A sub-processor is a company we use that may process personal data you put into The Job Planner (your "Customer Personal Data"), on our behalf. Our commitments about them are in section 6 of our Data Processing Addendum. Some of these providers also process our own account and website data — see our privacy notice.
Core providers
These are used for every account.
| Provider | What they do for us | Data they process | Where | How transfers are protected |
|---|---|---|---|---|
| Vercel Inc. | Hosts the website and app, and delivers them through its content delivery network | All data passing between your browser and the app, in transit; short-lived request logs | USA, with a global edge network; our application runs in an EU or UK region where configured | UK IDTA, under Vercel's DPA |
| Neon Inc. | Our main database, including backups and point-in-time restore | All data stored in the service | EU region | Data stored in the EEA, which the UK recognises as adequate; any onward access under Neon's DPA |
| Stripe Payments Europe Ltd and Stripe, Inc. | Subscription billing and card payments for your The Job Planner subscription | Account owner's name, email, billing details and card data (card data goes straight to Stripe and never reaches us) | Ireland and USA | EEA adequacy; for the USA, the UK Extension to the Data Privacy Framework or the UK IDTA, under Stripe's DPA |
| Resend | Sends transactional emails — sign-in links, notifications, and the job, quote and invoice emails you choose to send | Recipient name and email address, email content and attachments, delivery status | USA | UK Extension to the Data Privacy Framework, and the UK Addendum to the EU Standard Contractual Clauses, under Resend's DPA |
| Anthropic PBC | Provides the AI model behind AI features and the website assistant | Text sent to an AI feature — for example a customer's message, job, site and asset details — and the drafted reply. Website assistant questions (without IP address) | USA | UK Addendum to the EU Standard Contractual Clauses, under Anthropic's DPA. Anthropic's commercial terms say it may not train models on this data |
Optional providers
These are only used if you or your users switch the relevant feature on.
| Provider | What they do for us | Data they process | Where | How transfers are protected |
|---|---|---|---|---|
| Twilio Inc. | Sends SMS messages — only if your company turns on SMS | Recipient's mobile number, message content, delivery status | USA | UK Extension to the Data Privacy Framework, Twilio's Binding Corporate Rules, or the UK IDTA, under Twilio's DPA |
| Browser push services (Apple, Google, Mozilla — depending on the device and browser) | Deliver push notifications to phones and browsers — only if a user turns notifications on | A device address issued by the browser, and the notification (encrypted for delivery under the Web Push standard) | Varies by provider, including the USA | The push service is chosen by the user's browser or device and operates under that company's own terms and transfer safeguards |
Website only
This provider handles enquiries sent through our website. It doesn't process data you put into the app.
| Provider | What they do for us | Data they process | Where | How transfers are protected |
|---|---|---|---|---|
| Lead Capture AI | Runs the contact form and enquiry widget on our website, loaded only after the visitor consents | Name, contact details and message from people who send us an enquiry | See Lead Capture AI's privacy policy | See Lead Capture AI's privacy policy |
How we tell you about changes
- We'll give at least 30 days' notice before adding or replacing a sub-processor, by emailing account owners and updating this page (the date at the top will change).
- You can object on reasonable data protection grounds by emailing privacy@localhost within those 30 days. If we can't resolve your concern, you can close your account before the change takes effect and we'll refund any fees paid in advance for the unused period.
- If we have to replace a provider urgently — for example because it stops providing its service — we'll tell you as soon as we can, with the same right to object.
More about international transfers
Several of these providers are in the USA. UK law lets us send personal data there if the recipient is certified under the UK Extension to the EU–US Data Privacy Framework (the "UK–US data bridge"), or if an approved contract — the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — is in place, supported by a transfer risk assessment.
- ICO: How does the UK Extension to the EU-US Data Privacy Framework work?
- ICO: International transfers
- US Department of Commerce: Data Privacy Framework list — to check whether a US company is certified
We check each provider's safeguards when we take them on and when their terms change. Questions? Email privacy@localhost.