Draft for internal review. Not yet in force.

Sub-processors

Last updated: 5 October 2026

bernard uses these providers to run the service. Each one gets only the data it needs for its purpose.

ProviderPurposeDataLocationTransfer basis
Amazon Web ServicesHosting: application, site history, published files and media, forum uploads, backups. Audience email delivery (SES).All customer dataIreland (eu-west-1)UK adequacy regulations (EEA)
SupabaseDatabase, authentication and storageAccount data, contacts, buyers, students, forum members, form submissionsIreland (West EU)UK adequacy regulations (EEA)
CloudflareContent delivery, DNS and security for published sitesSite content, visitor IP addressesOriginals in Ireland; cached copies in Cloudflare data centres worldwideEU standard contractual clauses with the UK Addendum
PostmarkAccount and transactional emailEmail addresses, message contentUnited StatesUK Extension to the EU-US Data Privacy Framework; EU standard contractual clauses with the UK Addendum
StripeSubscription payments; payments from customers’ buyersNames, email addresses, payment detailsUnited States (Stripe, LLC)UK Extension to the EU-US Data Privacy Framework; UK Addendum as fallback
GoogleSign-in with Google; Google Analytics 4 on bernard and on hosted sites (with consent); Search Console data in BigQuery; Cloud Vision image checks; Safe Browsing and PageSpeed URL checksSign-in profile, analytics events, search data, images, URLsBigQuery: London (europe-west2). Others: Google facilities worldwideAnalytics and Cloud Vision: EU standard contractual clauses with the UK Addendum. Sign in with Google, Safe Browsing and PageSpeed: Google acts as an independent controller under its own terms
DeepgramTranscribing course and library video and audioAudio recordingsUnited States (api.deepgram.com)Being confirmed with Deepgram
Meta (Instagram)Importing a customer’s own Instagram media, when they connect itInstagram media and account IDUnited States (Meta Platforms, Inc.)Meta acts as an independent controller under the Meta Platform Terms
OpenRouter, and the model providers it routes tobernard-run AI featuresPrompts, site contentUnited States; model providers in their own regionsEU standard contractual clauses with the UK Addendum
Anthropicbernard-run AI editing (Claude)Prompts, site contentUnited States; requests may be processed in the US, Europe, Asia and AustraliaEU standard contractual clauses with the UK Addendum
Anthropic, OpenAI, Google (Gemini)AI editing with the customer’s own connected AIPrompts, site contentSet by the customer’s own account with that providerThe customer’s own contract with that provider
Sasha (Context is Everything)Site brain: what bernard knows about a businessBusiness facts, site contentEU (Germany)UK adequacy regulations (EEA)

We give 30 days’ notice before we add or replace a sub-processor that handles our customers’ audience data.

Our own website analytics

Microsoft Clarity runs only on bernardmoves.com, with your consent. Microsoft acts as an independent controller of that data.

Our providers’ credentials

These are our providers’ certifications, not bernard’s. bernard itself holds no certification yet.

Each row comes from the provider’s own page only. We read each page on the date in the last column. A credential not listed in a row was not stated on the page we read. “Could not verify” means we could not read the statement. It does not mean the provider lacks the credential.

