← Trust Centre

Trust Centre

Subprocessors and material service providers

This register identifies material third-party providers that may process personal data for relevant Raeburn Group services. A provider's presence here does not mean it processes every customer's data or is used by every Group company.

Current register

Applicability depends on the company, product, enabled features, customer relationship and project configuration. Provider documentation remains authoritative for provider-controlled processing locations and downstream subprocessors.

ProviderPurposeDataRegion / transfersTerms
VercelHosting and delivery of selected customer-facing web servicesService, request, device and user data as applicable to the deployed serviceDeployment and provider processing locations vary by service configuration; international transfers are governed by Vercel's contractual terms and DPAVercel DPA
Google WorkspaceBusiness email, collaboration and communicationsBusiness communications, contact information and files handled through Workspace servicesRelevant Google Workspace processing locations; transfer safeguards and subprocessors are governed by Google's Workspace termsGoogle Workspace DPA
OpenAIAI processing for approved business and application workflowsInputs intentionally submitted to enabled AI features and associated service metadata as applicableProcessing location depends on the contracted service, product controls and available regional configurationOpenAI DPA
StripePayments, checkout and authorised financial-account functionality where enabledPayment, transaction, billing, customer and authorised financial-account data required for the enabled Stripe servicesProvider-controlled processing locations subject to Stripe's contractual transfer safeguardsStripe DPA
SupabaseDatabase and application-backend services for selected Raeburn applicationsApplication and account data stored or processed by the relevant projectProject-specific region where configured; ancillary processing may occur as described in Supabase's DPASupabase DPA

Assessment approach

Material providers are reviewed according to the service supported, categories of data involved, contractual data-protection terms, security posture, transfer safeguards and the potential impact of provider compromise or unavailability. The depth of review is proportionate to risk.

Changes and customer information

We update this public register when a material provider is added, removed or materially changes role. Where a customer contract includes specific subprocessor-notification or objection rights, those contractual terms govern that relationship.

Related privacy and data-processing information

This register should be read with the Group Privacy Policy and Data Processing page. Those documents explain controller/processor roles, international transfers, lawful bases and the broader data-protection framework.

Last reviewed: 29 August 2026.