Skip to content
Cyber Horizon
Back to Legal

Sub-processors

Cyber Horizon Intelligence Ltd

Version 1.1 · Effective 3 September 2026 · Classification: Public

To provide the Cyber Horizon Intelligence platform, we engage a limited set of trusted third-party sub-processors. Each is bound by a data-processing agreement requiring appropriate technical and organisational safeguards, and processes personal data only as needed to deliver its service. This page is maintained as part of our Data Processing Agreement.

Current Sub-processors

Sub-processorPurposeProcessing regionTransfer mechanism
SupabaseManaged Postgres, primary data storeEuropean UnionUK adequacy (EEA) + DPA
VercelApplication hosting, compute, CDNUnited States / global edgeEU SCCs with UK Addendum (or IDTA) + DPA
ClerkAuthentication and identityUnited StatesEU SCCs with UK Addendum (or IDTA) + DPA
AnthropicAI processing for assistant and analysisUnited StatesEU SCCs with UK Addendum (or IDTA) · no training on API data
ResendTransactional emailUnited StatesEU SCCs with UK Addendum (or IDTA) + DPA
StripeBilling and paymentsUnited States / globalEU SCCs with UK Addendum (or IDTA) + DPA
SentryError monitoringUnited States / EUEU SCCs with UK Addendum (or IDTA) + DPA
CloudflareBot detection; encrypted off-site backupsUnited States / global edgeEU SCCs with UK Addendum (or IDTA) + DPA · encrypted to a key Cloudflare does not hold
UpstashRate limiting and abuse prevention, keyed on user ID or client IPUnited States / EUEU SCCs with UK Addendum (or IDTA) + DPA
CloudmersiveMalware scanning of uploaded filesUnited StatesEU SCCs with UK Addendum (or IDTA) + DPA · file bytes scanned in transit

Data Residency

Customer Data is stored in the European Union by default (Supabase, eu-west-1). Per-organisation regional residency in the United States, the United Kingdom and APAC is available on request; a dedicated regional project is provisioned before data is loaded. No managed region is currently available in the Middle East. Some processing takes place outside the EU — application hosting and serverless compute, identity management, AI features, transactional email, malware scanning of uploaded files, and encrypted off-site backups. Every sub-processor, the service it provides, the region in which it processes Customer Data and the transfer mechanism relied on are listed in Annex 3 of the DPA. Where processing takes place outside the UK or EEA, CHI applies the transfer safeguards set out in the DPA.

This wording is taken from clause 13 of the DPA v1.5, where Annex 3 also records the transfer instrument in force for each sub-processor. Your residency region is selected on the Order Form.

Changes

We may update this list as our services evolve. Under clause 8 of the DPA we give customers at least 30 days’ notice of any new or replacement sub-processor, by email to your notified contact and by updating this page — you do not need to ask for it. You may object on reasonable data-protection grounds within that period and, if the objection is unresolved, terminate the affected service. Questions to privacy@cyberhorizon.co, and may raise reasonable objections in accordance with the Data Processing Agreement.

Contact

privacy@cyberhorizon.co

Version
1.1
Effective
3 September 2026
Last reviewed
3 September 2026
Next review
3 September 2027
Classification
Public
Incorporated into the Master Services Agreement by reference.