Skip to content
Legal · Sub-processor register

Sub-processors

The third parties MPS Compare uses to deliver the service. This register is referenced from our data processing agreement and is the authoritative list.

Last updated 12 August 2026

Change notification

We give customer firms at least 30 days' notice before adding or replacing a sub-processor. Notice is delivered via an in-app banner shown to firm admin seats and an email to the firm's billing contact, and this page is updated on the same date.

Firm admins who want sub-processor change notifications by email at a specified inbox can subscribe by writing to privacy@mpscompare.co.uk.

Supabase

DPA →
Purpose
Database hosting, authentication, object storage (PDF exports).
Data processed
All controller personal data and all generated PDFs. Audit-trail rows, account profiles, firm metadata, snapshot data.
Region
eu-west-2 (London, United Kingdom)

Vercel

DPA →
Purpose
Application hosting and CDN edge runtime.
Data processed
Request metadata, authentication cookies (in transit), edge logs (IP, user agent, route). No personal data is persisted at this layer; storage runs to Supabase.
Region
Europe (edge pinned to LHR1 / London)

Cloudflare

DPA →
Purpose
Bot and abuse protection (Turnstile) on the sign-in and password-reset forms.
Data processed
Visitor IP address and browser interaction signals collected when the challenge widget runs on an authentication page. No account profile, firm, or client data. Cloudflare returns a pass/fail token only; it does not receive credentials.
Region
United States (Cloudflare, Inc.; served from its global edge)

Resend

DPA →
Purpose
Transactional email delivery: authentication messages (password reset, account set-up) via our authentication provider’s SMTP relay, and firm seat-invitation emails sent directly by the application.
Data processed
The recipient adviser's email address and the contents of the transactional email (a single-use invitation or set-password link). No client data; these emails never contain client-identifying information.
Region
United States (Resend, Inc.)

Anthropic

DPA →
Purpose
Large language model API behind the AI drafting and insight features on paid adviser tiers.
Data processed
No personal data. Requests carry only anonymised strategy catalogue data, figures computed by the platform, and adviser drafting instructions. Advisers are instructed not to enter client-identifying information, and no platform input field accepts client data. Prompts and outputs are not used to train Anthropic models under our commercial terms.
Region
United States (API processing; requests designed to carry no personal data)

Sentry

DPA →
Purpose
Application error monitoring: capturing unhandled exceptions so faults are detected and diagnosed.
Data processed
Technical error diagnostics only: exception type, stack trace, the route that failed, browser and release version. Request bodies, query parameters and form values are stripped by the application before transmission, along with cookies, request headers and IP addresses. The platform collects no client personal data, so none can reach Sentry.
Region
European Union (Frankfurt, Germany; Functional Software, Inc.)

International transfers

Our core data store, application hosting, and error monitoring are located in the United Kingdom or the European Economic Area: Supabase (London), Vercel (edge pinned to London), and Sentry (Frankfurt). Three sub-processors operate from the United States, each processing a narrow, defined data set:

  • Anthropic — AI requests are designed to carry no personal data: only anonymised catalogue data, platform-computed figures, and adviser drafting instructions.
  • Cloudflare — receives a visitor's IP address and challenge-interaction signals when the anti-bot widget runs on an authentication page, and returns only a pass/fail result.
  • Resend — relays authentication emails, so it processes the recipient adviser's email address and the message contents (a single-use link). No client data is ever contained in these emails.

None of these transfers involves end-client personal data. As a safeguard, each provider's data processing addendum incorporates the EU Standard Contractual Clauses together with the ICO's International Data Transfer Addendum, so any personal data reaching a US sub-processor remains covered by a UK-recognised transfer mechanism. If we ever propose to appoint a further sub-processor outside the UK / EEA to process personal data, the change-notification process above applies.

Contact

Questions about a sub-processor on this list: privacy@mpscompare.co.uk. Objections to a proposed new sub-processor should also be sent to that address within the 30-day notice window described in the DPA §6.