Sub-processors
Last updated
This is the complete list of third parties that process data on my behalf in running the business. Each is bound by a data processing agreement. It is published openly because enterprise security reviews always ask for it, and a page is faster than a questionnaire.
| Processor | Purpose | Data | Location |
|---|---|---|---|
| Cloudflare | Website hosting, CDN, DNS and DDoS protection | Server request data (IP, user agent, URL, timestamp) | Global edge; EU data localisation available |
| Resend | Transactional delivery of contact form submissions | Name, email, company, message content | EU / US, under SCCs |
| Google Workspace | Business email, documents and calendars | Business contact details and correspondence | EU region, under SCCs |
| GitHub | Source control for code I write during engagements | Code and configuration; no client personal data by policy | US, under SCCs |
| TODO invoicing provider | Invoicing and accounting | Client billing contacts and invoice records | EU |
During client engagements
No sub-processor is introduced into a client environment without written agreement. Model providers, vector databases and infrastructure used inside an engagement are chosen with the client and contracted by the client directly wherever possible, so that you hold the relationship and the exit rights. Anything contracted on your behalf is named in the engagement agreement.
Changes to this list
Existing clients are notified in writing at least 30 days before I add a sub-processor that would handle their data, with the opportunity to object. Email hello@rubradigital.com to be added to that notification list.