> Reviewed against current UK law; under ongoing internal review. Not formal legal advice.
Last updated: 17 July 2026
OptitechAutomation — a UK sole trader (the personal business of Cristian Moise-Putanu), based in Torquay, Devon, United Kingdom — uses the following sub-processors to operate the platform. Each sub-processor is engaged under a Data Processing Agreement or equivalent contractual safeguard.
This list is maintained in accordance with our Data Processing Agreement, which grants Controllers the right to object to new sub-processors within 30 days of notification.
Current Sub-Processors
Supabase Inc.
- Purpose: Database hosting, authentication, and real-time infrastructure.
- Data categories: All personal data stored on the platform (names, emails, phone numbers, booking records, worker profiles).
- Location: European Union — Republic of Ireland (Dublin), AWS eu-west-1.
- Safeguards: UK-to-EEA transfer under the UK adequacy regulations for the EEA (UK GDPR Art. 45 / DPA 2018 s.17A); SOC 2 Type II certified.
- Website: supabase.com
Stripe Inc.
- Purpose: Payment processing, subscription management, Stripe Connect for worker payouts.
- Data categories: Payment card tokens, transaction references, billing email addresses.
- Location: United States / United Kingdom (Stripe Payments UK Ltd is the UK contracting entity); PCI-DSS Level 1 certified.
- Safeguards: UK Extension to the EU-US Data Privacy Framework (the "UK-US Data Bridge") for US processing where Stripe is DPF-certified; UK Addendum to the EU Standard Contractual Clauses as fallback; PCI-DSS Level 1 compliance.
- Website: stripe.com
Resend Inc.
- Purpose: Transactional email delivery (booking confirmations, reminders, worker notifications).
- Data categories: Email addresses, names, booking reference numbers, email content.
- Location: United States.
- Safeguards: UK Extension to the EU-US Data Privacy Framework where certified (certification reference reviewed annually); otherwise the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
- Website: resend.com
Vercel Inc.
- Purpose: Application hosting, edge network, and deployment infrastructure.
- Data categories: IP addresses, request logs, technical performance data.
- Location: Global edge network; primary data processing in the United States.
- Safeguards: UK Extension to the EU-US Data Privacy Framework (the "UK-US Data Bridge"); UK Addendum to the EU Standard Contractual Clauses as fallback; SOC 2 Type II certified.
- Website: vercel.com
Upstash Inc.
- Purpose: Rate limiting and short-lived session caching.
- Data categories: IP addresses, rate limit counters (no personal content cached).
- Location: EU West (EEA).
- Safeguards: UK-to-EEA transfer under the UK adequacy regulations for the EEA (UK GDPR Art. 45); data retention set to minutes.
- Website: upstash.com
Sentry (Functional Software Inc.)
- Purpose: Application error monitoring and performance tracing.
- Data categories: Stack traces, error context, anonymised request metadata. No PII in error payloads by configuration.
- Location: United States.
- Safeguards: UK Extension to the EU-US Data Privacy Framework where certified; otherwise the ICO IDTA / UK Addendum to the EU SCCs; PII scrubbing enabled.
- Website: sentry.io
Anthropic PBC (Claude API)
- Purpose: AI website generation. When a business owner uses the website generator, the business facts they submit are sent to Anthropic's Claude API to draft website copy for that business.
- Data categories: The business facts the owner enters into the generator — for example trade type/niche, town, service areas, unique selling point, and trading-since year. These are business-description fields rather than third-party customer personal data; owners are asked not to submit other people's personal data into the generator.
- Location: United States.
- Safeguards: UK Extension to the EU-US Data Privacy Framework where Anthropic is certified; otherwise the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment. Anthropic's commercial API terms state that data submitted via the API is not used to train its models. [SOLICITOR TO CONFIRM: current Anthropic Commercial Terms / DPA reference and DPF certification status at launch.]
- Website: anthropic.com
Groq, Inc. (Groq Cloud API)
- Purpose: AI drafting and triage for our own sales correspondence. When a business replies to an email we have sent, the reply is passed to Groq's API so it can be summarised and a suggested response drafted for a human to review. Groq is also used to draft outreach text. Nothing Groq produces is sent to anyone without a person approving it first.
- Data categories: The business contact details held in our own sales pipeline (business name, contact name, work email address, website, trade and area) and the content of email correspondence that business sends to us, which may include whatever personal information the sender chooses to put in their message.
- Applies to: Our own prospective-customer correspondence. This sub-processor is not part of the platform service delivered to a Business, and no Business's own customer, worker or booking data is sent to Groq.
- Location: United States.
- Safeguards: [SOLICITOR TO CONFIRM: transfer mechanism for Groq, Inc. — UK Extension to the EU-US Data Privacy Framework if certified, otherwise the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, plus a transfer risk assessment; and the current Groq Cloud terms position on the use of submitted data for model training.]
- Website: groq.com
Intuition Machines, Inc. (hCaptcha)
- Purpose: Distinguishing genuine visitors from automated abuse on public forms such as booking, signup, sign-in and review submission, so that automated traffic cannot flood a Business's calendar or our messaging costs.
- Data categories: IP address, browser and device characteristics, and interaction signals collected during the challenge. No account content is sent.
- Location: United States.
- Safeguards: [SOLICITOR TO CONFIRM: transfer mechanism for Intuition Machines, Inc. — UK Extension to the EU-US Data Privacy Framework if certified, otherwise the ICO IDTA or the UK Addendum to the EU Standard Contractual Clauses, plus a transfer risk assessment; and whether the challenge is served on a lawful basis of legitimate interests or requires consent in our configuration.]
- Website: hcaptcha.com
Conditionally Engaged (BYO — Business-Provided)
Some Businesses choose to connect their own integrations. In these cases, the Business acts as the Controller for that sub-processor relationship:
- Resend (BYO): Business-provided Resend API key for branded customer emails. The Business is responsible for its own DPA with Resend.
- Twilio (BYO): Business-provided Twilio account for SMS notifications. The Business is responsible for its own DPA with Twilio.
Changes to This List
We will provide 30 days' prior written notice of any addition or replacement of sub-processors by updating this page and notifying affected Businesses. During this period, you may object to the new sub-processor in accordance with Section 6 of the Data Processing Agreement.
Contact
OptitechAutomation — Cristian Moise-Putanu (sole trader)
Torquay, Devon, United Kingdom
privacy@optitechautomation.co.uk