Change notification
We give customer firms at least 30 days' notice before adding or replacing a sub-processor. Notice is delivered via an in-app banner shown to firm admin seats and an email to the firm's billing contact, and this page is updated on the same date.
Firm admins who want sub-processor change notifications by email at a specified inbox can subscribe by writing to privacy@mpscompare.co.uk.
Supabase
DPA →- Purpose
- Database hosting, authentication, object storage (PDF exports).
- Data processed
- All controller personal data and all generated PDFs. Audit-trail rows, account profiles, firm metadata, snapshot data.
- Region
- eu-west-2 (London, United Kingdom)
Vercel
DPA →- Purpose
- Application hosting and CDN edge runtime.
- Data processed
- Request metadata, authentication cookies (in transit), edge logs (IP, user agent, route). No personal data is persisted at this layer; storage runs to Supabase.
- Region
- Europe (edge pinned to LHR1 / London)
Cloudflare
DPA →- Purpose
- Bot and abuse protection (Turnstile) on the sign-in and password-reset forms.
- Data processed
- Visitor IP address and browser interaction signals collected when the challenge widget runs on an authentication page. No account profile, firm, or client data. Cloudflare returns a pass/fail token only; it does not receive credentials.
- Region
- United States (Cloudflare, Inc.; served from its global edge)
Resend
DPA →- Purpose
- Transactional email delivery: authentication messages (password reset, account set-up) via our authentication provider’s SMTP relay, and firm seat-invitation emails sent directly by the application.
- Data processed
- The recipient adviser's email address and the contents of the transactional email (a single-use invitation or set-password link). No client data; these emails never contain client-identifying information.
- Region
- United States (Resend, Inc.)
Anthropic
DPA →- Purpose
- Large language model API behind the AI drafting and insight features on paid adviser tiers.
- Data processed
- No personal data. Requests carry only anonymised strategy catalogue data, figures computed by the platform, and adviser drafting instructions. Advisers are instructed not to enter client-identifying information, and no platform input field accepts client data. Prompts and outputs are not used to train Anthropic models under our commercial terms.
- Region
- United States (API processing; requests designed to carry no personal data)
Sentry
DPA →- Purpose
- Application error monitoring: capturing unhandled exceptions so faults are detected and diagnosed.
- Data processed
- Technical error diagnostics only: exception type, stack trace, the route that failed, browser and release version. Request bodies, query parameters and form values are stripped by the application before transmission, along with cookies, request headers and IP addresses. The platform collects no client personal data, so none can reach Sentry.
- Region
- European Union (Frankfurt, Germany; Functional Software, Inc.)
International transfers
Our core data store, application hosting, and error monitoring are located in the United Kingdom or the European Economic Area: Supabase (London), Vercel (edge pinned to London), and Sentry (Frankfurt). Three sub-processors operate from the United States, each processing a narrow, defined data set:
- Anthropic — AI requests are designed to carry no personal data: only anonymised catalogue data, platform-computed figures, and adviser drafting instructions.
- Cloudflare — receives a visitor's IP address and challenge-interaction signals when the anti-bot widget runs on an authentication page, and returns only a pass/fail result.
- Resend — relays authentication emails, so it processes the recipient adviser's email address and the message contents (a single-use link). No client data is ever contained in these emails.
None of these transfers involves end-client personal data. As a safeguard, each provider's data processing addendum incorporates the EU Standard Contractual Clauses together with the ICO's International Data Transfer Addendum, so any personal data reaching a US sub-processor remains covered by a UK-recognised transfer mechanism. If we ever propose to appoint a further sub-processor outside the UK / EEA to process personal data, the change-notification process above applies.
Contact
Questions about a sub-processor on this list: privacy@mpscompare.co.uk. Objections to a proposed new sub-processor should also be sent to that address within the 30-day notice window described in the DPA §6.