Legal

Sub-processors

Under GDPR Article 28, we disclose every third party that processes data on our behalf. This page lists them, what each one does, and where data lives.

A sub-processor is any third party we engage to help deliver our service — the hosting a site like this runs on, the scheduling tool a call is booked through. We keep the list short on purpose: fewer providers means fewer places information could live, and each one below was chosen for a specific job we cannot do better ourselves.

Every provider is bound by a contract that meets Article 28 requirements, covering confidentiality, security measures, and audit rights. None of them receives more than the minimum needed for the job described.

Cloudflare

Content delivery, DDoS protection, and hosting of this website (including robots.txt and caching).

Sees: IP addresses and request metadata (edge logs)
Location: Global edge network; EU and US data centers

Calendly

Scheduling of calls booked through our website.

Sees: Name, email address, company, and calendar availability you provide when booking
Location: United States (SOC 2 certified)

Analytics provider

Privacy-friendly, aggregate measurement of site usage.

Sees: Page views and referrers; no individual profiles, no cross-site tracking
Location: European Union

For client engagements, additional providers may be involved (for example cloud hosting for the systems we build). These are named in the engagement agreement before any data flows. We review this list at least annually and update this page when a provider is added or removed; material changes affecting active clients are communicated directly.

Questions about data processing, or need a Data Processing Agreement (DPA)? Reach out via our contact page. See also our Privacy Policy and security overview.