Skip to main content
    Legal

    Sub-processors

    Under UK GDPR Article 28(2), Recordme as a data processor must obtain controller authorisation before engaging sub-processors, and under Article 28(4) must impose equivalent data-protection obligations on each sub-processor. This page lists every third-party organisation that processes personal data on Recordme’s behalf as of the last-reviewed date below.

    Controller notification: if you are a data controller using Recordme and wish to receive advance notice of sub-processor changes (as required under a typical Art-28 contract), please email [email protected] to register for sub-processor change notifications. We aim to give at least 14 days’ advance notice of material changes.

    International transfers are protected by one or more of: a UK adequacy decision (Art-45), the UK-US Data Bridge (Art-46 — the UK Extension to the EU-US Data Privacy Framework, in force 12 October 2023), or a UK International Data Transfer Agreement / Addendum to Standard Contractual Clauses (Art-46(2)(c)).

    For further detail on how we handle international transfers, see our Privacy Policy (§6) and our Data Processing Agreement.

    Hetzner Online GmbH

    UK Adequacy
    Service
    Cloud hosting — compute (CPX22 staging, CCX23 production), Hetzner Object Storage (S3-compatible, Falkenstein) for file uploads. All Recordme application data at rest is stored on Hetzner infrastructure in Germany.
    Data processed
    AID, TUE, BIL, EML, AIL, OPS — all personal data processed by Recordme transits or rests on Hetzner compute.
    Processing region
    Germany (Nuremberg NBG1 + Falkenstein FSN1) — EU
    Transfer mechanism
    UK Adequacy Decision — EEA / EU (no transfer outside UK-adequate territory). Germany is an EU member state; the UK has retained adequacy for the EEA.
    Sub-processor DPA / privacy terms
    www.hetzner.com/AV/DPA_en.pdf

    Coolify Cloud (Andras Bacsai)

    UK AdequacyOPERATOR-CONFIRM
    Service
    Deployment control plane — manages container orchestration, environment variables, and deployment triggers on Hetzner VMs. Coolify Cloud holds deployment metadata and encrypted secrets injected into containers at runtime.
    Data processed
    OPS — deployment metadata, encrypted environment variable values (including secrets that indirectly protect personal data). Coolify Cloud does not receive or process tenant personal data directly.
    Processing region
    EU (Coolify Cloud infrastructure; Hetzner VMs remain operator-controlled in DE)
    Transfer mechanism
    UK Adequacy Decision — EEA / EU (EU-hosted control plane).
    Sub-processor DPA / privacy terms
    coolify.io/privacy

    Stripe, Inc.

    UK-US Data Bridge
    Service
    Payment processing and subscription billing — Stripe processes payment method data, billing addresses, and subscription lifecycle events. Recordme passes billing contact details to Stripe; raw card data never reaches Recordme servers.
    Data processed
    BIL, AID — billing contact name, email, organisation, payment method metadata (last 4 digits, card type, expiry). No food-safety or workforce personal data is shared with Stripe.
    Processing region
    United States (primary processing region), with EU data residency options per Stripe's configuration
    Transfer mechanism
    UK-US Data Bridge — Stripe, Inc. is certified under the UK Extension to the EU-US Data Privacy Framework (DPF). Verified at stripe.com/legal/privacy-center.
    Sub-processor DPA / privacy terms
    stripe.com/legal/dpa

    Resend, Inc.

    UK AdequacyOPERATOR-CONFIRM
    Service
    Transactional email delivery — all platform-generated emails (invitations, password resets, notifications, broadcast communications) are sent via Resend. EU region (Frankfurt) selected for data-residency parity.
    Data processed
    EML, AID — recipient email address, name (where included in email body), and email content (notification payload).
    Processing region
    EU (Frankfurt, eu-west-1) — Resend EU region selected per LOCKED-DECISIONS S12 for data-residency parity with Hetzner Nuremberg
    Transfer mechanism
    UK Adequacy Decision — EEA / EU (EU processing endpoint selected). Where Resend infrastructure traverses US systems, Resend's DPA safeguards apply — operator to confirm Resend's current UK-US Data Bridge (DPF) certification status.
    Sub-processor DPA / privacy terms
    resend.com/legal/dpa

