Skip to content
AI Digital Hub

Trust

Sub-processors

Every third party that touches data on our behalf, what it does and where. We publish this because it is the honest answer to 'where does my data go' — and because your compliance team will ask.

Last updated 1 July 2026 · Exinary Technologies Private Limited

Website and marketing

ProviderPurposeDataRegion
VercelWebsite hosting, edge delivery and serverless functionsRequest metadata, truncated IP addresses in logsGlobal edge, primary region configurable
AnthropicLanguage model powering the site assistantThe text you type into the assistantUnited States — contracted for zero retention, no training
ResendTransactional email — enquiry acknowledgements, receiptsName, email address, message contentUnited States / EU
StripePayment processing and hosted checkoutBilling name and address, payment metadata. Card data never reaches usGlobal, PCI DSS Level 1
Cal.comConsultation schedulingName, email, chosen timeEU / United States
PostHogAggregate product analyticsPage views, referrer, approximate region. No cross-site trackingEU
UpstashRate limiting and webhook idempotency storeTruncated IP addresses, event identifiers. No message contentConfigurable, EU or Asia-Pacific
SentryError monitoringStack traces and request context, with personal data scrubbedEU

Client engagements

Engagement sub-processors depend on the engagement, and are named specifically in your documentation rather than assumed from this list. The general shape:

CategoryPurposeDataRegion
Your cloud providerWe deploy into your AWS, Azure or GCP account by default, so your data stays in your own tenancyAs determined by your engagementYour chosen region
Model providersNamed explicitly in your engagement documentation. Always contracted for zero retention and no trainingOnly what the task requires, minimised and where possible de-identifiedPer engagement, in-region where residency requires it
Observability toolingTracing and evaluation for the systems we build for youRequest traces, with PII scrubbing configuredPer engagement

Our default is to deploy into your cloud account. That means for most engagements your data never enters our infrastructure at all, which is both better for you and simpler for both of our compliance teams.

Internal tools that do not touch client data

We use Google Workspace, GitHub, Slack, Linear and 1Password internally. Client personal data is not stored in these by policy — engagement data lives in the client’s own environment. They are listed for completeness rather than because they process your data.

Changes to this list

We give clients at least 30 days’ notice before adding or replacing a sub-processor that would touch their data. You may object on reasonable data protection grounds — see the Data Processing Addendum.

To be notified of changes, email [email protected] and ask to be added to the sub-processor notification list.

Questions?

Email [email protected] for anything about data or these policies, or [email protected] for security matters. See also our security page.