Sub-processor List
Effective: 1 August 2026. Version: 1.0.
This page lists the sub-processors that WislPort Compliance Limited (registered in Gibraltar, company number 124227) — trading as EnableGRC — engages to deliver the EnableGRC platform. When we process personal data on behalf of our clients (that is, as a processor under Article 28 of the UK GDPR and EU GDPR), we use the third parties below. Each is engaged under a written data-processing agreement with data-protection obligations no less protective than those we owe our clients.
This is distinct from the third parties that process our own corporate and marketing data (for example Microsoft 365, HubSpot and QuickBooks), where EnableGRC is the controller — those are listed in our Privacy Notice.
Platform sub-processors
| Sub-processor | Purpose | Data processed | Location / data residency | Transfer safeguard |
|---|---|---|---|---|
| Neon | Managed PostgreSQL — primary application data store | Tenant data held in the platform | EU — Frankfurt (eu-central-1) | EU-hosted; Neon DPA incorporating SCCs |
| Render | Application hosting & compute | Data processed in transit while serving requests | EU — Frankfurt | EU-hosted; Render DPA incorporating SCCs |
| Cloudflare R2 | Object storage for uploaded documents, evidence and attachments | Uploaded documents, evidence, attachments | EU (Europe) | Cloudflare DPA incorporating SCCs |
| Cloudflare | CDN, DNS, DDoS / bot protection (WAF) | Network metadata, IP addresses; no application data stored beyond edge logs | Global edge network | Standard Contractual Clauses |
| Stripe | Payment processing & subscription billing | Billing contact and payment metadata (card data handled by Stripe under PCI-DSS) | UK / EU / US | SCCs; PCI-DSS |
| Resend | Transactional email delivery (invitations, notifications, alerts) | Recipient name and email address; message content | United States | EU–US Data Privacy Framework + UK Extension (SCCs as backstop) |
| Anthropic (Claude) | AI features (insights, anomaly detection, report narrative) | Content submitted to AI features, which may include personal data | United States | EU SCCs (Modules 2/3) + UK Addendum, incorporated in Anthropic's commercial terms; content is not used for model training; API logs auto-delete after 7 days |
The database and application compute (Neon and Render) are hosted in the EU (Frankfurt); object storage is on Cloudflare R2 in Europe. Error-monitoring (Sentry) is provisioned but not currently enabled in production, so no data flows to it; it will be added here when activated.
Changes to our sub-processors
We will give our clients at least 30 days’ prior notice before we add or replace a sub-processor that processes their personal data — by email and by updating this page. Clients may subscribe to change notifications and may object, on reasonable data-protection grounds, within the notice period; if we cannot resolve an objection, the client may terminate the affected services as set out in their agreement.
Data Processing Agreement
Our Data Processing Agreement (Article 28) is published at enablegrc.ai/dpa and forms part of our contract; a copy is also available on request. It incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum for any restricted transfers.
Contact
For any question about this list or our data-processing practices, contact privacy@enablegrc.ai.