Skip to content
EnableGRC
  • Our solution
  • Features
  • Pricing
Client login Register interest

Sub-processor List

Effective: 1 August 2026. Version: 1.0.

This page lists the sub-processors that WislPort Compliance Limited (registered in Gibraltar, company number 124227) — trading as EnableGRC — engages to deliver the EnableGRC platform. When we process personal data on behalf of our clients (that is, as a processor under Article 28 of the UK GDPR and EU GDPR), we use the third parties below. Each is engaged under a written data-processing agreement with data-protection obligations no less protective than those we owe our clients.

This is distinct from the third parties that process our own corporate and marketing data (for example Microsoft 365, HubSpot and QuickBooks), where EnableGRC is the controller — those are listed in our Privacy Notice.

Platform sub-processors

Sub-processor Purpose Data processed Location / data residency Transfer safeguard
Neon Managed PostgreSQL — primary application data store Tenant data held in the platform EU — Frankfurt (eu-central-1) EU-hosted; Neon DPA incorporating SCCs
Render Application hosting & compute Data processed in transit while serving requests EU — Frankfurt EU-hosted; Render DPA incorporating SCCs
Cloudflare R2 Object storage for uploaded documents, evidence and attachments Uploaded documents, evidence, attachments EU (Europe) Cloudflare DPA incorporating SCCs
Cloudflare CDN, DNS, DDoS / bot protection (WAF) Network metadata, IP addresses; no application data stored beyond edge logs Global edge network Standard Contractual Clauses
Stripe Payment processing & subscription billing Billing contact and payment metadata (card data handled by Stripe under PCI-DSS) UK / EU / US SCCs; PCI-DSS
Resend Transactional email delivery (invitations, notifications, alerts) Recipient name and email address; message content United States EU–US Data Privacy Framework + UK Extension (SCCs as backstop)
Anthropic (Claude) AI features (insights, anomaly detection, report narrative) Content submitted to AI features, which may include personal data United States EU SCCs (Modules 2/3) + UK Addendum, incorporated in Anthropic's commercial terms; content is not used for model training; API logs auto-delete after 7 days

The database and application compute (Neon and Render) are hosted in the EU (Frankfurt); object storage is on Cloudflare R2 in Europe. Error-monitoring (Sentry) is provisioned but not currently enabled in production, so no data flows to it; it will be added here when activated.

Changes to our sub-processors

We will give our clients at least 30 days’ prior notice before we add or replace a sub-processor that processes their personal data — by email and by updating this page. Clients may subscribe to change notifications and may object, on reasonable data-protection grounds, within the notice period; if we cannot resolve an objection, the client may terminate the affected services as set out in their agreement.

Data Processing Agreement

Our Data Processing Agreement (Article 28) is published at enablegrc.ai/dpa and forms part of our contract; a copy is also available on request. It incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum for any restricted transfers.

Contact

For any question about this list or our data-processing practices, contact privacy@enablegrc.ai.

EnableGRC

Simplify complexity. Power growth.

  • Privacy notice
  • Terms of use
  • Cookie policy
  • Sub-processors
  • DPA