Sub-processors.
The third parties that touch your data, the data they see, and the region they hold it in. We notify customers in writing 30 days before a new sub-processor enters scope.
| Vendor | Purpose | Data | Region |
|---|---|---|---|
Vercel, Inc. SOC 2 Type II, ISO 27001, GDPR DPA available. | Application hosting (Next.js) + serverless function execution. | Application logs, request metadata. Customer-uploaded creative assets do not transit Vercel egress. | EU (fra1) primary. Failover to US East under outage. |
Supabase Inc. SOC 2 Type II, HIPAA-eligible, GDPR DPA available. | Primary application database (Postgres), authentication, file storage, Vault for OAuth tokens. | All structured customer data: org records, agent outputs, action logs, comments, OAuth tokens (encrypted via Vault). | eu-west-2 (London). No replication outside EU/UK. |
Google Cloud (BigQuery) SOC 2 Type II, ISO 27001/27017/27018, GDPR DPA available. | Performance data warehouse: ingestion exports + derived views. | Campaign-level paid media performance, GA4 export, Google Merchant Center product feed attributes, Shopify order and product aggregates, demographic stats. No identified end-user records. | europe-west2 (London). |
Anthropic, PBC SOC 2 Type II, ISO 27001, EU SCCs + UK Addendum in place. | Claude API for agent reasoning, AI-Read, strategy chat. | Aggregated metrics + redacted descriptions sent to the model. We do not ingest customer PII fields; free-text fields such as search terms can incidentally contain personal data, and a redaction layer strips common identifiers (emails, phone numbers, postcodes, National Insurance numbers, IP addresses) before any prompt leaves our systems. | EU API endpoint where available, US otherwise. Zero-retention contract; no model training on customer data. |
Funnel.io AB SOC 2 Type II, ISO 27001, GDPR DPA available. | Source-of-truth ingestion for paid-media platforms into BigQuery: Google Ads, Meta Ads, Microsoft Advertising, TikTok Ads and OpenAI Ads, each connected only where the client runs that platform. | OAuth refresh tokens, raw platform exports. | EU. |
Stripe Payments Europe Ltd. PCI-DSS Level 1, SOC 2 Type II, GDPR DPA available. | Subscription billing, setup-fee invoicing. | Billing email, organisation name, payment method (held by Stripe, never stored on Equaliser systems). | Ireland (EU). |
Resend, Inc. SOC 2 Type II, GDPR DPA available. | Transactional email delivery (weekly digests, NPS surveys, alerts). | Recipient email, message body. Logs purged at 30 days. | EU. |
Sentry (Functional Software, Inc.) SOC 2 Type II, ISO 27001, GDPR DPA available. | Application error monitoring. | Error traces, request metadata. EU-region ingestion; PII scrubbing enabled. | EU (de.sentry.io). |
Langfuse GmbH SOC 2 Type II, ISO 27001, GDPR DPA available. | AI observability: tracing agent runs for quality and cost. | Prompt/response traces of AI runs (aggregated metrics, no end-consumer PII), latency and cost metadata. | EU (Germany). |
GitHub, Inc. SOC 2 Type II, ISO 27001/27018. | Source code hosting + CI/CD. No customer data. | None; code only. | US. |
PostHog Inc. SOC 2 Type II, GDPR DPA available. | Product analytics: feature usage, page-view metrics, AI-Read engagement. | User UUID, organisation UUID, event metadata (page path, action name, latency). Cookieless mode: no analytics cookies or persistent browser storage; no session recording. | EU (eu.posthog.com). Zero replication outside EU. |
Storage regions in scope: EU · UK · US (failover only)
Updated 4 September 2026 (hand-dated on each register change). We notify customers in writing 30 days before any register change takes effect; to receive those notifications, email contact@equaliser.co.uk and we will add you to the notification list.