    Google LLC (Google Identity / OAuth 2.0)

    UK-US Data Bridge
    Service
    Single sign-on (SSO) via Google OAuth 2.0 — users who choose 'Sign in with Google' authenticate via Google's identity platform. Google receives the OAuth flow metadata; Recordme receives only the verified identity token.
    Data processed
    AID — email address, display name, and Google account identifier passed in the OAuth identity token. No workforce, food-safety, or billing data is shared with Google Identity.
    Processing region
    United States (Google Identity global infrastructure)
    Transfer mechanism
    UK-US Data Bridge — Google LLC is certified under the UK Extension to the EU-US Data Privacy Framework. Verified at google.com/privacy/ads-data-protection/.
    Sub-processor DPA / privacy terms
    cloud.google.com/terms/data-processing-addendum

    Google LLC (Gemini AI — Google AI Studio / Gemini API)

    UK-US Data BridgeOPERATOR-CONFIRM
    Service
    Powers "Ask RME", Recordme's in-app AI chat assistant — off by default and switched on per organisation by an owner (a UK GDPR Art-28(3)(a) processing instruction). When on, an authorised team member's typed question, and Recordme's reply, are sent to the Gemini API to generate an answer. Ask RME answers ONLY by calling a fixed set of permission-scoped internal tools that return aggregate figures and statuses about the organisation's own compliance/operations records (e.g. counts, dates, pass/fail) — it cannot query the database directly. IMPORTANT: the tool RESULTS sent to Gemini are aggregate/status data, but the USER'S OWN TYPED QUESTION is sent to Gemini as free text and is not filtered, scanned, or redacted before it leaves Recordme — a user who types a named individual's health or other special-category detail into a question sends that text to Google. As of this review, Ask RME is not reachable by any customer: it sits behind four independent fail-closed gates (a platform rollout flag, this organisation-level opt-in switch, the per-user permission, and the plan-tier gate) that all default OFF.
    Data processed
    AIL — AI interaction logs, in two parts. (a) The user's own typed question and the assistant's reply — stored as free text and NOT pre-filtered, so it may contain AID and may contain special-category data if the user chooses to type it. (b) The aggregate/status data the assistant retrieves from Recordme on the user's behalf via permission-scoped tools, which never includes a raw customer or employee record. Recordme's operational policy requires a paid Gemini API key (not the free tier); Google does not use paid-tier data to train models per the Gemini API Terms of Service (verified May 2026). A stronger "no data retention" commitment is shown to customers in-app when they opt in — this review has not found a signed vendor agreement in this repository substantiating that specific commitment; see the DPIA (docs/legal/DPIA-ASK-RME.md) for the open item.
    Processing region
    United States (Gemini API infrastructure)
    Transfer mechanism
    UK-US Data Bridge — Google LLC is certified under the UK Extension to the EU-US Data Privacy Framework. Standard Contractual Clauses (UK IDTA addendum) also available via Google Cloud DPA. Feature is subject to explicit controller instruction (opt-in, toggled per organisation by an owner) per UK GDPR Art-28(3)(a).
    Sub-processor DPA / privacy terms
    cloud.google.com/terms/data-processing-addendum

    Functional Software, Inc. (Sentry)

    UK-US Data Bridge
    Service
    Error tracking and performance monitoring — Sentry captures application errors, stack traces, and performance metrics to support platform reliability. Sentry is configured to minimise PII capture; error payloads are scrubbed before transmission.
    Data processed
    TUE — error stack traces, request metadata, browser/OS type, and anonymised user context (internal user ID only, not name or email). Sentry is configured with PII scrubbing rules; no raw personal data should appear in error payloads.
    Processing region
    United States (Sentry cloud infrastructure); Frankfurt region project provisioned for data-residency parity per ENV-VARS §2.1
    Transfer mechanism
    UK-US Data Bridge — Functional Software, Inc. (Sentry) is certified under the UK Extension to the EU-US Data Privacy Framework. Standard Contractual Clauses also available via Sentry's DPA.
    Sub-processor DPA / privacy terms
    sentry.io/legal/dpa

