← Chronox

Sub-processors

Last updated July 30, 2026 · Chronox is operated by Foundation Digital LLC. This is the complete, current list of third parties that process customer data on our behalf.

Chronox requires every sub-processor below to process data only to provide its service to Chronox - never for advertising, and never to train its own models on your workforce's data. That is the standard we impose in our data-processing terms and the condition on which each vendor is engaged; we are completing and maintaining the individual vendor data-processing agreements that record it. Vendors marked biometric path can touch biometric identifiers; all others are architecturally outside the biometric path.

Sub-processor change notice · posted July 30, 2026

The anti-spoofing (liveness) check has moved from the optional AWS browser flow to a server-side check by Luxand, Inc. Since July 29, 2026, the "is this a live person, not a photo or a screen" verdict on each face punch is produced on Chronox's servers by Luxand, Inc. (Alexandria, Virginia, USA) using the same single camera image that already verifies identity. The image is sent to Luxand with no name, employee ID, or company identifier attached - Luxand cannot connect it to a person. Luxand uses it only for that check, never to train its software, and deletes it within 90 days under its published policy. Face matching is unchanged (Amazon Rekognition), and the AWS cloud liveness flow remains available as a certified per-company alternative.

Section 8.1 of the Chronox Data Processing Addendum entitles customers to at least 30 days’ advance notice of a biometric-path sub-processor change and to object on reasonable grounds. This change took effect on July 29, 2026, before a full 30-day notice period had run - a departure from that commitment, and we are stating it rather than papering over it. What we have done about it: the image Luxand receives carries no identifiers of any kind; the objection right under section 8.2 remains open through August 29, 2026; and the change is reversible per company - any customer that objects can be moved to the certified AWS liveness tier immediately while we resolve the objection. The updated worker consent, notice at collection, retention policy, and DPA (v6, which asks for your re-acceptance) were published July 30, 2026. Objections and questions: privacy@chronoxapp.net.

Sub-processor change notice · posted July 26, 2026

Reverse geocoding has moved from Mapbox to Amazon Web Services. Since July 26, 2026, the lookup that turns a punch’s GPS coordinates into a readable place name is performed by Amazon Location Service (Oregon, us-west-2) instead of Mapbox. Only a coordinate pair is sent — no name, no worker identifier, no company identifier, and no biometric data. Mapbox no longer receives any Chronox data.

No new company gains access to your data, and nothing leaves the United States. AWS is already a Chronox sub-processor and already appears in the table below; this moves one function to a provider you have already approved, and removes Mapbox from the list entirely. Processing stays in the United States (Oregon), the same region as our existing AWS services.

Section 8.1 of the Chronox Data Processing Addendum entitles customers to at least 30 days’ advance notice of a sub-processor change and to object on reasonable grounds. This change took effect on the same day the notice was posted rather than after the 30-day period, which is a departure from that commitment and we are stating it rather than papering over it. No new company gained access to any data — AWS was already an authorised sub-processor — and one vendor was removed. The objection right under section 8.2 remains open through August 25, 2026; if you object we will work with you on an alternative configuration, and the change is reversible. Objections and questions: privacy@chronoxapp.net. The table below reflects the sub-processors in use today.

