Sub-processors
Cyber Horizon Intelligence Ltd
Version 1.1 · Effective 3 September 2026 · Classification: Public
To provide the Cyber Horizon Intelligence platform, we engage a limited set of trusted third-party sub-processors. Each is bound by a data-processing agreement requiring appropriate technical and organisational safeguards, and processes personal data only as needed to deliver its service. This page is maintained as part of our Data Processing Agreement.
Current Sub-processors
| Sub-processor | Purpose | Processing region | Transfer mechanism |
|---|---|---|---|
| Supabase | Managed Postgres, primary data store | European Union | UK adequacy (EEA) + DPA |
| Vercel | Application hosting, compute, CDN | United States / global edge | EU SCCs with UK Addendum (or IDTA) + DPA |
| Clerk | Authentication and identity | United States | EU SCCs with UK Addendum (or IDTA) + DPA |
| Anthropic | AI processing for assistant and analysis | United States | EU SCCs with UK Addendum (or IDTA) · no training on API data |
| Resend | Transactional email | United States | EU SCCs with UK Addendum (or IDTA) + DPA |
| Stripe | Billing and payments | United States / global | EU SCCs with UK Addendum (or IDTA) + DPA |
| Sentry | Error monitoring | United States / EU | EU SCCs with UK Addendum (or IDTA) + DPA |
| Cloudflare | Bot detection; encrypted off-site backups | United States / global edge | EU SCCs with UK Addendum (or IDTA) + DPA · encrypted to a key Cloudflare does not hold |
| Upstash | Rate limiting and abuse prevention, keyed on user ID or client IP | United States / EU | EU SCCs with UK Addendum (or IDTA) + DPA |
| Cloudmersive | Malware scanning of uploaded files | United States | EU SCCs with UK Addendum (or IDTA) + DPA · file bytes scanned in transit |
Data Residency
Customer Data is stored in the European Union by default (Supabase, eu-west-1). Per-organisation regional residency in the United States, the United Kingdom and APAC is available on request; a dedicated regional project is provisioned before data is loaded. No managed region is currently available in the Middle East. Some processing takes place outside the EU — application hosting and serverless compute, identity management, AI features, transactional email, malware scanning of uploaded files, and encrypted off-site backups. Every sub-processor, the service it provides, the region in which it processes Customer Data and the transfer mechanism relied on are listed in Annex 3 of the DPA. Where processing takes place outside the UK or EEA, CHI applies the transfer safeguards set out in the DPA.
This wording is taken from clause 13 of the DPA v1.5, where Annex 3 also records the transfer instrument in force for each sub-processor. Your residency region is selected on the Order Form.
Changes
We may update this list as our services evolve. Under clause 8 of the DPA we give customers at least 30 days’ notice of any new or replacement sub-processor, by email to your notified contact and by updating this page — you do not need to ask for it. You may object on reasonable data-protection grounds within that period and, if the objection is unresolved, terminate the affected service. Questions to privacy@cyberhorizon.co, and may raise reasonable objections in accordance with the Data Processing Agreement.
Contact
- Version
- 1.1
- Effective
- 3 September 2026
- Last reviewed
- 3 September 2026
- Next review
- 3 September 2027
- Classification
- Public