Skip to content
Suitxen
Fact-find15 structured steps, information captured onceCalculation engine46 modules across six familiesRisk profilingAttitude, capacity and knowledge considered separatelyWorksheet engineWhere the case becomes the evidence
AboutSecurity & complianceBetaLog inRequest beta access
PlatformFact-findCalculation engineRisk profilingWorksheet engineAboutSecurity & complianceBetaLog inRequest beta access
LEGALPublished document

Sub-processor Register

Article 28, UK GDPR — Suitxen Ltd

v1.1 — 21 September 2026All legal documents

In this document

  1. 1. Purpose
  2. 2. Register
  3. 3. International transfers
  4. 4. Change & notification process (Article 28(2))
  5. 5. New sub-processor onboarding checklist
  6. 6. Review and approval
Document ownerDirector (data-protection lead)
Version1.1
Effective date21 September 2026
Next reviewQuarterly, and on any sub-processor change
ClassificationPublic — published at www.suitxen.co.uk/legal/sub-processors; also provided to controllers on request

1. Purpose

This register lists the sub-processors Suitxen Ltd engages to deliver its service, the personal data each processes, where they are located, and the safeguards that apply. It supports Suitxen’s obligations under Article 28 of the UK GDPR and is published at www.suitxen.co.uk/legal/sub-processors and made available to customer firms (controllers).

“Processing role” indicates whether a provider supports the processor pipeline (handling customer firms’ client data on their instructions) or controller operations (Suitxen’s own business, staff and marketing data) — or both. For controller-operations data, most providers act as Suitxen’s processors under Article 28; a small number act as independent controllers for limited purposes of their own, noted on the relevant row. “Sub-processor” is used in this register for convenience across roles, and the Article 28(2) and 28(4) sub-processor obligations apply to the processor-pipeline role.

