Legal · GDPR Article 28
Sub-processors
We use a small set of trusted third parties to deliver Proprietas. Each one is bound by a written data-processing agreement and is assessed annually. We give account admins 30 days' notice before adding or replacing any sub-processor.
Last reviewed 4 August 2026.
Proprietas Technologies, Inc.
Their privacy policy ↗- Purpose
- US parent company. Provides platform engineering, operations and customer support for the service on behalf of Proprietas Technologies UK Ltd.
- Data categories
- Administrative and support access to the application database and object storage, which can include any customer data held in them.
- Jurisdiction
- United States (Delaware)
- Transfer mechanism
- Intra-group data transfer agreement incorporating the UK International Data Transfer Addendum and EU Standard Contractual Clauses.
OpenAI, LLC
Their privacy policy ↗- Purpose
- AI document extraction and the in-app assistant, reads uploaded PDFs (leases, compliance certificates) to return structured fields, and answers questions about your workspace.
- Data categories
- Document contents (which may include tenant names, contractor numbers, building addresses) and assistant prompts. Not used to train models.
- Jurisdiction
- United States
- Transfer mechanism
- EU-US Data Privacy Framework, with EU Standard Contractual Clauses and the UK International Data Transfer Addendum as fallback.
Anthropic, PBC
Their privacy policy ↗- Purpose
- Standby AI provider for the same extraction and assistant functions. Not in active use; listed so it can be enabled without waiting out the 30-day notice period if OpenAI is unavailable.
- Data categories
- Document contents and assistant prompts, only while enabled.
- Jurisdiction
- United States
- Transfer mechanism
- EU Standard Contractual Clauses + UK International Data Transfer Addendum (IDTA).
Stripe Payments UK, Ltd.
Their privacy policy ↗- Purpose
- Subscription billing, invoicing, payment-method storage.
- Data categories
- Billing email, billing address, card last-4, payment history.
- Jurisdiction
- United Kingdom (data centre EU + US replica)
- Transfer mechanism
- EU Standard Contractual Clauses + UK IDTA for any US replica access.
Resend, Inc.
Their privacy policy ↗- Purpose
- Transactional email delivery (magic links, notifications, receipts).
- Data categories
- Recipient email address, email subject & body.
- Jurisdiction
- European Union (Ireland)
- Transfer mechanism
- EU adequacy, no transfer outside the UK/EU.
Cloudflare, Inc. (R2 storage)
Their privacy policy ↗- Purpose
- Object storage for uploaded PDFs, photos, and audit-pack exports.
- Data categories
- Customer-uploaded files which may include PII (tenant names, contractor details, signatures).
- Jurisdiction
- European Union jurisdiction (data stored in EU only).
- Transfer mechanism
- EU adequacy + EU SCCs for control-plane operations from Cloudflare US.
Railway Corporation
Their privacy policy ↗- Purpose
- Application + database hosting.
- Data categories
- Entire application database including encrypted PII columns and audit log.
- Jurisdiction
- United Kingdom (London region) / EU.
- Transfer mechanism
- No transfer outside the UK/EU.
Vercel, Inc.
Their privacy policy ↗- Purpose
- Frontend hosting, edge cache, build & deploy.
- Data categories
- HTTP request metadata (IP, user-agent, path) and any data the user submits via the web app.
- Jurisdiction
- Global edge network with US control plane.
- Transfer mechanism
- EU SCCs + UK IDTA.
Google Ireland Ltd. (Google Ads)
Their privacy policy ↗- Purpose
- Advertising measurement, attributes which ad campaigns lead to sign-ups. Runs only on public marketing pages, only after advertising consent is granted; never loaded inside the signed-in app.
- Data categories
- Visitor advertising identifiers and conversion signals (ad click, sign-up/scan/lead conversion events). No account, workspace, or document data.
- Jurisdiction
- European Union (Ireland) with US control plane.
- Transfer mechanism
- EU SCCs + UK IDTA. Consent Mode v2, runs cookieless/modelled until the visitor grants advertising consent.
PostHog, Inc. (EU Cloud)
Their privacy policy ↗- Purpose
- Product and web analytics, measures feature usage, funnels, and traffic to improve the product. First-party via a same-origin proxy; autocapture and session replay are disabled.
- Data categories
- Pseudonymous usage events keyed to an internal user id and organisation id, with structural properties only (role, tier, event/feature counts, page paths). No document contents, names, emails, addresses, or free text.
- Jurisdiction
- European Union (PostHog Cloud EU, Frankfurt, Germany).
- Transfer mechanism
- EU data residency, events are stored in the EU. EU SCCs + UK IDTA cover any control-plane access from PostHog US.
Change notifications
To subscribe to changes, account admins receive a transactional email from Proprietas at least 30 days before a sub-processor is added or replaced. If you object to a new sub-processor you can terminate your subscription before the change takes effect and receive a pro-rata refund of the unused balance.
Questions: privacy@proprietas.app · See also our Privacy Policy.