Sub-processor List
Last updated: 10 July 2026
Summary
To run Pherox we use a small number of carefully chosen third parties ("sub-processors") to handle hosting, payments, and email. Each is bound by contractual obligations equivalent to our Data Processing Agreement (Schedule A to the Terms).
We give at least 30 days' notice before adding, replacing, or materially changing a sub-processor. Updates are posted on this page and emailed to paid-account customers. You have the right to object on data protection grounds within that 30-day window.
If you have any questions, email [email protected].
What this page is
UK data protection law (UK GDPR Article 28) requires us, as your data processor, to be transparent about the sub-processors we engage to help us provide Pherox to you.
This page lists every third party that processes:
- Personal data about you as our customer (we are the controller), or
- Personal data about your customers (Customer Personal Data, typically homeowners) that you enter into Pherox (you are the controller, we are your processor)
Pure infrastructure that does not handle personal data (CDN caches for marketing static assets, DNS, etc.) is not separately listed.
How to be told about changes
Two ways:
- This page is the live source of truth. The "Last updated" date at the top always reflects the latest change.
- Email notification. If you have a paid Pherox account, we will email you at the address on your account whenever we add, replace, or materially change a sub-processor, at least 30 days before the change takes effect.
If you would like to be notified by email even though you are on a free trial, or as a non-customer (for example a data protection professional reviewing our posture), email [email protected] with the subject "Sub-processor notifications" and we will add you to the notification list.
Your right to object
If you reasonably object to a new sub-processor on data protection grounds, tell us within the 30-day notice period at [email protected] with the subject "Sub-processor objection". We will discuss in good faith.
If we cannot agree, you can cancel the affected part of the service under section 16 of the Terms, with no further charge for the unaffected paid period.
Current sub-processors
Categories:
- Core: required for the basic service to function
- Planned (not yet active): planned but not running at launch; no analytics or A/B testing runs today. Each will be activated post-launch with at least 30 days' notice, and this page updated accordingly
Core sub-processors
| Sub-processor | Purpose | Personal data processed | Location | Transfer mechanism (if outside UK) |
|---|---|---|---|---|
| Supabase Pte. Ltd. (Singapore) | Database and backend hosting. Stores the application database, including account data and all Customer Personal Data entered into Pherox | Account data, billing metadata, all Customer Personal Data (typically homeowner name, property address, contact details, job scope, prices quoted) | London, eu-west-2 (UK) | EU Standard Contractual Clauses with the UK Addendum (ICO Approved Addendum B.1.0, Irish governing law) |
| Fly.io, Inc. | Application hosting. Runs the Pherox backend | Account data and Customer Personal Data processed in the application; request metadata | London (LHR) | UK Extension to EU-US Data Privacy Framework (Fly.io is DPF-certified) |
| Cloudflare, Inc. | Frontend and marketing-site hosting; CDN, WAF, and bot protection at the edge. Does not host the application database or the backend code | Frontend request metadata, IP address, edge security signals | Global edge | UK Extension to EU-US Data Privacy Framework (Cloudflare is DPF-certified) |
| Stripe Payments Europe Ltd / Stripe, Inc. | Subscription billing, payment processing, invoicing | Your billing email, billing address, card details (Stripe-only; we never see them), payment history | Ireland (Stripe Payments Europe Ltd) and United States (Stripe, Inc.) | UK adequacy decision (Ireland); UK Extension to EU-US Data Privacy Framework (United States) |
| Resend, Inc. | Transactional email delivery (magic-link sign-in, billing receipts, account notices, service-affecting alerts, sub-processor change notifications) | Recipient email address, email subject and body, delivery metadata | United States | UK Extension to EU-US Data Privacy Framework |
| Twilio Ireland Limited (Twilio Verify) | Phone verification at sign-up (anti-abuse one-time-passcode gate) | Account-holder phone number; verification code delivery and result metadata | Ireland | UK adequacy decision (EEA) |
| Google LLC (Google Workspace) | Hosting of the [email protected] inbox and any related correspondence including customer-support emails | Email contents (which may include personal data you or your customers send us), email metadata | United States | UK Extension to EU-US Data Privacy Framework |
| Functional Software, Inc. (Sentry) | Error monitoring and crash reporting | User account identifier, browser data, stack traces, request metadata (without payloads where avoidable); occasional incidental personal data captured in error contexts | European Union (Frankfurt) | UK Extension to EU-US Data Privacy Framework (Functional Software, Inc. is DPF-certified) |
Planned sub-processors (not yet active)
Pherox runs no analytics or A/B testing at launch. The following are planned but not yet active; each will move into the Core table (or a future Analytics table) with at least 30 days' notice when activated. Analytics tools that require cookies will load only after consent.
| Sub-processor | Purpose | Status | Planned location |
|---|---|---|---|
| Plausible Insights OÜ | Cookieless aggregate analytics | Planned post-launch; not yet active | European Union (Germany) |
| Google LLC (GA4 with Consent Mode v2) | Consent-gated identified analytics | Planned post-launch; not yet active | United States |
| Microsoft Corporation (Clarity) | Consent-gated session replay | Planned post-launch; not yet active | United States (Ireland data centre option) |
| Growth Book, Inc. (GrowthBook Cloud) | A/B testing and feature flags | Planned Day 60–90 post-launch; not yet active | United States |
Notes on transfer mechanisms
Where a sub-processor is outside the United Kingdom, we rely on one of the following safeguards under the UK GDPR:
- UK adequacy decision: covers the European Economic Area and a small number of other countries the UK has formally found to provide adequate protection. No further safeguard required.
- UK Extension to the EU-US Data Privacy Framework (DPF): covers transfers to organisations in the United States that are DPF-certified. We verify certification at the dataprivacyframework.gov register before relying on this mechanism. If a sub-processor's DPF certification lapses, we fall back to the UK IDTA or EU SCCs with UK Addendum without interruption.
- UK International Data Transfer Agreement (UK IDTA) or EU Standard Contractual Clauses with the UK Addendum: where DPF is not available or the recipient is in a non-DPF country. A Transfer Risk Assessment is on file for each.
If a transfer mechanism is invalidated (for example by a court decision or regulator action), we will switch to an alternative valid mechanism as soon as reasonably practicable, or stop the transfer.
Sub-processor due diligence
Before engaging any sub-processor we:
- Review their data protection terms (Data Processing Agreement, sub-processor list, security documentation)
- Verify their certifications (DPF where applicable; SOC 2, ISO 27001 where they hold them)
- Confirm the transfer mechanism
- Confirm contractual obligations equivalent in substance to our own DPA
- Document the assessment in our internal Record of Processing Activities
We re-review this material on each sub-processor at least annually.