Sub-processors
Last updated: {{updated}}
Vendors that may process personal data on behalf of {{company}}. Fill in with real vendors before publishing to production.
Template document, aligned with the UK GDPR, the Data Protection Act 2018 and the Online Safety Act 2023. Have it reviewed by UK legal counsel before official publication.
Vendor categories
- Hosting and infrastructure — account data, content and logs
- Authentication — e-mail, identifiers and logs
- Safety and moderation — content, reports and risk signals
- Analytics — usage events (under consent)
- User support — contact and tickets
- Age assurance — minimal age data
- Payments (if applicable) — payment data
For each vendor
We document: name, purpose, data categories, country/region and international transfer mechanism (adequacy, IDTA or SCCs with Addendum).
Changes
We update this list periodically. Material changes are reflected here and, where required, notified. Questions: {{email_privacy}}.