Subprocessors
Version 1.0 · Last updated 4 August 2026
A subprocessor is another company we use that may touch personal data while we deliver the Services. This page is the authoritative list. It is incorporated into the Data Processing Addendum as Annex III.
How you find out when this changes
We give at least 30 days' notice before a new subprocessor starts processing your data. You will get an email, and this page will change. If you have a reasonable data-protection objection, reply within those 30 days — see DPA §5 for what happens next.
To be notified, make sure a working address is on your account. There is nothing to subscribe to.
Where your data actually lives
All Capitis production infrastructure — the application servers, the primary PostgreSQL database and the cache — runs on a single hosting provider in Manchester, United Kingdom. End-user data — identifiers, clicks and conversions — is held there and is not replicated to any other country.
Everything else on this list touches a narrow slice of customer data only: billing, email delivery, or the sign-in handshake. Some of those providers are outside the UK, which is why the location and transfer mechanism for each one is set out in full below.
The list
| Subprocessor | What it does | Data it can touch | Location | Transfer mechanism |
|---|---|---|---|---|
| Hostinger International Limited | Hosting for all production infrastructure: application servers, database, cache, backups | All Customer and end-user data held by the Services | Company in Lithuania; servers in Manchester, United Kingdom | Data remains in the UK. Provider access from the EEA is covered by its data processing agreement; EU–UK transfers rely on the UK adequacy decision. |
| Stripe, Inc. and Stripe Payments Europe, Ltd. | Subscription billing, payment processing, invoicing | Customer billing contact and payment details. No end-user data. We never see or store card numbers. | Ireland and United States | Standard Contractual Clauses with the UK International Data Transfer Addendum, under Stripe's data processing agreement |
| Resend, Inc. | Delivery of transactional email — sign-in links, account and billing notifications | Customer name and email address, and the content of those emails. No end-user data. | United States | Standard Contractual Clauses with the UK International Data Transfer Addendum, under Resend's data processing agreement |
| ImprovMX SAS | Forwarding of inbound email sent to our published addresses | Whatever a sender puts in an email to us | France | EU/EEA — covered by the UK adequacy decision for transfers in the other direction; no third-country transfer |
| Google LLC | "Sign in with Google", if a user chooses it | Email address and profile name at sign-in only. No end-user data. | United States | Standard Contractual Clauses with the UK International Data Transfer Addendum |
| GitHub, Inc. | "Sign in with GitHub", if a user chooses it | Email address and profile name at sign-in only. No end-user data. | United States | Standard Contractual Clauses with the UK International Data Transfer Addendum |
Who is deliberately not on this list
The affiliate networks. Awin, Admitad, Rakuten Advertising, CJ, Skimlinks, FMTC and the rest receive click and conversion data when a shopper follows one of your links. They are not our subprocessors — they are independent controllers processing that data for their own purposes under their own privacy policies. We could not bind them to our terms if we tried. Your privacy notice needs to tell your users this disclosure happens; see the Publisher Policy §4 and DPA §1.
Merchants. A merchant receives the shopper on its own site after the redirect. What happens there is between the merchant and the shopper.
Our development tooling. We use a hosted vector database to store engineering notes and design decisions across working sessions. It holds no Customer data and no end-user data, so it is not a subprocessor. We mention it only so nobody finds the dependency in our code and assumes we hid something.
Analytics and monitoring vendors. There are none. Capitis runs no third-party analytics, session recording, advertising pixels or error-reporting service on its website, dashboard or API.
Questions: privacy@capitis.app · Objections to a new subprocessor: legal@capitis.app
Single.id Limited, 20 Wenlock Road, London, England, N1 7GU — Company Number 17044105