Trust
Sub-processors
Every third party that touches data on our behalf, what it does and where. We publish this because it is the honest answer to 'where does my data go' — and because your compliance team will ask.
Last updated 1 July 2026 · Exinary Technologies Private Limited
Website and marketing
| Provider | Purpose | Data | Region |
|---|---|---|---|
| Vercel | Website hosting, edge delivery and serverless functions | Request metadata, truncated IP addresses in logs | Global edge, primary region configurable |
| Anthropic | Language model powering the site assistant | The text you type into the assistant | United States — contracted for zero retention, no training |
| Resend | Transactional email — enquiry acknowledgements, receipts | Name, email address, message content | United States / EU |
| Stripe | Payment processing and hosted checkout | Billing name and address, payment metadata. Card data never reaches us | Global, PCI DSS Level 1 |
| Cal.com | Consultation scheduling | Name, email, chosen time | EU / United States |
| PostHog | Aggregate product analytics | Page views, referrer, approximate region. No cross-site tracking | EU |
| Upstash | Rate limiting and webhook idempotency store | Truncated IP addresses, event identifiers. No message content | Configurable, EU or Asia-Pacific |
| Sentry | Error monitoring | Stack traces and request context, with personal data scrubbed | EU |
Client engagements
Engagement sub-processors depend on the engagement, and are named specifically in your documentation rather than assumed from this list. The general shape:
| Category | Purpose | Data | Region |
|---|---|---|---|
| Your cloud provider | We deploy into your AWS, Azure or GCP account by default, so your data stays in your own tenancy | As determined by your engagement | Your chosen region |
| Model providers | Named explicitly in your engagement documentation. Always contracted for zero retention and no training | Only what the task requires, minimised and where possible de-identified | Per engagement, in-region where residency requires it |
| Observability tooling | Tracing and evaluation for the systems we build for you | Request traces, with PII scrubbing configured | Per engagement |
Our default is to deploy into your cloud account. That means for most engagements your data never enters our infrastructure at all, which is both better for you and simpler for both of our compliance teams.
Internal tools that do not touch client data
We use Google Workspace, GitHub, Slack, Linear and 1Password internally. Client personal data is not stored in these by policy — engagement data lives in the client’s own environment. They are listed for completeness rather than because they process your data.
Changes to this list
We give clients at least 30 days’ notice before adding or replacing a sub-processor that would touch their data. You may object on reasonable data protection grounds — see the Data Processing Addendum.
To be notified of changes, email [email protected] and ask to be added to the sub-processor notification list.
Questions?
Email [email protected] for anything about data or these policies, or [email protected] for security matters. See also our security page.