Subprocessors

Third parties acclr8 / accelereight engages to deliver the Service

Under GDPR Art. 28 we're required to disclose every party we share personal data with. The list below is current as of 2026-05-20. We update it before engaging new subprocessors and notify active customers by email at least 14 days in advance of any change.

SubprocessorPurposeDataLocationDPA
AnthropicAI language model — generates and verifies repliesCustomer messages, business profile, conversation historyUnited States (SCCs applied)DPA ↗
OpenAIEmbedding generation for RAG retrievalKnowledge base text chunks (not customer messages)United States (SCCs applied)DPA ↗
NeonPostgres database hostingAll application data (workspace-scoped, encrypted at rest)European Union (London region)DPA ↗
VercelApplication + edge hostingHTTP request logs, application codeEuropean UnionDPA ↗
ClerkAuthentication, session managementAccount email, password hash, session tokensUnited States (SCCs applied)DPA ↗
PostmarkTransactional email delivery (inbound + outbound)Email addresses, subject lines, message bodyEuropean Union (EU servers)DPA ↗
StripeBilling, payment processingBilling email, payment method (held by Stripe)United States / European UnionDPA ↗
Meta PlatformsWhatsApp / Messenger / Instagram channel integrationMessages sent to your connected Meta accounts, channel access tokensUnited States / European UnionDPA ↗

Cross-border transfers

Where data is transferred outside the UK/EU (notably to Anthropic, OpenAI, Clerk, and Stripe in the US), we rely on Standard Contractual Clauses (SCCs) and supplementary measures (encryption in transit, no training on data) as required by the Schrems II ruling.

No training

Anthropic, OpenAI, and the other AI providers we use do not train their models on data sent via their commercial APIs. This is contractually binding under their published API data policies.

Contact

Questions about subprocessors? Email info@accelereight.net.