Sub-processors
Last updated: 7 September 2026
This page lists the sub-processors sference (Neural Compute Ltd) engages to process customer data in connection with our services, as authorised under our Data Processing Agreement (Annex 3). Inference and storage of customer content run on infrastructure located within the EEA; ancillary vendors (analytics, monitoring, email, payments, status notifications) never receive inference content.
| Sub-processor | Purpose | Location of processing | Transfer mechanism |
|---|---|---|---|
| Verda (formerly DataCrunch Oy), Helsinki, Finland | GPU compute / inference hosting | Finland, Iceland (EEA) | Not required (intra-EEA) |
| Amazon Web Services EMEA SARL, Luxembourg | Cloud infrastructure (EU regions only) | EEA (EU regions) | Not required (intra-EEA hosting); AWS DPA incl. SCCs apply as fallback for any residual access |
| Cloudflare, Inc., USA | CDN, TLS termination, DDoS protection (EU points of presence / regional services) | Primarily EEA edge; US parent entity | EU SCCs / UK Addendum via Cloudflare DPA; EU-US Data Privacy Framework where certified |
| PostHog, Inc., USA (EU Cloud) | Platform usage analytics (dashboard/telemetry only; no inference content) | Germany (EEA hosting) | EU SCCs via PostHog DPA for any residual US access |
| Functional Software, Inc. dba Sentry, USA (EU region) | Error and performance monitoring (technical event data; no inference content) | Germany (EEA hosting, EU data residency region) | EU SCCs via Sentry DPA; EU-US Data Privacy Framework certified |
| Stripe Payments Europe, Ltd., Dublin, Ireland | Payment processing (billing and payment data only; no inference content) | Ireland (EEA); US affiliates (Stripe, Inc.) for processing support | EU SCCs via Stripe DPA; EU-US Data Privacy Framework certified |
| Peaberry Software, Inc. dba Customer.io, USA (EU region) | Transactional and lifecycle email (account and contact data only; no inference content) | EEA hosting (EU data region) | EU SCCs via Customer.io DPA for any residual US access |
| Google Ireland Ltd (Google Workspace) | Corporate email and support correspondence (account and contact data only; no inference content) | United States (global Google infrastructure) | EU SCCs / UK Addendum via Google Workspace agreement (Cloud Data Processing Terms); EU-US Data Privacy Framework where certified |
| Pineapple Technology Ltd dba incident.io, London, United Kingdom | Status page hosting and incident notification emails (subscriber email addresses only; no inference content) | United Kingdom (entity); Google Cloud Platform, Belgium (EU region) | Not required (intra-EEA hosting; UK adequacy); EU SCCs via incident.io DPA for any residual US access |
We announce additions and replacements on this page, and by email to subscribed contacts, at least 14 days before a new sub-processor processes customer data (see DPA Clause 5.2). To subscribe to change notifications, contact [email protected].
Change log
- 2026-09-07 · Added Google Ireland Ltd (Google Workspace) for corporate email and support correspondence, and Pineapple Technology Ltd dba incident.io for the status page and incident notification emails (both regularising existing use).
- 2026-08-17 · Replaced Mollie B.V. with Stripe Payments Europe, Ltd. (payment processing). Added Customer.io (EU region) for transactional and lifecycle email.
- 2026-07-23 · Initial published list.