Sub-processors
Where we process personal data on a client's behalf, these are the third parties we engage to help. The list is published rather than provided on request, because a sub-processor list you have to ask for is not really disclosure.
- Last updated
- 1 July 2026
- Applies to
- All Anithra Solutions entities
1. About this list
A sub-processor is a third party engaged by us, as processor, to process personal data on behalf of a client who is the controller. Each is bound by a written contract imposing data-protection obligations no less protective than those in our own Data Processing Agreement, as required by Article 28(4) of the UK and EU GDPR.
Not every sub-processor is used in every engagement. Your Data Processing Agreement and statement of work identify which apply to you. Where a client requires a specific region or excludes a specific provider, we accommodate that at the point of contracting.
2. Corporate sub-processors
Used across the business for communication, collaboration and client management.
| Sub-processor | Purpose | Processing location | Transfer safeguard |
|---|---|---|---|
| Google Workspace | Business email, documents and calendars | EU, UK, US | SCCs + UK Addendum |
| Atlassian (Jira, Confluence) | Delivery tracking and documentation | EU, US | SCCs + UK Addendum |
| Slack Technologies | Internal and client collaboration channels | EU, US | SCCs + UK Addendum |
| HubSpot | CRM for client and prospect contacts | EU (Frankfurt), US | SCCs + UK Addendum |
| Resend | Transactional email delivery for enquiry forms | EU, US | SCCs + UK Addendum |
| Zoom Video Communications | Client meetings and recorded walkthroughs | EU, UK, US | SCCs + UK Addendum |
3. Infrastructure and platform
Hosting, delivery and operational tooling. Region pinning is available on request for AWS and GCP workloads; error monitoring is EU-resident by default with personal data scrubbed before transmission.
| Sub-processor | Purpose | Processing location | Transfer safeguard |
|---|---|---|---|
| Vercel Inc. | Website hosting, edge delivery and deploy previews | Global edge; origin configurable | SCCs + UK Addendum, DPA in place |
| Amazon Web Services | Primary application hosting, storage and databases | eu-west-2, eu-central-1, us-east-1, ap-south-1 | AWS DPA with SCCs; region pinning available |
| Google Cloud Platform | Data and machine-learning workloads | europe-west2, us-central1, asia-south1 | Google Cloud DPA with SCCs |
| Cloudflare | DNS, WAF and DDoS protection | Global edge | SCCs + UK Addendum |
| Sentry | Application error monitoring (PII scrubbed at source) | EU (Frankfurt) | EU region; no restricted transfer |
| Datadog | Infrastructure and application observability | EU (Paris), US | SCCs + UK Addendum |
| GitHub | Source control and continuous integration | US | SCCs + UK Addendum |
4. Product-specific sub-processors
Engaged only where the relevant product or capability is in use.
| Sub-processor | Purpose | Processing location | Transfer safeguard |
|---|---|---|---|
| Stripe / Adyen | Card processing for Orbit Commerce deployments | EU, UK, US | SCCs + UK Addendum; PCI DSS Level 1 |
| Razorpay | Payment collection for India-based deployments | India | Domestic processing; DPDP Act 2023 applies |
| Twilio | SMS and voice one-time passcodes | EU, US | SCCs + UK Addendum |
| Mapbox | Mapping and geocoding for BookMyPlots and Shareprops | EU, US | SCCs + UK Addendum |
| Onfido | Identity verification within Ledgerline KYC flows | EU, UK | EU/UK processing |
| Apple / Google health platforms | Wearable data sync for Pulsr, at the user's instruction | Per platform | Platform terms; user-initiated |
5. Change notification and objection
- We give clients at least 30 days’ written notice before a new sub-processor begins processing their personal data.
- Clients may object on reasonable data-protection grounds within that period. We will work in good faith to offer an alternative.
- If no reasonable alternative exists, the client may terminate the affected services without penalty and with a pro-rata refund of prepaid fees.
- Where a change is required urgently to maintain security or availability, we may act first and notify immediately — the objection right is unaffected.
To subscribe to change notifications, write to privacy@anithrasolutions.com with your organisation name.
6. How we vet them
Before a sub-processor is engaged, we assess:
- certification and audit evidence — ISO 27001, SOC 2 Type II, PCI DSS as relevant;
- the data-processing terms offered, including the availability of SCCs and the IDTA;
- processing locations and whether region pinning is possible;
- breach notification commitments and their timelines;
- sub-processing chains — who they in turn rely on;
- financial stability and a credible exit path if the relationship ends.
Sub-processors are reviewed annually and whenever their certification status, ownership or processing locations change materially.
7. Contact
Questions about this list, or a request for a copy of a specific Data Processing Agreement: privacy@anithrasolutions.com. See also our Privacy Policy and the Trust Centre.