Sub-processors
We notify panellists 30 days before adding any new sub-processor that would materially change the level of disclosure or move data to a new jurisdiction, and trigger a re-consent flow where required.
| Vendor | Purpose | Jurisdiction | Transfer basis |
|---|---|---|---|
| Vercel | Front-end hosting (Next.js panel app and marketing site). | US (DPF-certified) and EU edge. | DPF + SCCs fallback. |
| Supabase | Auth and Postgres for the panellist directory (V1). | EU (Ireland) project region. | DPA in place. |
| Cloudflare R2 | Object storage for raw media, transcripts, avatars. | EU. | DPA + SCCs. |
| Twilio | SMS verification and panel SMS notifications. | US (DPF-certified) and EU. | DPF + SCCs fallback. |
| Meta WhatsApp Business | WhatsApp survey prompts and reward delivery messages. | US (DPF) / Ireland (EU controller). | DPF + SCCs fallback. |
| Resend | Transactional email (magic link, reward issued, etc). | US (DPF-certified). | DPF + SCCs. |
| Deepgram | Audio and video response transcription. | US. | SCCs + TIA. |
| Anthropic | LLM-as-judge content scoring (Layer B validation). | US. | SCCs + zero-retention tier. |
| Replicate | Avatar generation (face-preserving stylisation). | US. | SCCs + TIA. |
| ComplyCube | Liveness check and selfie verification. | UK (ICO-registered). | UK GDPR. |
| Tremendous | Reward issuance (multi-brand voucher fulfilment, 2,500+ brands across 230+ countries). | United States. Standard Contractual Clauses in place for UK and EU panellist data. | UK GDPR + EU GDPR Art 46 (SCCs). |
| IPQualityScore | Anti-fraud IP and device reputation signals. | US. | SCCs + legitimate interest. |
| Fingerprint.com | Anti-fraud device fingerprint. | US (DPF). | DPF + legitimate interest. |