WebPolisher Subprocessor Schedule
Version: subprocessors-v4.1
Legal set: webpolisher-legal-set-2026-08-27-v8
Status: Candidate.
1. Purpose and status labels
This schedule identifies providers used or proposed for the current WebPolisher production service.
Status labels mean:
- Active - approved for the stated production processing, subject to final legal-set approval.
- Conditional - may be used only while the stated account or configuration condition remains verified.
- Held - must not receive production customer personal data until the identified evidence is recorded.
- Disabled - integration is not active and is not authorised to receive production customer data.
The non-public provider register must contain current account, contract, DPA, security, region, transfer, retention and annual-review evidence.
2. Provider schedule
Vercel, Inc.
Status: Active.
Role: Processor for hosting and related service data. Separate controller activity may apply to PeckUK Limited's own account relationship.
Purpose: Application hosting, edge delivery, functions, deployment, queues, operational logs and consented Web Analytics.
Data: Request and network data, account and application payloads handled by a function, deployment metadata, operational logs and consented analytics events.
Location: United States and globally distributed infrastructure.
Safeguards: Vercel Pro terms and Data Processing Addendum, including applicable UK transfer provisions.
Retention: WebPolisher retention applies to its stored records. Vercel also applies documented operational, security, backup and legal periods.
Service level: The current Pro arrangement does not provide WebPolisher with the Vercel Enterprise uptime SLA.
Provider information: https://vercel.com/legal/dpa
Supabase, Inc.
Status: Active, subject to continued evidence that the production project remains on the approved paid plan and London region.
Role: Processor.
Purpose: PostgreSQL database, authentication, storage and backend services.
Data: Account, authentication, tenant, report, project, content, support, audit, billing-reference and hosted form data.
Primary project region: London, AWS eu-west-2.
Safeguards: Supabase terms and Data Processing Addendum, including applicable UK transfer provisions.
Retention: WebPolisher retention applies to live data. The current Pro plan provides seven days of daily database backups. WebPolisher must ensure any additional protected backup expires within the stated 35-day maximum unless a documented legal hold applies.
Service level: The current Pro arrangement does not provide an Enterprise uptime SLA.
Provider information: https://supabase.com/legal/dpa and https://supabase.com/docs/guides/platform/backups
Stripe Payments Europe, Limited and applicable Stripe affiliates
Status: Active when checkout is enabled after legal approval.
Role: Stripe acts as processor for some payment-platform services and as an independent controller for regulated payment, fraud, compliance, relationship and product purposes described in its DPA and privacy notice.
Purpose: Checkout, billing identity, subscriptions, invoices, VAT evidence, payment processing, fraud prevention, payment status and support.
Data: Business contact and billing details, order and payment references, tax information, IP, device and fraud signals, and payment-card data collected directly by Stripe.
Location: Ireland or the EEA, the United States and Stripe affiliate and service-provider locations.
Safeguards: Stripe Services Agreement, DPA and Data Transfers Addendum, including applicable adequacy and UK transfer mechanisms.
Retention: For the service and post-termination, financial-services, fraud, dispute and legal requirements described by Stripe.
Provider information: https://stripe.com/legal/dpa
Twilio Ireland Limited, Twilio Inc. and Twilio SendGrid
Status: Active for transactional service email only.
Role: Processor for email delivery activity performed on WebPolisher's instructions, with separate controller activity for Twilio's own account and legal purposes where applicable.
Purpose: Transactional email and delivery-event processing.
Data: Recipient and sender address, subject, message content, template information and delivery, network and security metadata.
Location: European Union, North America and current SendGrid subprocessor locations.
Safeguards: Twilio Terms and Data Protection Addendum, including applicable adequacy, Binding Corporate Rules, Standard Contractual Clauses and UK transfer provisions.
Controls: Open and click tracking must remain disabled unless separately approved, documented and lawfully enabled.
Retention: WebPolisher retains its records under the Privacy Policy. Provider content and metadata follow the applicable Twilio and SendGrid contract and account configuration.