    GitHub, Inc. (a Microsoft subsidiary)

    UK-US Data Bridge
    Service
    Source code hosting and container registry — Recordme's application source code is stored in private GitHub repositories. GitHub Container Registry (GHCR) stores Docker images built by GitHub Actions CI/CD pipelines. No tenant personal data is processed by GitHub.
    Data processed
    SRC — source code and Docker build artefacts only. GitHub does not process Recordme tenant personal data (no AID, TUE, BIL, EML, or AIL).
    Processing region
    United States (GitHub global infrastructure)
    Transfer mechanism
    UK-US Data Bridge — GitHub, Inc. (Microsoft) is certified under the UK Extension to the EU-US Data Privacy Framework. Standard Contractual Clauses also available via GitHub's DPA. Note: this is an operator-infrastructure sub-processor; no tenant personal data transits GitHub.

    Cloudflare, Inc.

    UK-US Data BridgeOPERATOR-CONFIRM
    Service
    DNS proxy, edge protection, CDN, and TLS termination — Cloudflare sits in front of Recordme's origin servers (Hetzner) to provide DDoS mitigation, WAF rules, bot management, and CDN caching for static assets. DNS migration is planned but was deferred post-MVP (LOCKED-DECISIONS S14).
    Data processed
    TUE — IP addresses and HTTP request metadata (headers, URLs) processed at the edge. Cloudflare does not see decrypted application payloads in standard proxy mode.
    Processing region
    United States (Cloudflare global edge network); EU edge nodes used for EU-origin requests
    Transfer mechanism
    UK-US Data Bridge — Cloudflare, Inc. is certified under the UK Extension to the EU-US Data Privacy Framework. Standard Contractual Clauses also available via Cloudflare's DPA.
    Sub-processor DPA / privacy terms
    www.cloudflare.com/cloudflare-customer-dpa

    Axiom, Inc.

    UK IDTA / SCCsOPERATOR-CONFIRM
    Service
    Log aggregation and metric observability — application logs and metrics from the Recordme API and worker processes are shipped to Axiom for operational monitoring and debugging. Per ENV-VARS §2.7.
    Data processed
    TUE — application log lines (structured JSON logs with internal request IDs, error codes, timing). Logs are configured to exclude raw PII; internal user IDs may appear in structured log fields.
    Processing region
    United States (Axiom cloud infrastructure)
    Transfer mechanism
    Standard Contractual Clauses (UK IDTA addendum) — Axiom provides SCCs via its DPA. Operator to confirm DPF certification status.
    Sub-processor DPA / privacy terms
    axiom.co/terms

    Data-category key

    AID
    Account & identity data (name, email, job title, organisation)
    TUE
    Technical usage & error data (stack traces, request logs, IP addresses)
    BIL
    Billing & payment data (plan tier, invoice amounts; no raw card numbers)
    EML
    Email content (notification body, recipient address)
    SRC
    Source code & build artefacts (no personal data at rest)
    OPS
    Operator configuration & deployment metadata
    AIL
    AI interaction logs (prompts & responses from the "Ask RME" chat assistant — opt-in feature)

    Last reviewed: 1 September 2026 (Gemini AI entry corrected — see docs/legal-reviews/2026-09-01-sub-processors-correction.md), for consistency with current UK law, by Claude Fable 5 (AI) — not a solicitor. Hetzner's DPA link was corrected 2 September 2026 after an unauthenticated link audit found it 404ing; the replacement was verified live before publishing. To register for sub-processor change notifications, or to raise any concern about this list, email [email protected]. This page will be updated before any new sub-processor is engaged. Entries marked OPERATOR-CONFIRM are confirmed in infrastructure documentation but require operator verification of the precise transfer mechanism; independent solicitor review of the international-transfer position is planned before we scale beyond our pilot phase.