Legal
Sub-processors
Datuma uses the following sub-processors to deliver the service. Each is bound by data-processing terms appropriate to the data they handle.
Current sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Application database (Postgres), Edge Functions, authentication | EU (Ireland) |
| Google Workspace (Google Cloud EMEA Limited, Ireland) | Hosts our business email. A file sent to us by email, and any written instruction or correspondence, is received and stored in our mailbox on this provider's systems until we delete it | Irish contracting entity; no data region is configured for our account, so mailbox content may be processed where the provider or its sub-processors maintain facilities (under its Cloud Data Processing Addendum, EU Standard Contractual Clauses and UK International Data Transfer Addendum; the provider also relies on the EU-US Data Privacy Framework and its UK Extension) |
| Resend | Transactional email delivery, including the email that returns finished files | US provider. We send from its Ireland region, but it states that account data, message metadata, logs and API records are stored in the US whatever region is selected (under EU Standard Contractual Clauses and the UK Addendum; the provider also states EU-US Data Privacy Framework compliance including the UK Extension) |
| Netlify | Marketing site and portal static hosting | Global CDN |
| Cloudflare | Turnstile anti-abuse check on the forms on this website, which processes the visitor's IP address and browser signals | Global network, US provider (under Cloudflare's data processing addendum; certified under the EU-US Data Privacy Framework including the UK Extension, with EU Standard Contractual Clauses and UK International Data Transfer Addendum where that certification does not apply) |
| Contact-data enrichment provider | Role and organisation verification on the lookup identifiers we send, where the identity layer runs. It processes those identifiers on our instructions, as our sub-processor; see the note below for the second capacity in which it acts | US provider, under EU Standard Contractual Clauses Module 3 (processor to processor) for the identifiers we send, with the UK International Data Transfer Addendum (ICO template version B.1.0). Data processing addendum executed 2026-08-15 |
| Email-verification provider | Business email deliverability validation | EU |
| Phone-verification provider | Mobile number liveness, carrier and line-type validation, where this feature is enabled | UK provider; the lookup itself queries the destination telephone network, which may be located anywhere in the world. Only the bare number is transmitted |
| Language-model provider (diagnostics only) | Where a processing run fails, and only where this diagnostic feature is switched on for our account, a short diagnostic summary (identifiers, error message, counts, recent log lines; no contact records) is sent to draft an internal diagnosis for our operator. Its published position for its programming interface is that inputs and outputs are deleted within 30 days of receipt, subject to four exceptions it publishes: a service with longer retention under the customer’s control, a separately agreed retention arrangement, retention needed to enforce its usage policy, and retention required by law. Where its automated systems flag a submission as a usage policy violation it retains inputs and outputs for up to two years, and classification scores for up to seven. That is its published position and not a commitment given to us. | The provider’s published Commercial Terms govern use of its programming interface and incorporate its data processing addendum, which provides for the EU Standard Contractual Clauses (Decision (EU) 2021/914), Modules Two and Three, and the UK International Data Transfer Addendum (ICO template version B.1.0). The provider does not rely on the Data Privacy Framework here and we do not claim it does. That is the position under its published terms. Personal data reaches it only where it happens to appear in a file name or a log line. |
| Plausible Insights OÜ (Estonia) | Website and portal page analytics. Cookieless, no contact data, IP addresses hashed transiently and not retained. | European Union |
The contact-data enrichment provider acts in two capacities. Where the identity layer runs, individual lookup identifiers (a professional profile URL, the contact’s name and job title, their business email address, and a company domain) are disclosed to it. For the identifiers we send it, it processes them on our instructions as our sub-processor, under EU Standard Contractual Clauses Module 3 (processor to processor), because we send them to it as your processor, with the UK International Data Transfer Addendum. That is why it is listed in the table above. For the results it compiles and returns from its own database, it acts as a controller in its own right, under Module 1 (controller to controller), and once those results reach us we are an independent controller of them. Its agreement with us commits it not to merge what we send into its own dataset, and not to use it to train or improve its models or databases, save where our agreement expressly permits it or where it is needed to detect or prevent fraud, security incidents or abuse. Our Data Processing Terms record both capacities in full.
Not a sub-processor: payments. Payment and any Direct Debit mandate are handled by GoCardless Ltd, which is authorised by the Financial Conduct Authority under the Payment Services Regulations 2017. Its own merchant terms state that it and its merchants each act as controllers in their own right for the personal data processed in running the payment relationship, so it is not our sub-processor and we do not list it as one. It receives the billing contact and bank details of the organisation that pays us, never a customer file or any record derived from one, and its processing for European payments runs on servers in the European Economic Area.
Changes
We notify customers of material sub-processor additions via email at least 30 days in advance. The specific name of the contact-data enrichment provider, along with details of its transitive sub-processors, is available on request to active customers and prospects with a signed non-disclosure agreement. Write to support@datuma.co.uk for these details. Our Data Processing Terms, with the full annex stating each provider's transfer mechanism, are published at datuma.co.uk/processing-terms.
Related policies
For the full description of how personal data is processed, see the Privacy Policy. For technical controls, see the Security page. For the terms governing the free check and the work we run for you, see the Terms of Service.