Sub-processor register
Last updated 27 July 2026. This is the definitive, current list of sub-processors Knownfor uses to deliver the platform — the list our Privacy policy and Data Processing Agreement both point to, so it only has to be kept accurate in one place.
Current sub-processors
A few of these are optional and only come into play once an account owner connects that specific integration for their own account — marked below. Everyone else on this list is used to run the core platform for every account.
| Sub-processor | Purpose | Personal data categories | Location / transfer safeguard |
|---|---|---|---|
| Vercel | Application hosting, edge network and infrastructure. | All personal data that transits or is cached by the platform (account, user and client customer data, as applicable). | US / global — UK IDTA or UK Extension to the EU SCCs. |
| Neon | Managed Postgres database — the platform's primary data store. | All personal data stored by the platform. | London / EEA region — in-region, no transfer required. |
| Vercel Blob | File storage for client portal uploads. | Whatever personal data appears in a file an account owner or client customer uploads to a portal. Files are private by default with no public URL. | US / global — UK IDTA or UK Extension to the EU SCCs. |
| Anthropic | AI drafting features (e.g. turning a described process into a structured procedure) — only where an account has AI switched on. | Prompt content, which may include personal data an account owner chooses to include in it. | US — UK IDTA or UK Extension to the EU SCCs. |
| Resend | Transactional and marketing email delivery. | Recipient name, email address, and message content. | US — UK IDTA or UK Extension to the EU SCCs. |
| Sentry | Error monitoring and diagnostics. | Technical and error data, which may incidentally include a user identifier or request details present at the time of an error. | EU region — in-region, no transfer required. |
| PostHog | Product analytics. | Usage and event data tied to an account or user. | EU region — in-region, no transfer required. |
| Stripe | Subscription billing and payment processing. | Billing name, email, and payment details. Card numbers are handled directly by Stripe and never reach our servers. | US, with UK/EU processing entities — UK IDTA or UK Extension to the EU SCCs. |
| HubSpot | Optional CRM sync — pushes lead and deal contact data into the account owner's own HubSpot account. Only active once an account owner connects it with their own HubSpot private-app token. | Contact name, email address, company, and deal/value details. | US — UK IDTA or UK Extension to the EU SCCs. |
| FreeAgent | Optional accounting sync — pushes invoice and client contact data into the account owner's own FreeAgent account. Only active once an account owner completes the FreeAgent connection. | Client/contact name, email address, and invoice line items and amounts. | UK — in-region, no transfer required. |
| Companies House | Public company register lookup, used for company search and enrichment. | The search term typed by the user (a company name or number). The response is public register data already published by Companies House (company status, registered address, incorporation date) — we do not submit further personal data to them. | UK — public government register, no transfer required. |
Changes to this list
If we add or replace a sub-processor that handles client customer data, we'll update this page and notify account owners (by email or in-app) before the change takes effect, so you have the chance to review it or object on reasonable data-protection grounds under our DPA.
Contact
Questions about this register should go to ryan@thethirtyco.com.