← All legal documents
Pilot version — published without solicitor review. Originally accurate as of 2026-08-07; the Anthropic and Xero entries were added 2026-08-24 once those features shipped (todo.md #42, #39), then verified further the same day against each provider's own primary documentation — including, for Xero, reading its actual Data Processing Addendum text directly (last updated by Xero 11 February 2025). That reading changed how Xero is categorised below — see "Third-party services Customers connect themselves." This document has not yet been reviewed by a solicitor; see the Pilot Notice.

Sub-processors

Last updated: 26 August 2026

Projexa uses the following sub-processors to provide the Service. We'll update this list and notify Customers before adding a new one, per our Data Processing Addendum.

Sub-processor Purpose Data processed Region Transfer safeguard
Supabase, Inc. Database, authentication, file storage All application data, including personal data entered by Customers EU (Ireland) None needed — data stays in the EEA
Vercel Inc. Application hosting / compute Data in transit while requests are handled EU (Dublin) — switched from US on 2026-08-07 None needed — data stays in the EEA
Resend Transactional email delivery (invites, progress reports, notifications) Recipient name/email, and the content of the specific email sent US (account data, logs, and API records are stored in the US regardless of sending region) UK Extension to the EU-US Data Privacy Framework (Resend is certified — confirmed via their published DPA and changelog), backed by Standard Contractual Clauses in Resend's DPA
Anthropic PBC AI-assisted drafting features (quote-drafting assistant, progress-report narrative generation, and similar — always a proposal a user must explicitly apply, never auto-applied) Prompt content sent to generate a suggestion — may include project/client names and other details a Customer's data includes US — Anthropic's first-party API does not currently offer EU/UK data residency; inference and workspace data storage are US-only Standard Contractual Clauses under Anthropic's Data Processing Addendum, published at anthropic.com/legal/data-processing-addendum and automatically incorporated into Anthropic's Commercial Terms of Service on acceptance — no separate sign-off step, confirmed via Anthropic's own support documentation (2026-08-24)

Note on Resend specifically: Resend's "sending region" setting (we could route emails via their Ireland region) only affects where messages are dispatched from for delivery latency — it does not change where the underlying account/customer data is stored, which is always the US. The actual transfer safeguard is Resend's Data Privacy Framework certification, not a region setting. Since DPF certifications can lapse, spot-check Resend's status against the official DPF list before publishing this document, and periodically afterwards.

Third-party services Customers connect themselves (not sub-processors in the conventional sense)

Xero — when a Customer enables "Sync to Xero" (todo.md #39), Projexa pushes their contacts and Staged Payments into the Customer's own Xero account as draft invoices, via an OAuth connection the Customer authorises themselves.

This is legally distinct from the sub-processors listed above, confirmed by reading Xero's own Data Processing Addendum directly (last updated by Xero 11 February 2025):

Put together: the Customer already has their own direct DPA with Xero, independent of Projexa, covering that data the moment it arrives. Projexa isn't "engaging" Xero as a vendor on the Customer's behalf the way it engages Resend or Anthropic — the Customer is directing Projexa to write into an account the Customer already independently controls.

Practical consequences — both flagged for the solicitor to confirm, not decided here:

Hosting region: checked both of Xero's own primary sources (their DPA text, quoted above, and their published subprocessors page) — neither discloses the specific AWS region UK/EU data is hosted in. The subprocessors page lists "Amazon Web Services — United States" but that's AWS's corporate domicile, not where the infrastructure actually runs; Xero's DPA only commits generically to Standard Contractual Clauses / the UK Addendum for "Restricted Transfers," without naming a region. This genuinely isn't published anywhere customer-facing as far as we could find — secondary sources suggest EU data in AWS eu-west-1 (Ireland) and UK data in AWS eu-west-2 (London), but treat that as an educated guess, not a confirmed fact, unless the solicitor gets a direct answer from Xero.

Security: Xero states (DPA §2.5) it is regularly audited against SOC 2 and ISO/IEC 27001:2022 by an independent third-party auditor, and can provide its SOC 2 report on request.

Future sub-processors (not yet in use)