| Document owner | Director (data-protection lead) |
| Version | 1.1 |
| Effective date | 21 September 2026 |
| Next review | Quarterly, and on any sub-processor change |
| Classification | Public — published at www.suitxen.co.uk/legal/sub-processors; also provided to controllers on request |
1. Purpose
This register lists the sub-processors Suitxen Ltd engages to deliver its service, the personal data each processes, where they are located, and the safeguards that apply. It supports Suitxen’s obligations under Article 28 of the UK GDPR and is published at www.suitxen.co.uk/legal/sub-processors and made available to customer firms (controllers).
“Processing role” indicates whether a provider supports the processor pipeline (handling customer firms’ client data on their instructions) or controller operations (Suitxen’s own business, staff and marketing data) — or both. For controller-operations data, most providers act as Suitxen’s processors under Article 28; a small number act as independent controllers for limited purposes of their own, noted on the relevant row. “Sub-processor” is used in this register for convenience across roles, and the Article 28(2) and 28(4) sub-processor obligations apply to the processor-pipeline role.
2. Register
| Sub-processor | Service / purpose | Personal data processed | Processing role | Location | Transfer mechanism & safeguards |
|---|---|---|---|---|---|
| Supabase | Database, backend & file storage | Encrypted/pseudonymised client data; firm user accounts | Processor pipeline + Controller ops | EEA — project hosted in the AWS Europe (Ireland) region (eu-west-1), with automated backups held in the same region; Supabase, Inc. is US-headquartered | Data hosted in the EEA (Ireland): the routine UK–EEA transfer is covered by the UK’s adequacy regulations for the EEA, so no additional transfer safeguard is required for hosting; the EU SCCs with the UK Addendum incorporated in Supabase’s DPA cover any residual US access (e.g. support) |
| Vercel | Application hosting & delivery (Next.js) | Transient request/usage data; no long-term client data store | Processor pipeline + Controller ops | US / global edge network; serverless function region set to London (lhr1) | EU SCCs with the UK Addendum incorporated in Vercel’s DPA; UK (London) function region selected so processing stays local where possible. Vercel also provides the site’s cookieless web analytics (Vercel Web Analytics) — aggregate statistics only, visit identifier discarded within 24 hours |
| Clerk | User authentication & identity | Firm users’ account identifiers, email addresses | Controller ops (accounts) | US | EU SCCs with the UK Addendum incorporated in Clerk’s DPA |
| Google (managed identity) | Staff single sign-on to business and sub-processor systems (managed Google identity) | Staff account identifiers and authentication metadata (no client data) | Controller ops (staff identity) | US / global (UK–EU data-centre options) | EU SCCs with the UK Addendum incorporated in Google’s data-processing terms (primary basis); Google is also DPF-certified including the UK Extension (UK–US Data Bridge), recorded as an additional basis and checked against the live list at each quarterly review |
| Anthropic | AI model provider (drafting) | Pseudonymised working content; no direct client identifiers | Processor pipeline | US | EU SCCs with the UK Addendum incorporated in Anthropic’s Commercial Terms / DPA. Under those terms, API inputs and outputs are not used for model training, and backend copies are deleted automatically (typically within 30 days, subject to the limited retention exceptions in Anthropic’s terms, such as trust-and-safety review and legal requirements); a zero-data-retention arrangement is available for eligible agreements and is being pursued for Suitxen’s account. The retention and data-use terms applying to Suitxen’s account — and the production models and endpoints in use — are recorded, with the date checked, in the internal vendor inventory and re-verified at least annually. Pseudonymisation of client content before submission is the key supplementary measure |
| Zoho | Business email & shared mailboxes | Business-contact correspondence only (no retail-client data) | Controller ops | EU data centres (Amsterdam / Dublin); UK data centre available from 2026 | EEA hosting is covered by the UK’s adequacy regulations for the EEA; the EU SCCs with the UK Addendum incorporated in Zoho’s DPA cover any US group access; UK data residency will be adopted, and this row updated, once Zoho’s UK data centre is available |
| Stripe | Payments & billing | Firm billing-contact & payment data | Controller ops | Global — payment data is processed by the Stripe group in the US and other regions (Stripe offers no customer-selectable data residency); UK and Irish contracting entities | Suitxen contracts with Stripe’s UK and Irish entities (Stripe Payments UK Ltd, FCA-authorised for regulated payment services, and Stripe Payments Europe Ltd); onward transfers within the Stripe group, including to Stripe, Inc. (US), are under Stripe’s DPA on the EU SCCs with the UK Addendum (primary basis, consistent with section 3); Stripe is also DPF-certified including the UK Extension (UK–US Data Bridge), recorded as an additional basis and checked against the live list at each quarterly review. Stripe processes payment data as Suitxen’s processor and also acts as an independent controller for its own fraud-prevention and regulatory-compliance purposes, per Stripe’s privacy documentation |
| Resend | Transactional email (system notifications) | Recipient email address, message metadata | Controller ops | US | EU SCCs with the UK Addendum incorporated in Resend’s DPA |
| Sentry | Error monitoring & logging | Technical logs; server-side PII scrubbing configured to minimise personal data | Processor pipeline + Controller ops | EU (Germany) — Sentry’s EU data-residency region (Frankfurt) selected for Suitxen’s organisation; Sentry (Functional Software, Inc.) is US-headquartered | Data hosted in the EEA (Germany): the routine UK–EEA transfer is covered by the UK’s adequacy regulations for the EEA; the EU SCCs with the UK Addendum incorporated in Sentry’s DPA cover any residual US access (e.g. support); server-side PII scrubbing enabled as a supplementary measure |
| Accountant / payroll provider (an independent controller when providing professional services) | Accounting & payroll | Staff/contractor & billing data | Controller ops (staff) | UK | No international transfer — processed in the UK under engagement terms |
Excluded providers: Cloudflare (email DNS only) and Bitdefender GravityZone (endpoint security on Suitxen’s own systems) do not process customer firms’ client data and are therefore not sub-processors; both are recorded in the internal vendor inventory and, for GravityZone, in the Information Security & Access Control Policy.