Biometric path

Sub-processorServiceData touchedLocation
Amazon Web Servicesbiometric pathFace matching (Amazon Rekognition). All Chronox face matching runs here today. The certified cloud liveness tier (Rekognition Face Liveness) is the optional per-company alternative to the standard Luxand check below.Transient face images at punch/enrollment, face-geometry descriptors (one isolated collection per customer company), and - only where the certified cloud liveness tier is enabled, which is not currently enabled for any company - short liveness video frames streamed from the worker's browser.us-west-2 (Oregon, USA)
Luxand, Inc.biometric pathAnti-spoofing (liveness) - the standard check on every face punch and enrollment since July 29, 2026. A server-side verdict that a live person, not a photo or screen, is in front of the camera, produced from the same single image that verifies identity.The transient punch/enrollment face image only, sent server-to-server with no name, employee ID, or company identifier attached - Luxand cannot connect an image to a person. Used only to produce the liveness verdict, never to train Luxand's software; deleted by Luxand within 90 days of upload under its published policy.USA - Alexandria, Virginia (U.S.-located hosting per Luxand's published policy)
Amazon Cognito (AWS)biometric pathVends the short-lived, scoped AWS credentials a worker's browser uses to stream the certified cloud liveness check directly to AWSNo face images and no face templates are stored here. Cognito issues a temporary access key for a single liveness session; it sees the credential request, not your biometric data. Used only where the certified cloud liveness tier is enabled - not currently enabled for any company.us-west-2 (Oregon, USA)
Supabasebiometric pathDatabase, storage, authentication, edge functionsAll application data, including encrypted (AES-256-GCM) offline face-template ciphertext, consent records, punch records, deletion receipts, and - in a separate, private Storage bucket under row-level access - Photo-mode timekeeping selfies (image, event reference, timestamp), kept apart from the face-template envelope. The Photo-mode selfie bucket is not accessible to any facial-recognition sub-processor; no face-recognition vendor processes Photo-mode images.USA
Neurotechnologynot enabledVeriLook face-matching SDK for the optional on-device (offline) mode. Not currently enabled for any company, and no matching runs on it today - all face matching runs in cloud AWS Rekognition.None. No offline face templates exist. If it is ever enabled, the SDK would run entirely on the device and no data would flow to the vendor. Listed for transparency only.Vendor: Lithuania · Processing: on your devices (only if enabled)

Non-biometric services

Sub-processorServiceData touchedLocation
CloudflareWeb hosting & CDN (app.chronoxapp.net and this site), bot protectionApplication traffic in transit (TLS), standard connection logs. No stored biometric data.Global edge; USA
Google (Firebase)Push notifications; Google Sign-In where a worker chooses itDevice push tokens, notification payloads (e.g., timesheet reminders); for Google Sign-In, name/email from your Google account. No biometric or GPS data.USA
Amazon Web Services (Amazon Location Service)Reverse geocoding of punch coordinatesPunch-moment GPS coordinates only - sent without names or identifiers attachedUSA (Oregon, us-west-2)
StripeBillingCompany billing details and usage counters. No employee, biometric, or punch data.USA
AnthropicAI features (Chronox AI summaries & assistance)Timekeeping, project, and task content a user submits to the assistant - text and any images the user attaches (e.g., receipts, delivery tickets). Never face templates or any biometric identifier; API data is not used to train Anthropic's models per our commercial terms.USA
OpenAIAI features (document extraction, embeddings, some assistant tasks)Same scope as Anthropic: user-submitted text and attached document images. Never face templates or any biometric identifier; API data is not used for model training per OpenAI's API terms.USA
ResendTransactional email (invites, password resets, notices)Recipient name/email and the message contentUSA
TwilioTransactional SMS (invites, alerts)Recipient phone number and the message contentUSA
Check Technologies not enabledEmbedded payroll - only if your company enables Chronox Payroll; no company hasNone today. If a company enables Chronox Payroll, Check would receive the payroll onboarding data supplied on Check's hosted flows (bank details, withholdings, tax forms) plus hours and earnings for pay runs. No company has enabled it, so nothing has been sent. No biometric data.USA (if enabled)
Sentry not enabledCrash & error reporting - integrated in our app but switched off; no data is sentNone. The error-reporting SDK only starts when a reporting key is supplied at build time, and our production builds do not supply one, so it never runs. If we ever turn it on it is configured not to send personal data by default (sendDefaultPii=false), and we would execute a data processing agreement with Sentry first. No biometric data either way.USA (if enabled)

Employer-directed integrations (not sub-processors)

When your company connects its own accounts to export payroll or accounting data - Gusto, QuickBooks (Intuit), Square, BambooHR, OnPay - Chronox transmits the data your company selects to the provider your company chose, at its direction. Those providers process that data under your company's agreement with them, not as Chronox sub-processors. Voice entry is transcribed on your device by your phone's operating system; the audio is not sent to a Chronox vendor.

Changes to this list

Before adding or replacing any sub-processor that can touch biometric identifiers, we update this page and give customers 30 days' advance email notice with the right to object, per our Data Processing Addendum. Other sub-processor changes are posted here promptly. To receive change notifications, email privacy@chronoxapp.net with the subject "Sub-processor updates".

Related: Biometric Retention & Destruction Policy · No-Sale / No-Harvest Pledge · Privacy Policy

Vendor attribution: Face Recognition powered by Luxand.com (Luxand provides the anti-spoofing liveness check; face matching is performed by Amazon Rekognition).