Subprocessor Register
For countersigned originals, contact legal@sercxi.io.
Live list of third parties that process personal data on Sercxi's behalf. Updated on change; 30 days' notice for material additions.
Notifications sent from legal@sercxi.io. Enterprise clients under a signed DPA receive direct notice in addition to this list. Material additions or changes to the register are announced 30 days in advance.
| Subprocessor | Purpose | Corporate HQ | Data location | Transfer mechanism | Status |
|---|---|---|---|---|---|
| Supabase, Inc. | Managed Postgres, authentication, private object storage | United States (Delaware) | EU — Frankfurt (eu-central-1) | EU Standard Contractual Clauses (SCCs 2021/914, Module 2) + supplementary technical measures | Active |
| Cloudflare, Inc. | DNS, edge caching, DDoS protection, WAF | United States (California) | Global edge; no personal data at rest | EU SCCs + EU-US Data Privacy Framework (DPF) certified | Active |
| Proton AG | Proton Mail Business (E2EE), Proton VPN, Proton Drive (client-side encrypted), Proton Pass — partner operator security. 2FA mandatory on every partner account. | Switzerland (Geneva) | Switzerland | EU Commission adequacy decision for Switzerland (2000/518/EC, renewed) | Active |
| Umami Software, Inc. | Cookieless, IP-hashed website analytics — no cross-site tracking | United States (Delaware) | EU (Frankfurt) | EU SCCs + no personal data collected at source (cookieless) | Active |
| Cal.com, Inc. | Meeting scheduling for prospective clients | Germany (Berlin operating entity) / United States | EU | GDPR direct (EU processing) + SCCs for any US onward transfer | Active |
| OnePageCRM Ltd. | Client-relationship record system | Ireland (Galway) | EU (Ireland) | GDPR direct — no international transfer | Active |
| Resend, Inc. | Transactional email delivery (assessment results, framework downloads) | United States (San Francisco) | EU + US regional processing | EU SCCs + EU-US Data Privacy Framework (DPF) certified | Active |
| WhatsApp Ireland Ltd. (Meta Platforms) | Client-initiated messaging channel only | Ireland (EU controller) / United States (Meta Platforms, Inc.) | Global (Meta infrastructure) | EU SCCs + EU-US Data Privacy Framework (DPF) certified | Conditional |
| Firecrawl, Inc. | Public-web ingestion for market mapping — no personal data submitted by Sercxi | United States | United States | EU SCCs; no personal data submitted | Active |
- Supabase, Inc.Active
Managed Postgres, authentication, private object storage
- HQ
- United States (Delaware)
- Data
- EU — Frankfurt (eu-central-1)
- Transfer
- EU Standard Contractual Clauses (SCCs 2021/914, Module 2) + supplementary technical measures
- Cloudflare, Inc.Active
DNS, edge caching, DDoS protection, WAF
- HQ
- United States (California)
- Data
- Global edge; no personal data at rest
- Transfer
- EU SCCs + EU-US Data Privacy Framework (DPF) certified
- Proton AGActive
Proton Mail Business (E2EE), Proton VPN, Proton Drive (client-side encrypted), Proton Pass — partner operator security. 2FA mandatory on every partner account.
- HQ
- Switzerland (Geneva)
- Data
- Switzerland
- Transfer
- EU Commission adequacy decision for Switzerland (2000/518/EC, renewed)
- Umami Software, Inc.Active
Cookieless, IP-hashed website analytics — no cross-site tracking
- HQ
- United States (Delaware)
- Data
- EU (Frankfurt)
- Transfer
- EU SCCs + no personal data collected at source (cookieless)
- Cal.com, Inc.Active
Meeting scheduling for prospective clients
- HQ
- Germany (Berlin operating entity) / United States
- Data
- EU
- Transfer
- GDPR direct (EU processing) + SCCs for any US onward transfer
- OnePageCRM Ltd.Active
Client-relationship record system
- HQ
- Ireland (Galway)
- Data
- EU (Ireland)
- Transfer
- GDPR direct — no international transfer
- Resend, Inc.Active
Transactional email delivery (assessment results, framework downloads)
- HQ
- United States (San Francisco)
- Data
- EU + US regional processing
- Transfer
- EU SCCs + EU-US Data Privacy Framework (DPF) certified
- WhatsApp Ireland Ltd. (Meta Platforms)Conditional
Client-initiated messaging channel only
- HQ
- Ireland (EU controller) / United States (Meta Platforms, Inc.)
- Data
- Global (Meta infrastructure)
- Transfer
- EU SCCs + EU-US Data Privacy Framework (DPF) certified
- Firecrawl, Inc.Active
Public-web ingestion for market mapping — no personal data submitted by Sercxi
- HQ
- United States
- Data
- United States
- Transfer
- EU SCCs; no personal data submitted
Infrastructure
- Supabase (database, auth, storage) — hosting in EU region.
- Cloudflare (DNS, edge caching, DDoS protection) — global edge, no personal data at rest.
Analytics
- Umami — cookieless, self-hosted-compatible analytics. No IP addresses stored. No cross-site tracking.
Operator Communications & Security
- Proton AG (Switzerland, EU adequacy) — Proton Mail Business on a Sercxi custom domain (end-to-end and zero-access encryption), Proton VPN with always-on and kill-switch for partner devices, Proton Drive for client-side encrypted document storage, and Proton Pass for credential management. Two-factor authentication is mandatory on every partner account.
Communications and Scheduling
- Cal.com — meeting scheduling for prospective clients.
- WhatsApp Business — client communication where the client initiates that channel.
- OnePageCRM — client-relationship record system, EU-hosted where offered.
Research Tooling
- Firecrawl — public-web ingestion for market mapping. No personal data submission by Sercxi.
Change Notice
Material additions or changes are announced 30 days in advance on this page. Clients under a processor DPA receive direct notice.
This document is part of the Sercxi governance suite. It does not replace bespoke legal advice for a specific mandate.
For questions or to request the full text of any gated document, contact legal@sercxi.io.