Legal and security
Sub processors
Last updated 23 August 2026.
Publishing this list is an obligation once there are customers, and it is one of the first things a careful buyer checks. It is short because the architecture keeps it short.
Two companies are named below, and only one of them processes anything today. The list stays short because the compute, the per organisation databases, the file storage and the mail all sit on one platform rather than being assembled from a different supplier for each, and the security page explains what that arrangement is and is not responsible for.
The second is Stripe, which the product calls for subscriptions. It is written and wired and it is dormant: no key is configured at the time of writing, so nothing has been sent to it. It is named here now rather than on the morning it starts, because a sub processor that appears on this page the day it begins processing is one a buyer found out about too late to object.
| Provider | What it does | Where |
|---|---|---|
| Cloudflare, Inc. | All hosting, compute, database, file storage, email delivery and network protection. Customer data is stored in the region chosen for each organisation. | European Union or United States, per organisation |
| Stripe | Subscriptions and payment, from the point the paid plans open. It receives your organisation's identifier and the names of the plan and modules being bought, and separately whatever card and billing details somebody types into Stripe's own pages, which never pass through us. It receives no customer records and no relationship data of any kind. Not in use at the time of writing. | Stripe's own infrastructure, outside your organisation's region |
Transfers, and the safeguards that cover them
The data processing agreement says this page names the appropriate safeguards for any processing outside the United Kingdom or European Economic Area. It did not, which was a promise in a contract pointing at a page that did not keep it. This section is that promise kept.
Where your data actually sits
In the region chosen when your organisation was created, and only there. That choice is between the European Union and the United States, it is fixed at creation, and it is physical instead of a label, because your organisation's database is created in that jurisdiction. An organisation created in the European Union has its database in the European Union.
An organisation that chose the European Union therefore involves no transfer at all for its stored records, and the rest of this section does not apply to it. We would rather say that than describe safeguards no one needs, which is the usual shape of this page elsewhere.
Where a transfer can still arise
Five places, and each is worth naming rather than leaving to be inferred.
Support. We are a United Kingdom company. Where you ask us for help that requires someone here to look at a record held in the United States region, that access is a transfer. It is limited to the people who need it, happens only on your instruction, and is recorded in your audit trail where you can read it.
Network handling. Requests reach the nearest point of our provider's network before being routed to the object holding your organisation. Content is encrypted in transit throughout and is not stored outside your chosen region.
The VAT registration check. When somebody in your organisation asks the product to check a VAT number, that number is sent to HMRC and what comes back is the name and the address the registration is held in. Only the number goes: not the record it sits on, not who asked, not the name of your organisation. HMRC is a United Kingdom public authority rather than a supplier of ours, so it is not a sub processor and there is no contract with it for us to publish. It is here because a number belonging to somebody you deal with does leave, and you should be told that by a page rather than by a network log.
The password check. Every password anybody sets here is checked against the public register of breached passwords at Have I Been Pwned. What is sent is the first five characters of a hash of the password and nothing whatever else: not the password, not the address it belongs to, not your organisation. The service answers with every hash that begins with those five characters and the comparison happens here, so it never learns which one was being asked about, and the request is padded so that the size of the answer says nothing either. If it cannot be reached the password is accepted and the failure is recorded, because refusing everybody a password while somebody else's service is down is the worse of the two outcomes.
The public registers. Company details are read from Companies House and the bank holiday dates from GOV.UK. What leaves for the first is a company number, and for the second nothing at all. Both are public registers being read rather than processors being given anything, and neither receives a customer record.
One thing deliberately not on that list: a mailbox or a calendar somebody in your organisation connects. Messages then leave through your own account with your own provider, under your own agreement with them, which is why it is not a transfer of ours to describe. The integrations page says exactly what is asked of that account and what is read from it.
The safeguards relied on
For transfers from the European Economic Area, the European Commission's standard contractual clauses, as incorporated in our provider's data processing addendum. For transfers from the United Kingdom, the same clauses with the Information Commissioner's international data transfer addendum.
Where the receiving organisation is certified under the applicable adequacy framework we rely on that instead, and the clauses remain in place beneath it instead of being replaced, because an adequacy finding can be withdrawn and has been before.
Our provider's current addendum and certification status are published by them and can be checked without asking us, which is the property that makes this section worth anything. If you need the executed copies for your own file, write to privacy@consonas.com and we will send them.
What we have not done
We have not carried out a published transfer impact assessment. For a customer in the European Union whose data never leaves it, there is nothing to assess. For a customer choosing the United States region, the assessment is one you should make for your own processing instead of one you should take from us, and we would rather say so than supply a document that looks like diligence and is not.
Expected additions
These are not in use yet and are listed so the direction is visible rather than a surprise. Each will appear in the table above, with notice, before it processes any customer data.
- An error tracking provider, for diagnosing faults.
- A support tooling provider, for handling correspondence.
A payment provider used to be on this list. It is Stripe, it is named in the table above, and it has moved up because naming it and calling it are two different days and the earlier one is the one that is useful to you.
How changes are handled
Customers are told by email before a sub processor is added, with enough notice to object. If you object and we cannot resolve it, you may end your subscription and take a full export with you.
To be notified of changes, write to privacy@consonas.com and ask to be added to the list. What we hold about you in order to send it is covered by the privacy notice.