Sub-processors
Effective .
Last updated 8 September 2026.
This document names every third party that processes personal data on our behalf, in the sense the GDPR uses the word: a sub-processor engaged by us as processor for a customer who is the controller of the prospect data in their workspace.
The current list
The list itself is on the trust page rather than in this document, and that is deliberate. It changes whenever a dependency changes, and a list maintained inside a legal document is a list that goes stale silently, months before anyone reads it closely enough to notice. The version on that page is generated from the application's own configuration, so updating it is part of the change that introduced the processor.
Each entry names the processor, what it is used for, what categories of data reach it, and where it processes them.
Notifying you of changes
We will publish an updated list before a new sub-processor begins processing, and the effective date at the top of this document moves when it does. Customers on a written agreement that requires advance notice will be emailed at the address on the account. If you need the wording of an earlier version, for example to check what was in force on a particular date, ask us and we will send it: every publication is kept, and the one you accepted is recorded against your account.
If you object to a new sub-processor on reasonable data-protection grounds, write to us before it takes effect. Where we cannot offer an alternative, you may terminate the affected part of the service and receive a pro-rata refund of anything paid in advance.
Transfers outside the UK, EU and India
Three processors on the list operate in the United States: the LLM provider used to draft outreach copy, Google, which measures a prospect's website performance and returns discovery results, and PostHog, which records how a workspace uses the application. Transfers to all three rely on the EU standard contractual clauses together with the UK addendum, and on our own transfer risk assessment.
The data that reaches them is narrow and worth stating precisely: the LLM provider receives audit findings and the public business details of the prospect being written to, Google receives website URLs and the search terms and locations a customer searched for, and PostHog receives a workspace identifier, a user identifier where one is signed in, the name of the action taken and the website domain it concerned. None of them receives your customer records, your credentials, or the contents of your workspace beyond that.
None of the three is permitted to use what it receives to train models. The LLM provider and Google retain nothing beyond what is required to return a response. PostHog is different in kind and worth saying plainly: an analytics product stores the events it is sent, so those are held for as long as the project is configured to hold them rather than discarded after an answer.
Processors we do not use
We do not use data brokers or purchased contact lists, and no advertising or ad-tech network receives anything from the product. The marketing site uses cookieless analytics that stores no IP address and sets no cookie, which is why you were not shown a consent banner on the way here.
Contact
Write to hello@siteassay.com with anything this document does not answer.