Subprocessor list
Version 0.12 (draft) · Pending legal review
A “sub-processor” is a third party that processes personal data on our behalf. This list names every one of them, what they do, what data they handle, where they process it, and on what contractual basis.
Customer documents do not transit our infrastructure under any tier or any add-on, so no sub-processor on this list receives them. What sub-processors handle for us is operational data — error reports, billing records, website and email correspondence. The categories are set out in the Privacy Notice.
We notify you of any material change to this list — a sub-processor added, removed, or given a materially different scope — by a notice on our website within 10 working days, a dated entry in the change history below, and, for customers whose contract includes sub-processor-change rights, a direct email at least 30 days before the change takes effect.
Current sub-processors
As at 12 August 2026.
| Sub-processor | Service | Data processed | Location | Transfer basis | Status |
|---|---|---|---|---|---|
| Cloudflare, Inc. | DNS, CDN, WAF, site hosting, form handling, bot protection (Turnstile), and access gating for preview URLs | Visitor IP addresses (truncated at the edge); request metadata; contact, pilot-enquiry and newsletter form contents; Turnstile bot-detection signals (IP, TLS fingerprint, user agent, origin — not form content), which Cloudflare also uses to improve its own service and is a controller for | UK / EEA points of presence; global edge for static assets | SCCs and the UK International Data Transfer Addendum, under Cloudflare’s published DPA | In use |
| Plausible Insights OÜ | Cookieless site analytics for surematters.com | Aggregate visitor counts, page views, referrer, browser family, country signal. No full IP address and no per-session identifier | EU (Estonia / Frankfurt) | UK–EU adequacy | In use |
| Anthropic PBC | AI assistance for our own engineering, drafting and content production | Prompts and outputs from our internal sessions; our own strategy documents and engineering artefacts. No customer documents are sent to Anthropic. | US | SCCs under Anthropic’s commercial terms | In use |
| Bugsink B.V. | Error and crash reporting for the desktop products | Stack traces, error messages, software version, operating-system family, and a pseudonymous device identifier. File paths, exception messages, request bodies and stack-trace local variables are stripped on your machine before anything is sent. | EU. Bugsink’s own sub-processors are Hetzner Online GmbH (Germany) and Scaleway S.A.S. (France); Stripe processes Bugsink’s payments only and is contractually excluded from application data | UK–EU adequacy. No SCCs or IDTA required | In use |
| Keila GmbH | Newsletter delivery and sign-up | Email address, optional name, opt-in timestamp, send and open events | EU (Germany and France), with sending via Amazon SES on EU infrastructure | UK–EU adequacy | In use |
| Google Cloud EMEA Ltd | Key management (Cloud KMS) for the signing keys behind licence files, software releases and detector bundles | Cryptographic signing operations on our own artefacts. No customer documents, and no telemetry — we do not operate a telemetry service. | europe-west2 (London) | UK–EU adequacy | In use, for key management only |
| Google Ireland Limited / Google LLC (Google Workspace) | Email for the SureMatters addresses; the script that receives website contact and pilot form submissions; internal document storage | Sender and recipient addresses; message contents for mail to and from our addresses; contact and pilot form submissions (name, email, organisation, message); routing metadata. No customer documents under any tier. | EU primary, with some sub-processing in the US | UK–EU adequacy for EU processing; SCCs and IDTA for US sub-processing under Google’s Workspace DPA | In use |
| Microsoft Corporation | Code-signing for our Windows release builds | Binary hashes, signing-request metadata, and our own validated company identity. No personal data of customers or operators. | North Europe (Dublin) | Microsoft Online Services Terms; UK–EU adequacy for the EU-hosted signing operations | In use |
| Stripe Payments UK Ltd | Card payment processing | Account-holder name, email, organisation, billing address, VAT number, payment-method token, transaction metadata | UK, with some sub-processing by Stripe, Inc. (US) | UK–US Data Bridge and SCCs, under Stripe’s published DPA | Contracted; not yet in use. Begins when self-service purchasing opens |
| Xero (UK) Limited | Our accounting and invoicing system | Organisation name, company number, billing address, VAT number, accounts-payable contact name and email, invoice line items and payment records. No customer documents. | UK and EEA | UK–EU adequacy; Xero’s published UK DPA | In use |
Stripe is listed before it is active because a reviewer assessing us should see what is coming, not discover it later. It is marked so you can tell the difference.