ProviderTrust centreMain credentials (as stated)Scope noteChecked
Supabasehttps://supabase.com/securitySOC 2 Type 2. ISO 27001. HIPAA (needs a BAA). DPA at https://supabase.com/legal/dpa with Standard Contractual Clauses (SCCs) and a UK Addendum.Reports and certificate are in the dashboard for Team and Enterprise customers. The page says an EU region keeps primary database data in that region. The page does not state a Cyber Essentials, ISO 27017, 27018 or 27701 credential.2026-10-05
Amazon Web Serviceshttps://aws.amazon.com/compliance/programs/ISO 27001, 27017, 27018, 27701. SOC 1, SOC 2, SOC 3. PCI DSS. CSA STAR. UK Cyber Essentials Plus. UK G-Cloud. UK PASF. DPA: https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdfThe page lists programs, not services. It does not name Amazon SES. The SES guide sends readers to the “services in scope” list, and we could not read that list. SES scope: could not verify. The page says customers can choose any AWS Region for their data. The page gives no SOC type and no PCI level.2026-10-05
Cloudflarehttps://www.cloudflare.com/trust-hub/compliance-resources/ISO 27001 (certified since 2019, now ISO 27001:2022). ISO 27018:2019. ISO 27701:2019 (processor and controller). SOC 2 Type II, SOC 3, PCI DSS Level 1 (merchant and service provider): stated in a Cloudflare blog post from 2021, not on the trust hub page we could read. DPA: https://www.cloudflare.com/cloudflare-customer-dpa/ with SCCs, UK Addendum and Data Privacy Framework (DPF).The ISO scope is “the Cloudflare global cloud platform and subsidiary offices” (ISO page). The compliance resources page lists no certifications. It sends readers to the dashboard for the reports. We did not see a current SOC 2 or PCI statement on a trust hub page. Treat those two as stated in 2021 only.2026-10-05
Postmarkhttps://postmarkapp.com/securityThe page states a “Type 2 SSAE 16 SOC 1 accredited facility” (the data centre). Postmark’s EU privacy page states: “Postmark itself has not undergone a SOC audit” and the data centre is SOC 2 Type 2. DPA: https://postmarkapp.com/dpa with DPF (including UK Extension), SCCs and UK Addendum.The DPA names AC PM LLC as the processor. The ActiveCampaign page says “ActiveCampaign is heavily focused on GDPR, SOC 2, and HIPAA compliance” and does not name Postmark. We found no statement that an ActiveCampaign report covers Postmark. Which entity’s report covers Postmark: could not verify. The EU privacy page says primary data and servers are at a Deft data centre outside Chicago and in AWS, with no plan for EU servers. The EU privacy page has no date.2026-10-05
Stripehttps://docs.stripe.com/securityPCI Service Provider Level 1. SOC 1 and SOC 2 Type II, produced each year and given on request. SOC 3 is public. EU-US DPF, UK Extension and Swiss-US DPF. DPA: https://stripe.com/legal/dpa with SCCs and UK Addendum.The PCI audit covers Stripe’s Card Data Vault and its integration code. The page states no ISO 27001 credential.2026-10-05
Google (Google Cloud and Workspace)https://cloud.google.com/security/compliance/offeringsISO/IEC 27001:2022. SOC 2 Type II (core Google Cloud and Workspace reports, issued each quarter). SOC 3. PCI DSS. NCSC Cyber Essentials Plus. DPA: https://cloud.google.com/terms/data-processing-addendumThe ISO 27001 and PCI DSS pages name BigQuery and Cloud Vision in their product lists. Cyber Essentials Plus scope is “bound to UK personnel and office locations”. We found no G-Cloud statement on these pages. These pages cover Google Cloud and Workspace. They do not cover Google Analytics, Sign-in with Google, Search Console, Safe Browsing or PageSpeed. For those: could not verify. The DPA transfer mechanism: could not verify.2026-10-05
Deepgramhttps://developers.deepgram.com/trust-security/data-privacy-complianceSOC 2 Type 1 and Type 2. PCI compliant (yearly review). HIPAA (Business Associate).Reports are on request from Deepgram. The page states no ISO credential. It offers an EU endpoint (api.eu.deepgram.com) and an Australian endpoint. Our code uses api.deepgram.com (US). The page links only an AU DPA. A general DPA: could not verify.2026-10-05
Meta (Instagram API)https://developers.facebook.com/terms/dfc_platform_terms/No trust centre and no certification stated on the pages we read. The Platform Terms require developers to keep safeguards.Meta’s Data Processing Terms (https://www.facebook.com/legal/terms/dataprocessing) name the Business Tools Terms and Customer List Custom Audiences Terms. They do not name the Instagram API. We did not confirm that they apply to our use. They include a UK Data Transfer Addendum.2026-10-05
OpenRouterhttps://trust.openrouter.ai/SOC 2 Type 2. No other credential on the page.The privacy policy says personal data may go to the US or other countries outside the EEA, under SCCs. It says that if a customer has a DPA, that DPA and OpenRouter’s agreements with model providers govern the data. The model providers behind OpenRouter have their own terms.2026-10-05
Anthropichttps://trust.anthropic.comThe trust page needs JavaScript. We could not read it. Anthropic’s privacy centre states: “HIPAA-ready configuration (BAA available), ISO 27001:2022 (Information Security Management), ISO/IEC 42001:2023 (AI Management Systems), SOC 2 Type I & Type II”. DPA: https://www.anthropic.com/legal/data-processing-addendum with SCCs and UK Addendum.The privacy centre article is https://privacy.claude.com/en/articles/10015870-what-certifications-has-anthropic-obtained. The DPA is part of the Commercial Terms and applies to Claude for Work and the Claude API. Our claude_cli engine uses a subscription login. Check which terms apply to that login before we state DPA cover. Trust page content: could not verify.2026-10-05
OpenAIhttps://trust.openai.comSOC 2 Type 2. SOC 3. ISO/IEC 27001:2022, 27017:2015, 27018:2019, 27701:2019, 42001:2023. CSA STAR. PCI DSS v4.0.1. GDPR.The portal says these apply to the API, ChatGPT Enterprise, ChatGPT Edu and ChatGPT Team. It does not name consumer plans. We could not read the DPA page (https://openai.com/policies/data-processing-addendum/ returned an access error). OpenAI DPA: could not verify.2026-10-05
Google (Gemini API)https://ai.google.dev/gemini-api/termsNo certification stated on the Gemini API terms. For paid services the terms say Google processes prompts under its Data Processing Addendum for Products Where Google is a Data Processor (https://business.safety.google/processorterms/).The terms say data “may be stored transiently or cached in any country in which Google or its agents maintain facilities”. Do not apply the Google Cloud certifications above to the Gemini API without a Google page that names it.2026-10-05

Third parties you add to your own site

You can choose to put other companies’ tools on a site we host for you: for example a booking calendar, a video player, a newsletter or enquiry form, a chat widget, or your own analytics and advertising tags. You choose these tools, and your agreement with each company covers what it collects from your visitors. They are not bernard’s sub-processors, and bernard does not control the data they collect.

made with bernard