To run Karibu we rely on the third-party services below ("sub-processors"). Each one is bound by a Data Processing Agreement (DPA) or equivalent contract, and each is listed here with what it does, the categories of data it touches, and where it is hosted. This is the granular companion to our Privacy Policy and Security pages.
30 days notice. We give at least 30 days notice before adding or materially changing any sub-processor. To be notified, email
privacy@usekaribu.com and ask to join the sub-processor changelog. Enterprise customers can request a counter-signed DPA from the same address.
LinkedIn — not a sub-processor
We deliberately do not list LinkedIn as a sub-processor. We never scrape LinkedIn at scale and never store LinkedIn page content centrally. The Karibu Chrome extension reads only what you, the customer, are already viewing in your own LinkedIn session; programmatic enrichment that involves public profile context is routed through Apify actors, never a direct Karibu request to LinkedIn (see ADR 0001). No customer or prospect data is sent to LinkedIn by Karibu.
International transfers
Customer data is primarily stored in the EU (Supabase, Frankfurt). Where a sub-processor operates outside the EEA — chiefly the AI and identity providers above — transfers rely on Standard Contractual Clauses and, where offered, the provider's EU data region or zero-retention terms. We minimise what leaves the EU: payloads to AI providers carry only the data needed for the task, and inference inputs are never used to train third-party models.