Last Updated: September 21, 2026
This page lists the third parties that process personal data on our behalf. It forms part of our Data Processing Agreement, and customers who have accepted that agreement give general written authorisation to the sub-processors listed here.
Before we add or replace a sub-processor, we update this page and notify affected customers at least 30 days in advance. You may object on reasonable data protection grounds within that period; section 7 of the Data Processing Agreement explains what happens if we cannot resolve the objection. To receive those notifications, write to [email protected].
A sub-processor is a third party that processes personal data on our behalf in order to deliver the service. We impose the same data protection obligations on each of them by contract, and we remain fully liable to you for their performance.
Some of the providers below only receive data in our role as controller, for example when we bill you or send you a service email. Those are not sub-processors in the strict sense, but we list them anyway, because a list that hides a data flow is not useful to anyone.
These providers can receive personal data that reaches us through the widget, the API or the quote engine.
Runs the application, the PostgreSQL database, the Redis cache and our outbound mail server. The server is administered by us; the provider supplies and operates the underlying infrastructure and therefore has technical access to it.
Powers the AI live-support assistant. Receives the full text of the messages a user types into that assistant, which may contain personal data if the user includes it.
Outbound transactional email is sent from our own mail server on our own infrastructure, so there is no separate email delivery provider receiving your messages. The provider below is the only third party in this section.
Acts as merchant of record for paid plans. Handles checkout, payment collection, tax and VAT determination, invoicing and renewals.
The providers in this section are loaded in the browser. Those that are not strictly necessary load only after you consent through our cookie banner, and not before.
Protects forms and guest quoting against automated abuse. Classified as strictly necessary, so it loads without separate consent.
Measures site usage and performance. Loads only if you accept analytics cookies.
Serves advertising on parts of the public website. Loads only if you accept marketing cookies. It is not used on the dashboard, the admin area, authentication pages, or the embedded widget.
Optional federated sign-in. Used only if you choose to sign in with one of these providers, and the provider then confirms your identity to us.
Every change is recorded here with its effective date. Where a change adds or replaces a sub-processor that handles data we process on your behalf, customers receive at least 30 days' notice before it takes effect.
If you need this list in a signed form for your own records or for a procurement process, write to [email protected].