Provider information: https://www.twilio.com/legal/data-protection-addendum
Better Stack
Status: Held pending confirmation of the exact contracting entity, accepted DPA, account data region and configured error retention.
Role: Intended processor.
Purpose: Error, security and reliability monitoring through a Sentry-compatible endpoint.
Data: Scrubbed exception, request method and URL, release, runtime and limited diagnostic metadata.
Required controls: Default personal-information collection disabled, application scrubbing enabled, no full request body, credentials, form content or payment data, and EU data region confirmed.
Retention: Must be configured to no more than 90 days and shortened where operationally suitable.
Production rule: No production event may be sent until the held account and DPA evidence is recorded.
Provider information: https://betterstack.com/security
OpenAI OpCo, LLC
Status: Conditional on continued use of the approved business API account and approved endpoints and retention settings.
Role: Processor for API customer data.
Purpose: Report analysis, grounded drafting, concept and image generation, and output quality checks.
Data: Bounded public website evidence, customer instructions, report context, prompts, generated outputs and provider request identifiers. Special-category, criminal-offence and unnecessary private personal data are prohibited.
Location: United States and provider or subprocessor locations. UK or EU API data residency is not claimed for the current account.
Safeguards: OpenAI Services Agreement and Data Processing Addendum. UK transfers use the EU Standard Contractual Clauses as amended by the UK Addendum where applicable.
Retention and training: API inputs and outputs are not used to train OpenAI models by default unless the account holder opts in. Standard abuse-monitoring logs may be retained for up to 30 days. Features with longer application-state retention must remain disabled for production customer data unless separately approved and recorded.
Provider information: https://cdn.openai.com/pdf/openai-data-processing-addendum.pdf and https://platform.openai.com/docs/models/default-usage-policies-by-endpoint
GitHub, Inc.
Status: Held until the organisation account is confirmed as GitHub Team, Enterprise Cloud or another product covered by the current GitHub Data Protection Agreement.
Role: Intended processor for approved repository data. GitHub also acts as controller for its own account, security and relationship data as described in its privacy statement.
Purpose: Private source control, review, CI and deployment-source records.
Data: Source code, commit and deployment metadata, authorised administrator identity and public customer website content deliberately committed to a generated site repository.
Prohibited data: Operational database records, full form submissions, payment-card data, provider secrets and unnecessary private personal data must not be committed.
Location: United States and global service locations.
Safeguards: Applicable GitHub Customer Agreement and Data Protection Agreement, including UK transfer provisions, only after the plan condition is confirmed.
Production rule: No new repository containing customer personal data may be created while this status is Held.
Provider information: https://github.com/customer-terms
3. Disabled integrations
The following direct integrations are Disabled and are not authorised to receive production customer data:
- Cloudflare Turnstile;
- Firecrawl;
- Google Analytics; and
- Google Search Console data access.
Cloudflare may remain an upstream provider used by Vercel or another approved provider. That upstream role does not activate the direct WebPolisher Turnstile integration.
4. Changes and objections
WebPolisher will give customers at least 30 days' written notice before a new Subprocessor begins processing Covered Data, subject to the urgent security replacement provision in the DPA.
Posting a changed schedule without a directed customer notification is not sufficient notice for this purpose.
A customer may object within 14 days on reasonable data-protection grounds under the DPA.
5. Provider control
The platform owner must review the provider register:
- before enabling a provider;
- when a provider, feature, contract, region or retention setting changes; and
- at least annually.
Held and Disabled providers must fail closed. Marketing need, convenience or existing code is not approval evidence.
6. Supplier details
WebPolisher is a trading name of PeckUK Limited.
PeckUK Limited is registered in England and Wales under company number 08756155.
Registered office: 90 Stowmarket Road, Needham Market, Ipswich, Suffolk, IP6 8DX, United Kingdom.
VAT number: 173 8752 74.
Contact: updates@webpolisher.co.uk.