpts, jurisdiction context |
| Stripe, Inc. | Subscription billing and payment processing | United States / EEA | Email, billing metadata (card data stays with Stripe) |
| SMTP / email provider (configured in production) | Transactional email (welcome, magic-link/erasure confirm, alerts) | Per provider | Email address, message content |
2.2
Voyage AI, Inc. (United States) — legal-domain embeddings for an optional hybrid retrieval arm. Query and authority text are sent to Voyage only when that arm is enabled. It is not the default production path. Any additional embedding or retrieval provider will be named here before activation.
§ 03Optional analytics
3.1
| Provider | Purpose | Consent |
|---|---|---|
| Google Analytics (Google LLC) | Aggregated product analytics | Loaded only after Accept on the cookie banner; declined by default |
| Google Ads (conversion tags, when configured) | Measure subscription conversions | Same consent gate as analytics |
§ 04Changes
4.1
Material additions of subprocessors that process personal data will be reflected on this page. Where required by a customer DPA, we will provide advance notice per that agreement.
§ 05DPAs and further diligence
5.1
A customer Data Processing Agreement (controller → CommonBench as processor for firm seats, or CommonBench → customer tooling) is available on request. Email privacy@commonbench.ai with subject “DPA request”.
5.2
We do not claim ISO 27001 or SOC 2 certification on this page. Security controls in production are described accurately in the Privacy Policy §08 and SECURITY.md.
Data Protection — CommonBench
privacy@commonbench.ai
© 2026 CommonBench. All rights reserved.