Sub-processors and service providers
This page lists the third-party providers we rely on to deliver our services: what each one does, the capacity in which we engage it, where it processes data, and the safeguard we rely on where data leaves the European Economic Area (the “EEA”).
It does two jobs. It is the current list of sub-processors we are required to keep under the Data Processing Agreement we hold with each client, and it is the provider list referred to in our Privacy Policy.
Where client data actually sits
Client systems — the applications, databases and uploaded files belonging to the businesses we build and host for — run exclusively on infrastructure we own and operate in Ireland. We do not use third-party cloud hosting to run client systems, and we do not store the personal data those systems hold on anyone else’s platform.
The providers listed below sit in the network path, deliver a specific function, or hold source code and configuration. None of them hosts client systems.
The two capacities we act in
We handle personal data in two distinct roles, and which one applies changes who is responsible for what.
As a processor, we handle personal data on behalf of a client — the people who use a website or application we have built and now host for that client. The providers we engage to help us do that work are our sub-processors, and each client has a contractual right to be told before we add one. The notice mechanism is set out below.
As a controller, we handle personal data for our own business — our website visitors, enquiries, client contracts and billing. The providers we use for that are our own processors. They are not sub-processors, because the underlying data is ours to determine, not a client’s.
Several providers act for us in both capacities at once. The table records which.
Providers
| Provider | What it does | Capacity | Where it processes | Transfer safeguard where data leaves the EEA |
|---|---|---|---|---|
| Cloudflare, Inc. | Content delivery, reverse proxy and tunnels, web application firewall, DDoS mitigation, and bot protection | Sub-processor, and our own processor | Global edge network | EU Standard Contractual Clauses (Modules Two and Three); UK Addendum; EU–US Data Privacy Framework |
| GitHub, Inc. | Source-code repository hosting and deployment configuration for the applications we build | Sub-processor | United States, and other countries in which GitHub or its sub-processors operate | EU Standard Contractual Clauses (Module Two or Three, as applicable); EU–US Data Privacy Framework; UK Addendum |
| Google (Google Ireland Limited and Google LLC) | Website analytics where the visitor has consented; a cloud project supporting booking functionality where a client uses it; our own business tooling | Sub-processor, and our own processor | European Union and United States | EU Standard Contractual Clauses |
| Namecheap, Inc. (Private Email) | Email hosting for our functional mailboxes and their aliases | Sub-processor, and our own processor | United States (Phoenix, Arizona) | EU Standard Contractual Clauses (Module Two) |
| Stripe (Stripe Payments Europe Limited, with processing by Stripe, LLC) | Processing payments made to us. Card details go directly to Stripe; we never see or store them | Our own processor — not a sub-processor | Ireland and United States | EU Standard Contractual Clauses; Stripe Data Transfers Addendum |
| Twilio Inc. | Transactional SMS sent by client applications, through a sub-account under our parent account | Sub-processor | United States and European Union | EU Standard Contractual Clauses (Module Three); Binding Corporate Rules; EU–US Data Privacy Framework; UK IDTA |
Source code and configuration. GitHub holds the source code and deployment configuration for the applications we build. It does not hold the live databases those applications run on: the personal data a live system processes stays on our own infrastructure in Ireland.
Providers that also act as independent controllers
Some of these providers also process certain data for their own purposes, which they determine themselves. That processing falls outside our instructions and outside the contracts we hold with them. We set it out here so the position is stated plainly rather than left buried.
| Provider | Data concerned | What they do with it |
|---|---|---|
| GitHub, Inc. | Account, billing and customer-relationship data and related correspondence; abuse and virus-scanning signals; aggregated statistics | Account, billing and relationship management; compensation; meeting legal obligations; abuse detection and prevention, virus scanning, and detecting breaches of its terms of service; and aggregated statistics for internal, financial and capacity planning. GitHub states this list is exhaustive, and that it does not use the data for profiling, advertising, or the sale or brokering of data. |
| Stripe | Identity, contact, transaction and payment-method data | Fraud prevention and detection; anti-money-laundering and know-your-customer obligations; risk and loss mitigation; and the analysis and development of its own products and services. |
| Twilio Inc. | Account data; communications usage data, including sender and recipient numbers, message logs, timestamps and delivery status; and message content | Providing electronic communications services; fraud and service-abuse prevention, including developing and improving its internal tools and related model training; legal and regulatory obligations; and product development and business analytics. |
Providers that are not our sub-processors
Where a client holds an account directly and we only administer it on the client’s instruction, that provider is the client’s own processor, not ours. This applies to:
- Google Workspace tenants the client owns
- A client’s own payment-provider account
Changes to this list
Before a new sub-processor begins processing client personal data, we give each affected client at least 30 days’ notice — by updating this page and sending notice to the client’s nominated contact address. Updating the page on its own is not notice.
Within that period, a client may object on reasonable data-protection grounds. We will discuss any objection in good faith, and if it cannot be resolved, the client may terminate the affected part of the services without penalty.
Our Data Processing Agreement also records, plainly, any point at which a provider’s own terms fall short of an obligation we owe our clients. A client may request that disclosure at any time.
Questions
Registered in Ireland, company number 793621.