2. Register

Sub-processorService / purposePersonal data processedProcessing roleLocationTransfer mechanism & safeguards
SupabaseDatabase, backend & file storageEncrypted/pseudonymised client data; firm user accountsProcessor pipeline + Controller opsEEA — project hosted in the AWS Europe (Ireland) region (eu-west-1), with automated backups held in the same region; Supabase, Inc. is US-headquarteredData hosted in the EEA (Ireland): the routine UK–EEA transfer is covered by the UK’s adequacy regulations for the EEA, so no additional transfer safeguard is required for hosting; the EU SCCs with the UK Addendum incorporated in Supabase’s DPA cover any residual US access (e.g. support)
VercelApplication hosting & delivery (Next.js)Transient request/usage data; no long-term client data storeProcessor pipeline + Controller opsUS / global edge network; serverless function region set to London (lhr1)EU SCCs with the UK Addendum incorporated in Vercel’s DPA; UK (London) function region selected so processing stays local where possible. Vercel also provides the site’s cookieless web analytics (Vercel Web Analytics) — aggregate statistics only, visit identifier discarded within 24 hours
ClerkUser authentication & identityFirm users’ account identifiers, email addressesController ops (accounts)USEU SCCs with the UK Addendum incorporated in Clerk’s DPA
Google (managed identity)Staff single sign-on to business and sub-processor systems (managed Google identity)Staff account identifiers and authentication metadata (no client data)Controller ops (staff identity)US / global (UK–EU data-centre options)EU SCCs with the UK Addendum incorporated in Google’s data-processing terms (primary basis); Google is also DPF-certified including the UK Extension (UK–US Data Bridge), recorded as an additional basis and checked against the live list at each quarterly review
AnthropicAI model provider (drafting)Pseudonymised working content; no direct client identifiersProcessor pipelineUSEU SCCs with the UK Addendum incorporated in Anthropic’s Commercial Terms / DPA. Under those terms, API inputs and outputs are not used for model training, and backend copies are deleted automatically (typically within 30 days, subject to the limited retention exceptions in Anthropic’s terms, such as trust-and-safety review and legal requirements); a zero-data-retention arrangement is available for eligible agreements and is being pursued for Suitxen’s account. The retention and data-use terms applying to Suitxen’s account — and the production models and endpoints in use — are recorded, with the date checked, in the internal vendor inventory and re-verified at least annually. Pseudonymisation of client content before submission is the key supplementary measure
ZohoBusiness email & shared mailboxesBusiness-contact correspondence only (no retail-client data)Controller opsEU data centres (Amsterdam / Dublin); UK data centre available from 2026EEA hosting is covered by the UK’s adequacy regulations for the EEA; the EU SCCs with the UK Addendum incorporated in Zoho’s DPA cover any US group access; UK data residency will be adopted, and this row updated, once Zoho’s UK data centre is available
StripePayments & billingFirm billing-contact & payment dataController opsGlobal — payment data is processed by the Stripe group in the US and other regions (Stripe offers no customer-selectable data residency); UK and Irish contracting entitiesSuitxen contracts with Stripe’s UK and Irish entities (Stripe Payments UK Ltd, FCA-authorised for regulated payment services, and Stripe Payments Europe Ltd); onward transfers within the Stripe group, including to Stripe, Inc. (US), are under Stripe’s DPA on the EU SCCs with the UK Addendum (primary basis, consistent with section 3); Stripe is also DPF-certified including the UK Extension (UK–US Data Bridge), recorded as an additional basis and checked against the live list at each quarterly review. Stripe processes payment data as Suitxen’s processor and also acts as an independent controller for its own fraud-prevention and regulatory-compliance purposes, per Stripe’s privacy documentation
ResendTransactional email (system notifications)Recipient email address, message metadataController opsUSEU SCCs with the UK Addendum incorporated in Resend’s DPA
SentryError monitoring & loggingTechnical logs; server-side PII scrubbing configured to minimise personal dataProcessor pipeline + Controller opsEU (Germany) — Sentry’s EU data-residency region (Frankfurt) selected for Suitxen’s organisation; Sentry (Functional Software, Inc.) is US-headquarteredData hosted in the EEA (Germany): the routine UK–EEA transfer is covered by the UK’s adequacy regulations for the EEA; the EU SCCs with the UK Addendum incorporated in Sentry’s DPA cover any residual US access (e.g. support); server-side PII scrubbing enabled as a supplementary measure
Accountant / payroll provider (an independent controller when providing professional services)Accounting & payrollStaff/contractor & billing dataController ops (staff)UKNo international transfer — processed in the UK under engagement terms

Excluded providers: Cloudflare (email DNS only) and Bitdefender GravityZone (endpoint security on Suitxen’s own systems) do not process customer firms’ client data and are therefore not sub-processors; both are recorded in the internal vendor inventory and, for GravityZone, in the Information Security & Access Control Policy.

Development contractors: Suitxen’s overseas development contractors are individuals engaged under written contracts with binding confidentiality and information-security obligations. They process only under Suitxen’s authority and documented instructions (Article 32(4) UK GDPR) and have no routine access to live client personal data. Because they are independent contractors located outside the UK, a contractor acts as a sub-processor of Suitxen if and when they access production personal data, and any such exceptional access is a restricted transfer under Chapter V UK GDPR. It is permitted only once, for that contractor: (i) the ICO International Data Transfer Agreement (VERSION A1.0) at Schedule 1 of the contractor agreement has been executed with its tables completed for the engagement; (ii) the Article 28 processing terms at Schedule 2 of that agreement apply; (iii) a transfer risk assessment has been completed; and (iv) the affected customer firms have been given the notice-and-objection process in DPA clause 5.2. Each access is approved in writing by the data-protection lead, limited to a named individual and task, time-limited, logged and revoked on completion. No such access has been granted to date; this register and the Overseas Development & Data Access Statement will be updated when the package is first executed.

