Sub-processors
Every third party that may process customer personal data, what it does and where.
Version 1.0 · Effective 6 August 2026 · Last updated 6 August 2026
Published under clause 6 of the Data Processing Agreement. We give at least 30 days' notice before adding or replacing anyone on this list. To be notified, email us and ask to be added to the sub-processor notification list.
1. Current sub-processors
| Provider | What it does | Data it may touch | Where |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All customer content and account data | EU (London/Ireland region) |
| Vercel | Application hosting and delivery | Data in transit; request logs | EU/UK edge, US corporate access |
| Stripe | Payment processing | Billing contact and payment data. Card details go to Stripe directly and never reach us | EU/US, standard contractual clauses |
| Resend | Transactional email delivery | Recipient name and email, message content | EU/US, standard contractual clauses |
| Anthropic | AI compliance assistant responses | The question asked and the account context needed to answer it | US, standard contractual clauses |
The AI assistant is the one to look at closely. A question typed into it is sent to a model provider. It is not used to train models. If your governance does not permit that, tell us and we will disable the assistant for your organisation — the rest of the Service is unaffected.
2. Our own access
Care Shield staff may access customer data only to provide support, to investigate a fault, or where required by law. Access is limited to those who need it and is logged.
Care Shield Compliance is a division of Africa Procurement Group Ltd, registered in England and Wales, company number 10553435. Registered office: Devonshire House, One Mayfair Place, London, England, W1J 8AJ. Questions about this document: hello@careshieldcompliance.co.uk.