Pherox
Try free Pricing About Sign in
Try free

Site menu

Pricing About Sign in
Try free

Sub-processor List

Last updated: 10 July 2026

Summary

To run Pherox we use a small number of carefully chosen third parties ("sub-processors") to handle hosting, payments, and email. Each is bound by contractual obligations equivalent to our Data Processing Agreement (Schedule A to the Terms).

We give at least 30 days' notice before adding, replacing, or materially changing a sub-processor. Updates are posted on this page and emailed to paid-account customers. You have the right to object on data protection grounds within that 30-day window.

If you have any questions, email [email protected].

What this page is

UK data protection law (UK GDPR Article 28) requires us, as your data processor, to be transparent about the sub-processors we engage to help us provide Pherox to you.

This page lists every third party that processes:

  • Personal data about you as our customer (we are the controller), or
  • Personal data about your customers (Customer Personal Data, typically homeowners) that you enter into Pherox (you are the controller, we are your processor)

Pure infrastructure that does not handle personal data (CDN caches for marketing static assets, DNS, etc.) is not separately listed.

How to be told about changes

Two ways:

  1. This page is the live source of truth. The "Last updated" date at the top always reflects the latest change.
  2. Email notification. If you have a paid Pherox account, we will email you at the address on your account whenever we add, replace, or materially change a sub-processor, at least 30 days before the change takes effect.

If you would like to be notified by email even though you are on a free trial, or as a non-customer (for example a data protection professional reviewing our posture), email [email protected] with the subject "Sub-processor notifications" and we will add you to the notification list.

Your right to object

If you reasonably object to a new sub-processor on data protection grounds, tell us within the 30-day notice period at [email protected] with the subject "Sub-processor objection". We will discuss in good faith.

If we cannot agree, you can cancel the affected part of the service under section 16 of the Terms, with no further charge for the unaffected paid period.

Current sub-processors

Categories:

  • Core: required for the basic service to function
  • Planned (not yet active): planned but not running at launch; no analytics or A/B testing runs today. Each will be activated post-launch with at least 30 days' notice, and this page updated accordingly

Core sub-processors

Sub-processorPurposePersonal data processedLocationTransfer mechanism (if outside UK)
Supabase Pte. Ltd. (Singapore)Database and backend hosting. Stores the application database, including account data and all Customer Personal Data entered into PheroxAccount data, billing metadata, all Customer Personal Data (typically homeowner name, property address, contact details, job scope, prices quoted)London, eu-west-2 (UK)EU Standard Contractual Clauses with the UK Addendum (ICO Approved Addendum B.1.0, Irish governing law)
Fly.io, Inc.Application hosting. Runs the Pherox backendAccount data and Customer Personal Data processed in the application; request metadataLondon (LHR)UK Extension to EU-US Data Privacy Framework (Fly.io is DPF-certified)
Cloudflare, Inc.Frontend and marketing-site hosting; CDN, WAF, and bot protection at the edge. Does not host the application database or the backend codeFrontend request metadata, IP address, edge security signalsGlobal edgeUK Extension to EU-US Data Privacy Framework (Cloudflare is DPF-certified)
Stripe Payments Europe Ltd / Stripe, Inc.Subscription billing, payment processing, invoicingYour billing email, billing address, card details (Stripe-only; we never see them), payment historyIreland (Stripe Payments Europe Ltd) and United States (Stripe, Inc.)UK adequacy decision (Ireland); UK Extension to EU-US Data Privacy Framework (United States)
Resend, Inc.Transactional email delivery (magic-link sign-in, billing receipts, account notices, service-affecting alerts, sub-processor change notifications)Recipient email address, email subject and body, delivery metadataUnited StatesUK Extension to EU-US Data Privacy Framework
Twilio Ireland Limited (Twilio Verify)Phone verification at sign-up (anti-abuse one-time-passcode gate)Account-holder phone number; verification code delivery and result metadataIrelandUK adequacy decision (EEA)
Google LLC (Google Workspace)Hosting of the [email protected] inbox and any related correspondence including customer-support emailsEmail contents (which may include personal data you or your customers send us), email metadataUnited StatesUK Extension to EU-US Data Privacy Framework
Functional Software, Inc. (Sentry)Error monitoring and crash reportingUser account identifier, browser data, stack traces, request metadata (without payloads where avoidable); occasional incidental personal data captured in error contextsEuropean Union (Frankfurt)UK Extension to EU-US Data Privacy Framework (Functional Software, Inc. is DPF-certified)

Planned sub-processors (not yet active)

Pherox runs no analytics or A/B testing at launch. The following are planned but not yet active; each will move into the Core table (or a future Analytics table) with at least 30 days' notice when activated. Analytics tools that require cookies will load only after consent.

Sub-processorPurposeStatusPlanned location
Plausible Insights OÜCookieless aggregate analyticsPlanned post-launch; not yet activeEuropean Union (Germany)
Google LLC (GA4 with Consent Mode v2)Consent-gated identified analyticsPlanned post-launch; not yet activeUnited States
Microsoft Corporation (Clarity)Consent-gated session replayPlanned post-launch; not yet activeUnited States (Ireland data centre option)
Growth Book, Inc. (GrowthBook Cloud)A/B testing and feature flagsPlanned Day 60–90 post-launch; not yet activeUnited States

Notes on transfer mechanisms

Where a sub-processor is outside the United Kingdom, we rely on one of the following safeguards under the UK GDPR:

  • UK adequacy decision: covers the European Economic Area and a small number of other countries the UK has formally found to provide adequate protection. No further safeguard required.
  • UK Extension to the EU-US Data Privacy Framework (DPF): covers transfers to organisations in the United States that are DPF-certified. We verify certification at the dataprivacyframework.gov register before relying on this mechanism. If a sub-processor's DPF certification lapses, we fall back to the UK IDTA or EU SCCs with UK Addendum without interruption.
  • UK International Data Transfer Agreement (UK IDTA) or EU Standard Contractual Clauses with the UK Addendum: where DPF is not available or the recipient is in a non-DPF country. A Transfer Risk Assessment is on file for each.

If a transfer mechanism is invalidated (for example by a court decision or regulator action), we will switch to an alternative valid mechanism as soon as reasonably practicable, or stop the transfer.

Sub-processor due diligence

Before engaging any sub-processor we:

  • Review their data protection terms (Data Processing Agreement, sub-processor list, security documentation)
  • Verify their certifications (DPF where applicable; SOC 2, ISO 27001 where they hold them)
  • Confirm the transfer mechanism
  • Confirm contractual obligations equivalent in substance to our own DPA
  • Document the assessment in our internal Record of Processing Activities

We re-review this material on each sub-processor at least annually.

Pherox

Mon to Fri, 8am to 6pm

Product

  • Pricing
  • Making Tax Digital

Company

  • About
  • Contact
  • Company information

Resources

  • Guides
  • Security
  • Accessibility

  • Privacy
  • Terms
  • Cookies
  • Sub-processors
  • Complaints

© 2026 Pherox Technologies Ltd · Registered in England and Wales, company no. 17181975