Subprocessor list
Last updated ·
The third parties that process data on our behalf, what each one is there for, and how clients are told before the list changes.
What a subprocessor is
A subprocessor is a third party that processes data on our behalf while we are processing it on yours. Hosting, transactional email and the platform an automation runs on are all subprocessors; a tool we use that never touches your data is not. This page is the register the data processing terms refer to, and it is the same register for every client unless an engagement says otherwise.
What this website uses
The site you are reading uses hosting, transactional email, and backup storage from the list below. It runs no analytics and sets no cookies; the cookie policy sets that out in full. What you type into the enquiry form goes to those three and to nobody else, and nothing at all is sent before you submit it. The backup is a nightly copy of the enquiry records, held for thirty days and then deleted.
Where processing happens
Automations are hosted in Cloudflare's global edge network. The site and its data run on infrastructure distributed across Cloudflare's worldwide points of presence rather than a single named server or region — this is a deliberate feature of the hosting, not a placeholder.. Where a subprocessor processes data outside the client’s own jurisdiction, transfer safeguards such as the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), together with the UK International Data Transfer Addendum where a transfer originates in the United Kingdom are put in place. The data processing terms state the mechanism in full; this page names the parties rather than restating it.
Document and language processing
Where document reading, classification or drafting is part of an engagement, null is the provider. The client is told before it is used which provider processes the data, whether that provider retains content, and whether content may be used to train a model. Our default is providers and settings that exclude client data from training.
How we tell you about changes
Clients are notified before a new subprocessor with access to their data is introduced, and may object on reasonable grounds; if an objection cannot be resolved, we will set out what alternatives are available for that engagement. Removing a subprocessor, or replacing one with another that has no access to client data, is published here rather than notified individually.
The current list
Each row is a role that has to be filled rather than a vendor we are attached to. Where a row is still a bracketed placeholder, that decision has not been made or recorded yet, and this register is not final until every row names a real provider.
| Purpose | Provider | Where it applies |
|---|---|---|
| Website and application hosting | Cloudflare, Inc. (global edge network) | This website |
| Transactional email — enquiry notifications and auto-replies | Brevo (Sendinblue SAS) | This website |
| Nightly backup of the enquiry database | GitHub, Inc. (GitHub Actions artifact storage) | This website |
| Customer relationship management | Not used | Enquiries and client records |
| Meeting scheduling | Not used | Enquiries |
| Website analytics | Not used | This website |
| Automation platform used to build and run client workflows | Not used | Client engagements |
| Document reading, classification and drafting | Not used | Client engagements, where used |
Every provider named above is bound by written terms no less protective than our data processing terms, and processes data only on documented instructions. Where a row reads “Not used”, nothing is sent to anybody for that purpose.