What we do not yet operate
We do not currently run a telemetry service. Where the products record operational information, it stays on your own machine and is visible to you there. Nothing is transmitted to us, so nothing is stored by us and no sub-processor receives it. If that changes, it changes under the notice terms above.
We do not currently run a licence-verification service or an automatic update service. Licences are issued manually and updates are downloaded from our website when you choose to take them.
How we choose a sub-processor
Four requirements, applied before anything is signed.
- Personal data stays in the UK or the EU, and the commitment sits in the contract rather than in a configuration setting we could change.
- A data processing agreement we can read in full before we commit, with the sub-processors named.
- No path to customer documents. This is a property of how the products are built, not a promise we ask a supplier to keep.
- A way out — data export, and a portable or self-hostable alternative where one exists.
Where a supplier cannot meet these, we use someone else. We do not publish our assessments of suppliers we did not choose; a private view of another company’s contract is not ours to broadcast.
Recipients who are not sub-processors
- Your own cloud provider, where you deploy a SurePrepare helper service into your own tenancy. That helper runs in your infrastructure under your agreement with your provider. We have no sub-processor relationship with them in respect of it.
- Our advisors — solicitors, accountants, auditors — under professional confidentiality obligations.
- Regulators and courts, where the law requires it.
- A successor organisation, in a restructuring, sale or insolvency, subject to the protections data protection law provides.
These are recorded in the Privacy Notice. They are not on the list above because they do not process personal data on our instructions in the Article 28 sense.
Change history
| Date | Version | Change |
|---|---|---|
| 2026-05-09 | v0.1 | Initial draft. |
| 2026-05-22 | v0.2 | Google Workspace added. Newsletter vendor selected. Cloudflare entry widened to cover site hosting and access gating. |
| 2026-06-01 | v0.3 | Newsletter vendor changed to Keila, an EU-hosted provider. Removes the US transfer mechanism the previous listing carried. |
| 2026-06-10 | v0.4 | Company renamed from Footprint Limited to SureMatters Ltd, effective 8 June 2026; company number 03724474 unchanged. Email primary domain moved to surematters.com. |
| 2026-06-14 | v0.5 | Error-tracking listing marked as not yet active, the integration having been deferred to a later release. |
| 2026-06-19 | v0.7 | Error-tracking vendor changed to Bugsink B.V., whose data processing agreement commits to EU-only processing of hosted personal data with named EU sub-processors. |
| 2026-06-23 | v0.8 | Microsoft added for Windows code-signing. No personal data reaches this service. |
| 2026-06-24 | v0.9–v0.11 | Bugsink due diligence completed, integration verified, and the data processing agreement executed. Scrubbing of personal data before transmission confirmed working. Retention of raw event data is 60 days. |
| 2026-08-12 | v0.12 | Structural revision. Vendor due-diligence records, internal planning references and supplier commercial terms removed; these are not sub-processor information. Assessments of suppliers we did not select removed. Entries not yet processing any data are now marked as such. Registered office added. |
| 2026-08-12 | v0.12 | Correction. Earlier versions described a telemetry service, a licence-verification service and an update-distribution service as operating. They are not, and no telemetry has ever been transmitted to us. The Google Cloud entry is corrected to what it actually covers — key management for signing. Xero is corrected to in use; it is our accounting system and predates the products. This version also removes Sentry GmbH, which had remained listed as a current sub-processor since being replaced by Bugsink on 19 June 2026. |
Contact
Questions about this list: privacy@surematters.com. We reply within 5 working days.
SureMatters Ltd, Ground Floor, 108–112 Main Road, Sundridge, Sevenoaks, TN14 6ES.
Drafted with AI assistance and reviewed by a named person, per our AI Policy.