Last reviewed 2026-05-31
Subprocessors
Under GDPR Article 28(2), this page lists every third party that processes personal data on our behalf in connection with the ECGT Ready platform. Where practicable, we aim to give reasonable prior notice before adding or replacing a subprocessor by updating this page, unless a faster change is required by law, a binding order, a security incident, or to keep the service running.
Want to be notified by email of changes here? Add a contact at contact@ecgtready.eu.
Active subprocessors
| Vendor | Purpose | Data categories | Location | Transfer safeguard |
|---|---|---|---|---|
| Supabase Inc. | Database, authentication, storage | Account data, scan results, demo requests, uploaded company policy and Deep Scan supporting documents | EU (eu-central-1, Frankfurt) | Within EEA, no transfer outside EU |
| Vercel Inc. | Hosting, edge, serverless functions | All web traffic, logs, request metadata | US with EU edge | SCCs (2021/914); Vercel is DPF certified |
| Anthropic, PBC | LLM inference for the scan engine | Page text being scanned and the URL; for a Deep Scan also the workspace product profile and the labels and descriptions of uploaded supporting documents (not the files themselves) | US | SCCs; Anthropic does not train on API data |
| Anthropic, PBC (Connect Scanner) | LLM inference for the separate Connect Scanner engine (Haiku 4.5 triage, Sonnet 4.6 deep pass, Sonnet 4.6 self verifier, Opus 4.8 tie breaker on uncertain verdicts). Same vendor as above, isolated under a distinct API key for usage and access separation. | Product text or product specification submitted to the Connect Scanner, plus the customer's compliance profile inputs from /connect/profile (approved phrasings, forbidden phrasings, certifications, product categories, jurisdictions, brand voice, additional context), the company policy text the customer has uploaded, and the substantiation document text the customer has uploaded | US | SCCs; Anthropic does not train on API data |
| Anthropic, PBC (Building regulations scanner) | LLM inference for the separate Building regulations scanner engine (Opus 4.8) that reviews an uploaded construction or building plan against local building law. Same vendor as above, isolated under a distinct API key for usage and access separation. | The uploaded plan file itself (PDF, image, text, or CAD) and the address the customer enters. The plan content is sent to Anthropic so the model can read it | US | SCCs; Anthropic does not train on API data |
| Stripe Payments Europe Ltd. | Payment processing | Customer name, email, tokenised card data, billing address | Ireland (EU) primary, US fallback | SCCs; PCI-DSS Level 1 |
| Resend, Inc. | Transactional email | Recipient email and message content | US | SCCs; DPF certified |
Conditional subprocessors
| Vendor | Purpose | Data categories | Location | Status |
|---|---|---|---|---|
| Cloudflare, Inc. | CDN and DDoS mitigation (if added) | IP addresses, request metadata | Global with EU presence | Not active today; listed for transparency |
| CAD conversion service | Rendering and content extraction of native CAD plans (DWG, RVT, DGN, DWF) uploaded to the Building regulations scanner, so the model can read them. Only used for native CAD; DXF, IFC, SVG, PDF, image, and text plans are not sent to it. | The native CAD plan file the customer uploads | Depends on the configured provider | Not active by default; enabled per deployment when native CAD conversion is configured |
How to object
If you object to a subprocessor on reasonable data-protection grounds, write to contact@ecgtready.eu within 14 days of the change notice. We will work with you to find an alternative. If we cannot, you may terminate the affected service for convenience.
All legal pages
- Imprint
- Privacy
- Cookies
- Terms
- Disclaimer
- DPA
- Acceptable Use
- SLA
- Security
- Subprocessors
- Methodology
- Accessibility
- Refunds
- Data subject requests
- AI Act notice
- Intellectual property
- Communications
- Supply chain
- Speak up
- Our own claims
- Ethics
Questions about this page? contact@ecgtready.eu