Development contractors: Suitxen’s overseas development contractors are individuals engaged under written contracts with binding confidentiality and information-security obligations. They process only under Suitxen’s authority and documented instructions (Article 32(4) UK GDPR) and have no routine access to live client personal data. Because they are independent contractors located outside the UK, a contractor acts as a sub-processor of Suitxen if and when they access production personal data, and any such exceptional access is a restricted transfer under Chapter V UK GDPR. It is permitted only once, for that contractor: (i) the ICO International Data Transfer Agreement (VERSION A1.0) at Schedule 1 of the contractor agreement has been executed with its tables completed for the engagement; (ii) the Article 28 processing terms at Schedule 2 of that agreement apply; (iii) a transfer risk assessment has been completed; and (iv) the affected customer firms have been given the notice-and-objection process in DPA clause 5.2. Each access is approved in writing by the data-protection lead, limited to a named individual and task, time-limited, logged and revoked on completion. No such access has been granted to date; this register and the Overseas Development & Data Access Statement will be updated when the package is first executed.
Verification records: The signed data-processing terms, security due-diligence records, the transfer mechanism actually incorporated in each provider’s terms, and dated Data Bridge/DPF status checks for each provider are held in Suitxen’s internal vendor inventory; each entry in this register is checked against that inventory at every quarterly review, and summaries are available to controllers on reasonable request.
3. International transfers
Where a sub-processor hosts the data in the EEA (currently Supabase, Zoho and Sentry), the routine UK–EEA transfer is covered by the UK’s adequacy regulations for the EEA and no additional safeguard is required for that hosting; the provider’s contractual mechanism below covers any residual access from outside the EEA. Otherwise, where a sub-processor is outside the UK, Suitxen relies on either the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK International Data Transfer Addendum — the mechanism actually incorporated in that provider’s terms, as recorded above — as the primary documented transfer mechanism, supported by a transfer risk assessment and supplementary measures — in particular encryption and the pseudonymisation of client data before AI processing. Several US providers are also self-certified under the UK Extension to the EU–US Data Privacy Framework (the UK–US Data Bridge), which provides an alternative adequacy basis; where this applies it is noted against the provider above. Suitxen deliberately keeps the SCCs or IDTA as the primary basis for every provider, rather than relying on the Data Bridge alone, so that lawful transfers do not depend on the continuing validity of any adequacy decision. Each provider’s DPF status is checked against the live list at dataprivacyframework.gov at the point of reliance and re-checked at each quarterly review. Where a provider offers UK/EU data residency, that option is preferred; the register records whether it has been selected.
4. Change & notification process (Article 28(2))
Customer firms are entitled to be informed of intended changes to sub-processors and to object. Suitxen’s process:
- Any proposed new or replacement sub-processor is assessed under the onboarding checklist (section 5) before engagement.
- Affected customer firms are given at least 30 days’ advance notice of the intended change — by updating the published register page and by notification within the platform — and may raise a reasoned objection during that period.
- If an objection cannot be resolved, the parties follow the mechanism in the Data Processing Agreement.
- On the change taking effect, this register is updated, version-incremented, and re-approved.
5. New sub-processor onboarding checklist
Before engaging a new sub-processor, confirm and record:
- What personal data it will process, and that the data is minimised to what is necessary.
- Its location(s) and whether a UK/EU residency option is available and selected.
- A written data-processing agreement / Article 28 terms are in place.
- An appropriate international-transfer mechanism is in place where required, with a transfer risk assessment.
- Its security posture (certifications, encryption, breach commitments) has been reviewed.
- Customer-firm notification has been given under section 4 for every new or replacement sub-processor (the notice is not limited to “material” changes).
6. Review and approval
This register is a living record, reviewed quarterly and whenever a sub-processor changes. It is version-controlled and approved by the data-protection lead.
Document control: version 1.1, approved by the Director (data-protection lead) on 21 September 2026. Approval records are held internally. From first publication of this register, any change to its text is issued under an incremented version identifier with a change-history entry; published or accepted versions are archived and never overwritten.