Sub-processors
The companies that process personal data on behalf of GovScape customers, what each one receives, and why. This list forms Annex B to our data processing agreement.
Last reviewed 9 September 2026
Draft — not yet published
This document is complete except for the facts below, which cannot be determined from the application and must be supplied before it is relied on:
- Registered company name of the operating entity
- Companies House company number
- Registered office address
- ICO registration reference (data protection fee)
- A monitored inbox for privacy and data subject requests
- Supabase project region — where the database, logins and uploaded files actually live
- Sentry data residency — currently the US, with AUD-44 open to move it to the EU
- Confirmation that a UK IDTA or SCC addendum is signed with every processor outside the UK
Filling in lib/legal/entity.ts removes this notice from every legal page.
A sub-processor is a company we engage that handles personal data belonging to a customer. We name every one of them here rather than describing them by category, because “cloud infrastructure providers” is not a sentence anyone can assess a risk against.
This page is generated from a register held in the application’s own source code, and an automated check fails the build if a new third-party service is added without appearing here, or if an entry names a service we no longer use. That check is the reason this page can be trusted to be current rather than merely recent.
Where processing happens
Application code runs in London, United Kingdom (Vercel region lhr1).
Processing locations marked “to be confirmed” below are set on hosting accounts rather than in the application, and are being verified. We would rather leave them open than state a region we have not checked; a data residency claim is exactly the kind of assurance a customer builds their own compliance position on.
Sub-processors
Supabase
Supabase, Inc.
Application database, user authentication, and file storage.
Personal data it receives
- Account records: email address, hashed password, display name, and multi-factor authentication enrolment.
- All governance records created in the product, including free-text fields naming accountable individuals.
- Uploaded policy and evidence files, and the text extracted from them.
- Audit records, which retain a snapshot of each changed row.
Processing location: To be confirmed — see the note at the top of this page.
Files are held in a single bucket, under paths scoped to the customer organisation.
Vercel
Vercel, Inc.
Application hosting, request routing, and scheduled jobs.
Personal data it receives
- All data in transit between the user and the application.
- Operational request logs, which include IP address and request path.
Processing location: London, United Kingdom (region lhr1)
Serverless functions are pinned to London in vercel.json. This fixes where code runs, not where data is stored.
Anthropic
Anthropic PBC
The AI models behind control extraction, document triage, briefing extraction and the in-product advisor.
Personal data it receives
- The full text of uploaded policy documents.
- Text extracted from files in a connected Microsoft 365 environment, where that connector is enabled.
- Transcripts of recorded briefings.
- Advisor conversations and the governance context shown alongside them.
Processing location: To be confirmed — see the note at the top of this page.
Document text is sent as written. It is not redacted or pseudonymised first, so a policy naming an individual is transmitted naming them.
OpenAI
OpenAI, L.L.C.
Speech-to-text transcription of recorded briefings.
Personal data it receives
- The audio recording itself, including every voice captured on it.
Processing location: To be confirmed — see the note at the top of this page.
This is the only place raw audio leaves the product. GovScape does not retain the audio; the returned transcript is stored and is subsequently processed by Anthropic. Anyone recording a call is responsible for the consent of everyone on it.
Resend
Plus Five Five, Inc. (Resend)
Transactional email.
Personal data it receives
- Recipient name and email address for team invitations, partner correspondence and enquiry notifications.
- Organisation names and headline figures included in internal notification emails.
Processing location: To be confirmed — see the note at the top of this page.
Sentry
Functional Software, Inc. (Sentry)
Error monitoring, performance tracing and session replay.
Personal data it receives
- Error reports and stack traces, which can contain fragments of the data being handled when the error occurred.
- Browser console output.
- Session replays: a reconstruction of the page and the interactions on it, for a sampled share of sessions and for every session in which an error occurs.
Processing location: To be confirmed — see the note at the top of this page.
Replays are captured with all text masked. Images and other media are not masked. Browser telemetry is routed through the application's own domain, which means an ad-blocker will not stop it.
Upstash
Upstash, Inc.
Rate limiting, to stop abuse of public forms and metered endpoints.
Personal data it receives
- A counter key, which is either the caller's IP address or an organisation identifier, held only for the length of the rate-limit window.
Processing location: To be confirmed — see the note at the top of this page.
Reached either directly or through Vercel KV, which is Upstash underneath. It is one processor, not two. This is the only place a caller's IP address is stored unhashed anywhere in the system, and it expires with the window.
Systems you connect yourself
These are not sub-processors. They are your own systems, which you may choose to connect, and which stay under your own agreement with the vendor. We list them because connecting one changes what data reaches the sub-processors above.
Microsoft
Customer-authorised sourceMicrosoft Corporation
Reading document metadata and content from a customer's own Microsoft 365 environment, where they choose to connect it.
Personal data it receives
- Authentication requests identifying the customer tenant. No GovScape customer data is written into Microsoft 365.
Processing location: The customer's own Microsoft 365 tenant
Listed for completeness rather than as a sub-processor: the data flows from the customer to us, under their own agreement with Microsoft, and only after an explicit consent grant. The disclosure that matters is the onward one — connecting Microsoft 365 causes file names, file paths, the email addresses of file owners, and the text of documents selected for review to be processed as described above, including by Anthropic.
Changes to this list
Customers with a signed data processing agreement are notified before a new sub-processor begins handling their data, and may object on reasonable data protection grounds. Write to sales@govscape.app to be added to that notification list.