All legal documents

Sub-processors

Every third party that may process customer personal data, what it does and where.

Version 1.0 · Effective 6 August 2026 · Last updated 6 August 2026

Published under clause 6 of the Data Processing Agreement. We give at least 30 days' notice before adding or replacing anyone on this list. To be notified, email us and ask to be added to the sub-processor notification list.

1. Current sub-processors

ProviderWhat it doesData it may touchWhere
SupabaseDatabase, authentication, file storageAll customer content and account dataEU (London/Ireland region)
VercelApplication hosting and deliveryData in transit; request logsEU/UK edge, US corporate access
StripePayment processingBilling contact and payment data. Card details go to Stripe directly and never reach usEU/US, standard contractual clauses
ResendTransactional email deliveryRecipient name and email, message contentEU/US, standard contractual clauses
AnthropicAI compliance assistant responsesThe question asked and the account context needed to answer itUS, standard contractual clauses

The AI assistant is the one to look at closely. A question typed into it is sent to a model provider. It is not used to train models. If your governance does not permit that, tell us and we will disable the assistant for your organisation — the rest of the Service is unaffected.

2. Our own access

Care Shield staff may access customer data only to provide support, to investigate a fault, or where required by law. Access is limited to those who need it and is logged.

Care Shield Compliance is a division of Africa Procurement Group Ltd, registered in England and Wales, company number 10553435. Registered office: Devonshire House, One Mayfair Place, London, England, W1J 8AJ. Questions about this document: hello@careshieldcompliance.co.uk.