Sub-processors

The third parties CARDO relies on to run the service, and what each of them processes.

Effective TODO_EFFECTIVE_DATE

Draft, not for publication. The legal entity, registered address, contact addresses and effective date are still placeholders in content/site.ts. This document also needs review by a solicitor before it goes live.

Current sub-processors

TODO_LEGAL_ENTITY engages the following sub-processors. Each is bound by a data processing agreement with confidentiality, security and audit obligations, and by transfer safeguards where processing happens outside the UK and EEA.

Sub-processorPurposeData processedLocation
Google Cloud PlatformApplication hosting, Firestore database, file storage, loggingAll customer data at rest and in transitConfigured per deployment region
Google (Gemini API)Generates AI risk and mitigation assessments on requestOnly the text submitted to an AI feature at the moment it is usedUnited States
SentryApplication error monitoringError traces, which may include an account identifierUnited States

AI features are opt-in per organisation. If your organisation does not enable them, no data reaches the Gemini API at all.

Notice of changes

We will give account holders at least 30 days’ notice by email before adding or replacing a sub-processor, and this page will be updated at the same time.

Objecting to a change

If you object to a new sub-processor on reasonable data protection grounds, tell us at TODO_PRIVACY_EMAIL within the notice period. We will work with you to find an alternative. If we cannot, you may terminate the affected part of the service without penalty for the remainder of the term.

See also the privacy policy and the data processing agreement.