Subprocessor Register

For countersigned originals, contact legal@sercxi.io.

Live list of third parties that process personal data on Sercxi's behalf. Updated on change; 30 days' notice for material additions.

Notifications sent from legal@sercxi.io. Enterprise clients under a signed DPA receive direct notice in addition to this list. Material additions or changes to the register are announced 30 days in advance.

  • Managed Postgres, authentication, private object storage

    United States (Delaware)
    EU — Frankfurt (eu-central-1)
    EU Standard Contractual Clauses (SCCs 2021/914, Module 2) + supplementary technical measures
  • DNS, edge caching, DDoS protection, WAF

    United States (California)
    Global edge; no personal data at rest
    EU SCCs + EU-US Data Privacy Framework (DPF) certified
  • Proton AGActive

    Proton Mail Business (E2EE), Proton VPN, Proton Drive (client-side encrypted), Proton Pass — partner operator security. 2FA mandatory on every partner account.

    Switzerland (Geneva)
    Switzerland
    EU Commission adequacy decision for Switzerland (2000/518/EC, renewed)
  • Cookieless, IP-hashed website analytics — no cross-site tracking

    United States (Delaware)
    EU (Frankfurt)
    EU SCCs + no personal data collected at source (cookieless)
  • Meeting scheduling for prospective clients

    Germany (Berlin operating entity) / United States
    EU
    GDPR direct (EU processing) + SCCs for any US onward transfer
  • Client-relationship record system

    Ireland (Galway)
    EU (Ireland)
    GDPR direct — no international transfer
  • Transactional email delivery (assessment results, framework downloads)

    United States (San Francisco)
    EU + US regional processing
    EU SCCs + EU-US Data Privacy Framework (DPF) certified
  • Client-initiated messaging channel only

    Ireland (EU controller) / United States (Meta Platforms, Inc.)
    Global (Meta infrastructure)
    EU SCCs + EU-US Data Privacy Framework (DPF) certified
  • Public-web ingestion for market mapping — no personal data submitted by Sercxi

    United States
    United States
    EU SCCs; no personal data submitted

Infrastructure

  • Supabase (database, auth, storage) — hosting in EU region.
  • Cloudflare (DNS, edge caching, DDoS protection) — global edge, no personal data at rest.

Analytics

  • Umami — cookieless, self-hosted-compatible analytics. No IP addresses stored. No cross-site tracking.

Operator Communications & Security

  • Proton AG (Switzerland, EU adequacy) — Proton Mail Business on a Sercxi custom domain (end-to-end and zero-access encryption), Proton VPN with always-on and kill-switch for partner devices, Proton Drive for client-side encrypted document storage, and Proton Pass for credential management. Two-factor authentication is mandatory on every partner account.

Communications and Scheduling

  • Cal.com — meeting scheduling for prospective clients.
  • WhatsApp Business — client communication where the client initiates that channel.
  • OnePageCRM — client-relationship record system, EU-hosted where offered.

Research Tooling

  • Firecrawl — public-web ingestion for market mapping. No personal data submission by Sercxi.

Change Notice

Material additions or changes are announced 30 days in advance on this page. Clients under a processor DPA receive direct notice.

For questions or to request the full text of any gated document, contact legal@sercxi.io.