Trust Centre
Subprocessors and material service providers
This register identifies material third-party providers that may process personal data for relevant Raeburn Group services. A provider's presence here does not mean it processes every customer's data or is used by every Group company.
Current register
Applicability depends on the company, product, enabled features, customer relationship and project configuration. Provider documentation remains authoritative for provider-controlled processing locations and downstream subprocessors.
| Provider | Purpose | Data | Region / transfers | Terms |
|---|---|---|---|---|
| Vercel | Hosting and delivery of selected customer-facing web services | Service, request, device and user data as applicable to the deployed service | Deployment and provider processing locations vary by service configuration; international transfers are governed by Vercel's contractual terms and DPA | Vercel DPA ↗ |
| Google Workspace | Business email, collaboration and communications | Business communications, contact information and files handled through Workspace services | Relevant Google Workspace processing locations; transfer safeguards and subprocessors are governed by Google's Workspace terms | Google Workspace DPA ↗ |
| OpenAI | AI processing for approved business and application workflows | Inputs intentionally submitted to enabled AI features and associated service metadata as applicable | Processing location depends on the contracted service, product controls and available regional configuration | OpenAI DPA ↗ |
| Stripe | Payments, checkout and authorised financial-account functionality where enabled | Payment, transaction, billing, customer and authorised financial-account data required for the enabled Stripe services | Provider-controlled processing locations subject to Stripe's contractual transfer safeguards | Stripe DPA ↗ |
| Supabase | Database and application-backend services for selected Raeburn applications | Application and account data stored or processed by the relevant project | Project-specific region where configured; ancillary processing may occur as described in Supabase's DPA | Supabase DPA ↗ |
Assessment approach
Material providers are reviewed according to the service supported, categories of data involved, contractual data-protection terms, security posture, transfer safeguards and the potential impact of provider compromise or unavailability. The depth of review is proportionate to risk.
Changes and customer information
We update this public register when a material provider is added, removed or materially changes role. Where a customer contract includes specific subprocessor-notification or objection rights, those contractual terms govern that relationship.
Related privacy and data-processing information
This register should be read with the Group Privacy Policy and Data Processing page. Those documents explain controller/processor roles, international transfers, lawful bases and the broader data-protection framework.
Last reviewed: 29 August 2026.