Subprocessors
Last updated: 8 August 2026
CraftCert is a product of Crocker Digital Ltd (Company No. 17008789). The following third-party services process data on our behalf to provide the CraftCert service.
Corrections — 8 August 2026
- Cloudflare has been added. Cloudflare Turnstile has protected our sign-up, log-in and password-reset forms since 21 April 2026 and should have been listed from that date. This entry corrects an omission in our disclosure. It is not the addition of a new sub-processor, so the 30-day notice below is not engaged by it.
- The “technical successors” exception has been removed. This page previously said that sub-processor additions which are strictly technical successors of an existing processor did not require 30 days' notice. Clause 5.2(c) of our Data Processing Agreement contains no such exception and the DPA prevails, so the statement was wrong. One rule now applies: 30 days' notice for any addition or replacement.
- The transfer-mechanism note has been corrected. It previously described EU Standard Contractual Clauses Module 2 (controller-to-processor) as governing these transfers generally. For Customer Personal Data we act as processor and these vendors as sub-processors, so that was not accurate for every transfer.
- Supabase's purpose has been corrected from “authentication, database hosting, and file storage” — no file-storage facility is used.
- Each entry now links the provider's data-processing terms as well as its privacy notice. Previously only the privacy notice was linked.
A fuller erratum covering our Data Processing Agreement is published at the top of the DPA page.
| Service | Purpose | Data processed | Location | Processing terms |
|---|---|---|---|---|
| Supabase | Authentication and database hosting | Account data, product data, formulations, labels, evidence records, session tokens | UK (AWS eu-west-2, London) | DPA |
| Stripe | Payment processing and subscription management | Billing details, payment card data, subscription status, customer ID | US/EU | DPA |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | Email addresses, email content (account notifications) | EU (eu-west-1). Operated by Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114. | DPA |
| Netlify | Website hosting and deployment | HTTP request metadata (IP addresses, user agents) via server logs | US/EU | DPA |
| Cloudflare | Turnstile anti-abuse checks on sign-up, log-in and password reset | IP address, user-agent and browser signals collected to issue and verify a challenge token. No account, product or formulation data. | Global edge network (Cloudflare, Inc., US) | DPA |
| GoatCounter | Privacy-focused website analytics | Aggregate page view data only — no personal data, no cookies | EU | Sole trader — no separate DPA; terms in the linked privacy notice |
| Sentry | Error monitoring and performance tracking | Error stack traces, browser metadata, request IDs. No formulation or ingredient data. | EU (de.sentry.io) | DPA |
| Upstash | Rate limiting and abuse prevention | IP addresses and user IDs (temporarily, for rate limit windows) | EU | DPA |
| Microsoft 365 | Support mailbox + DSR-instruction inbox (support@craftcert.co.uk) | Email addresses, email content (inbound support and data-subject-request correspondence) | United Kingdom — Microsoft Ireland Operations Limited (contracting entity) | DPA |
Note on US management-plane access
Several sub-processors above are operated by US-headquartered entities (Supabase, Upstash, Cloudflare) whose engineers may exercise management-plane access to data resident in EU/UK regions for the purposes of operating, maintaining, and supporting the underlying infrastructure.
Where CraftCert initiates a restricted transfer of Customer Personal Data to an approved sub-processor, CraftCert will use an applicable UK transfer mechanism and, where required, complete and review a proportionate transfer risk assessment. Applicable mechanisms may include UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or EU Standard Contractual Clauses with the ICO Addendum. Where a vendor instead processes CraftCert's own account, billing or service-administration data, a different mechanism and a different set of clauses may apply to that processing. We do not state a specific module or mechanism for a given vendor here unless its current contract supports it. See our Data Processing Agreement Schedule 3 and Privacy Policy for per-sub-processor detail.
Changes to this list
We will update this page when we add or remove subprocessors. Material changes are notified in advance: we email all customers at least 30 days before adding a new subprocessor or changing how an existing one processes personal data. If you object to a planned change you can reply to the notification email; we'll work with you on alternatives or, where the change is unavoidable, on terminating your account cleanly (including a pro-rata refund where applicable).
This applies to any addition or replacement of a sub-processor. There is no exception for changes we regard as technical, and no exception for a successor to an existing provider. That is the commitment given in clause 5.2(c) of the Data Processing Agreement, which prevails over anything on this page.
Contact
Questions about our subprocessors? Contact support@craftcert.co.uk.