Cursiv

Sub-processors

Everyone who handles customer data on our behalf. Six of them, each named with what actually leaves this system — not a category, the thing itself.

Last updated . Material changes are announced to workspace owners by email before they take effect.

1The list

Twilio SendGrid

United States

Delivers invitations, reminders, receipts and account email.

What leaves: Recipient name and email address, the subject line of the envelope, and the signing link.

Cloudflare R2

Configurable at the bucket. Confirm the jurisdiction of your bucket before relying on this line.

Stores uploaded documents, signature images and sealed records.

What leaves: The documents themselves and everything placed on them.

Paystack

South Africa and Nigeria

Takes card payments for credits.

What leaves: Billing name, email and the amount. Card details are entered on Paystack and never reach this system.

Google Ads, Meta and Microsoft Advertising

United States, and for Google also Ireland

Told that an advert they showed produced a customer, so we know which advertising to keep paying for.

What leaves: The click identifier that platform itself placed in the link, and the fact that the person who clicked it opened an account. Sent once, by our server, at that moment. No name, email or document.

Only ever applies to someone who arrived by clicking one of our adverts. No advertising script runs on the site, so nothing is sent when a page is merely read.

OpenRouter, and the model provider it routes to

United States

Reads a document to propose who signs where, when a workspace asks it to.

What leaves: Extracted text only — never the document file. Names and other personal information appearing in that text are included.

Off unless an API key is configured, and the screen says so before it runs.

IntelliDesk

Widget served from intellidesk.co; help requests and screenshots are held in a Convex deployment in AWS eu-west-1 (Ireland).

The help widget: lets a person open a support request from inside the product.

What leaves: What Cursiv sends it: when you are signed in, your name, email address and workspace plan; on every page, the name of the screen you are on with any link token or record id replaced (for example /sign/[token]) — never the query string or the full address. Whatever you type into a help request goes to it, and so does a screenshot if you attach one; a screenshot shows whatever is on your screen at that moment, which can include a document. Because the widget loads from IntelliDesk, your browser also contacts it directly, so it sees your IP address and browser details.

Loads on every page, including the signing page. It is not given the documents themselves, and its diagnostics are switched off.

2What is not on this list

There is no analytics provider, no advertising network, no customer data platform and no session recorder. There is one support tool, IntelliDesk, listed above: it is not given your documents, but a screenshot a person attaches to a help request shows whatever is on their screen, which can include a document. If another is added it appears here in the same change that adds it.

The database is ours and self-hosted. It is not a managed service and no third party administers it.

3Cross-border transfer

All of them are outside South Africa or operate partly outside it, which engages section 72 of POPIA. The basis we rely on is set out in the privacy policy. If your organisation requires data to remain in the Republic, the storage bucket’s region is configurable but email and analysis are not — tell us before you buy rather than after.

4Notice of change

We will tell workspace owners by email before a new sub-processor begins handling customer data, with enough notice to object. If you object and we cannot resolve it, you may close your workspace and take a refund of unspent credits.

Sub-processors · Cursiv