Sub-processors
Last updated: 26 August 2026
Projexa uses the following sub-processors to provide the Service. We'll update this list and notify Customers before adding a new one, per our Data Processing Addendum.
| Sub-processor | Purpose | Data processed | Region | Transfer safeguard |
|---|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | All application data, including personal data entered by Customers | EU (Ireland) | None needed — data stays in the EEA |
| Vercel Inc. | Application hosting / compute | Data in transit while requests are handled | EU (Dublin) — switched from US on 2026-08-07 | None needed — data stays in the EEA |
| Resend | Transactional email delivery (invites, progress reports, notifications) | Recipient name/email, and the content of the specific email sent | US (account data, logs, and API records are stored in the US regardless of sending region) | UK Extension to the EU-US Data Privacy Framework (Resend is certified — confirmed via their published DPA and changelog), backed by Standard Contractual Clauses in Resend's DPA |
| Anthropic PBC | AI-assisted drafting features (quote-drafting assistant, progress-report narrative generation, and similar — always a proposal a user must explicitly apply, never auto-applied) | Prompt content sent to generate a suggestion — may include project/client names and other details a Customer's data includes | US — Anthropic's first-party API does not currently offer EU/UK data residency; inference and workspace data storage are US-only | Standard Contractual Clauses under Anthropic's Data Processing Addendum, published at anthropic.com/legal/data-processing-addendum and automatically incorporated into Anthropic's Commercial Terms of Service on acceptance — no separate sign-off step, confirmed via Anthropic's own support documentation (2026-08-24) |
Note on Resend specifically: Resend's "sending region" setting (we could route emails via their Ireland region) only affects where messages are dispatched from for delivery latency — it does not change where the underlying account/customer data is stored, which is always the US. The actual transfer safeguard is Resend's Data Privacy Framework certification, not a region setting. Since DPF certifications can lapse, spot-check Resend's status against the official DPF list before publishing this document, and periodically afterwards.
Third-party services Customers connect themselves (not sub-processors in the conventional sense)
Xero — when a Customer enables "Sync to Xero" (todo.md #39), Projexa pushes their contacts and Staged Payments into the Customer's own Xero account as draft invoices, via an OAuth connection the Customer authorises themselves.
This is legally distinct from the sub-processors listed above, confirmed by reading Xero's own Data Processing Addendum directly (last updated by Xero 11 February 2025):
- Clause 1.2(a)-(b): Xero's DPA is between Xero and whichever party "appoints Xero to process Personal Data on its behalf" — for a Sync-to-Xero connection, that's the Projexa Customer, who already holds their own Xero account, not Projexa.
- Clause 1.2(e), verbatim: "If the Customer uses or integrates any third-party service to Xero's services (such as an app from the Xero App Store), any processing of Data by that third-party service will be governed by that third-party's privacy notice and/or data processing terms, and not by this Addendum." — i.e. Xero's own DPA explicitly does not extend to cover Projexa as the connecting app.
- Xero's separate Developer Platform Terms confirm the reverse direction: once a connected app sends data in, "Xero's terms of use, privacy notice and data processing terms... will apply to Xero's use of that user data from the time it's received, and the app developer's terms will no longer apply."
Put together: the Customer already has their own direct DPA with Xero, independent of Projexa, covering that data the moment it arrives. Projexa isn't "engaging" Xero as a vendor on the Customer's behalf the way it engages Resend or Anthropic — the Customer is directing Projexa to write into an account the Customer already independently controls.
Practical consequences — both flagged for the solicitor to confirm, not decided here:
- Xero likely shouldn't sit under the DPA's §9 "30 days' notice before engaging a new sub-processor" clause — there's no new engagement happening on Projexa's side each time a Customer connects their own account.
- Some disclosure to Customers is still the right instinct for transparency — a Customer should know enabling this feature sends their data to Xero — just framed as "this feature sends data to your own connected Xero account," not "we've added a new sub-processor." Worth asking the solicitor whether the DPA needs its own short clause for this category (Customer-directed integrations) rather than folding Xero into the sub-processor table/consent mechanism.
Hosting region: checked both of Xero's own primary sources (their DPA text, quoted above, and their published subprocessors page) — neither discloses the specific AWS region UK/EU data is hosted in. The subprocessors page lists "Amazon Web Services — United States" but that's AWS's corporate domicile, not where the infrastructure actually runs; Xero's DPA only commits generically to Standard Contractual Clauses / the UK Addendum for "Restricted Transfers," without naming a region. This genuinely isn't published anywhere customer-facing as far as we could find — secondary sources suggest EU data in AWS eu-west-1 (Ireland) and UK data in AWS eu-west-2 (London), but treat that as an educated guess, not a confirmed fact, unless the solicitor gets a direct answer from Xero.
Security: Xero states (DPA §2.5) it is regularly audited against SOC 2 and ISO/IEC 27001:2022 by an independent third-party auditor, and can provide its SOC 2 report on request.
Future sub-processors (not yet in use)
- Stripe — will be added here once billing (Phase 8) goes live, along with its own transfer-safeguard entry (Stripe publishes standard DPA terms covering this).