Verification records: The signed data-processing terms, security due-diligence records, the transfer mechanism actually incorporated in each provider’s terms, and dated Data Bridge/DPF status checks for each provider are held in Suitxen’s internal vendor inventory; each entry in this register is checked against that inventory at every quarterly review, and summaries are available to controllers on reasonable request.

3. International transfers

Where a sub-processor hosts the data in the EEA (currently Supabase, Zoho and Sentry), the routine UK–EEA transfer is covered by the UK’s adequacy regulations for the EEA and no additional safeguard is required for that hosting; the provider’s contractual mechanism below covers any residual access from outside the EEA. Otherwise, where a sub-processor is outside the UK, Suitxen relies on either the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK International Data Transfer Addendum — the mechanism actually incorporated in that provider’s terms, as recorded above — as the primary documented transfer mechanism, supported by a transfer risk assessment and supplementary measures — in particular encryption and the pseudonymisation of client data before AI processing. Several US providers are also self-certified under the UK Extension to the EU–US Data Privacy Framework (the UK–US Data Bridge), which provides an alternative adequacy basis; where this applies it is noted against the provider above. Suitxen deliberately keeps the SCCs or IDTA as the primary basis for every provider, rather than relying on the Data Bridge alone, so that lawful transfers do not depend on the continuing validity of any adequacy decision. Each provider’s DPF status is checked against the live list at dataprivacyframework.gov at the point of reliance and re-checked at each quarterly review. Where a provider offers UK/EU data residency, that option is preferred; the register records whether it has been selected.

4. Change & notification process (Article 28(2))

Customer firms are entitled to be informed of intended changes to sub-processors and to object. Suitxen’s process:

  1. Any proposed new or replacement sub-processor is assessed under the onboarding checklist (section 5) before engagement.
  2. Affected customer firms are given at least 30 days’ advance notice of the intended change — by updating the published register page and by notification within the platform — and may raise a reasoned objection during that period.
  3. If an objection cannot be resolved, the parties follow the mechanism in the Data Processing Agreement.
  4. On the change taking effect, this register is updated, version-incremented, and re-approved.

5. New sub-processor onboarding checklist

Before engaging a new sub-processor, confirm and record:

  • What personal data it will process, and that the data is minimised to what is necessary.
  • Its location(s) and whether a UK/EU residency option is available and selected.
  • A written data-processing agreement / Article 28 terms are in place.
  • An appropriate international-transfer mechanism is in place where required, with a transfer risk assessment.
  • Its security posture (certifications, encryption, breach commitments) has been reviewed.
  • Customer-firm notification has been given under section 4 for every new or replacement sub-processor (the notice is not limited to “material” changes).

6. Review and approval

This register is a living record, reviewed quarterly and whenever a sub-processor changes. It is version-controlled and approved by the data-protection lead.

Document control: version 1.1, approved by the Director (data-protection lead) on 21 September 2026. Approval records are held internally. From first publication of this register, any change to its text is issued under an incremented version identifier with a change-history entry; published or accepted versions are archived and never overwritten.

Suitxen

A connected financial planning workspace built so the case record develops as the work progresses.

Platform

  • Fact find
  • Calculation engine
  • Risk profiling
  • Worksheet engine
  • How it works

Company

  • About
  • Mission
  • Values
  • Security & compliance
  • Who we serve

Legal

  • Terms of Service
  • Data Processing Agreement
  • Privacy Notice
  • Sub-processors
  • Cookie Policy
  • Beta NDA
  • Beta Programme Agreement

Connect

  • info@suitxen.co.uk

© 2026 Suitxen Ltd · Registered in England & Wales · Company No. 17284189 · Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ · ICO ZC207632

Suitxen is a software tool for UK financial advice professionals. It drafts working documents for adviser review and sign-off; it does not provide financial advice and is not authorised or regulated by the Financial Conduct Authority. The customer firm is the data controller and remains responsible for the advice and all outputs.