Sub-processor List

Last updated: 2026-06-14 · Last reviewed: 2026-06-14

Sub-processor List

This page lists the third-party Sub-processors GDPRChecker may use to deliver the Service when we process personal data on your behalf as a processor, depending on the features you use.

We will give at least 30 days' notice before adding or replacing a Sub-processor that processes Customer Data, by email to your account address and by updating this page.

You may object to a new Sub-processor on reasonable grounds relating to data protection by emailing us within 14 days of notice. If we cannot accommodate the objection with a commercially reasonable alternative, you may terminate the affected paid Service before the new Sub-processor begins processing.

This list forms part of our Data Processing Agreement (DPA).

Current Sub-processors

Sub-processorPurposeData processedLocationSafeguards
Vercel Inc.Application hosting and edge deliveryCustomer Data in transit and at rest within platform infrastructureUnited States (EU regions may be used where configured)Data Processing Agreement; Standard Contractual Clauses where required
Supabase, Inc.Database, authentication, and storageAccount data, site configuration, consent logs, and Customer Data stored by the ServiceUnited States / EU (project region dependent)Data Processing Agreement; Standard Contractual Clauses where required
Stripe, Inc.Subscription billing and payment processingBilling identifiers, invoice metadata, and payment status (not full card numbers)United States / Ireland (Stripe entity dependent)Data Processing Agreement; Standard Contractual Clauses; PCI DSS
Google LLC (Google OAuth)Optional customer sign-inAuthentication identifiers and email when Customer chooses Google sign-inUnited States / global infrastructureGoogle API terms; Standard Contractual Clauses where applicable
Resend, Inc.Transactional email deliveryRecipient email addresses, message content, and delivery metadata for Service notificationsUnited StatesData Processing Agreement; Standard Contractual Clauses where required
Cloudflare, Inc.DNS, proxy, or security services (when configured for the Service)IP addresses, request metadata, and security signals in transitUnited States / global edge networkData Processing Agreement; Standard Contractual Clauses where required
AI model providers (e.g. OpenAI)AI-assisted document or risk review features if enabled by the CustomerContent submitted for AI-assisted review when that feature is usedUnited States / provider-dependentData Processing Agreement or provider terms; Standard Contractual Clauses where required

Part of our Data Processing Agreement.