Sub-processors
The third parties we use to process personal data, and what each one does. We keep the list short, name the providers, and say where the data goes.
01What a sub-processor is
A sub-processor is a third party we engage that processes personal data on our behalf. This happens in two contexts. First, on this website and the on-site assistant, where Vernius is the controller (and in places a processor) for personal data a visitor submits. Second, in Client engagements, where Vernius acts as a processor for a Client under the Data Processing Agreement.
A sub-processor is not the same as a supplier who does not touch personal data (for example a general software tool we use internally), and it is not the same as a third party the Client appoints and controls. This page lists only the third parties that actually process personal data in our website and hosted stack.
This is the current, maintained list. It is referenced by our Privacy Policy and by the Data Processing Agreement.
02How authorisation works
Under the Data Processing Agreement, the Client gives a general written authorisation for Vernius to appoint the sub-processors listed on this page. Vernius remains fully liable to the Client for the acts and omissions of each sub-processor, as if they were our own.
Each sub-processor is engaged under a written contract that imposes data-protection obligations equivalent to those we owe the Client under the Data Processing Agreement.
The standard stack and the Order. The sub-processors listed here are our standard stack. Project-specific sub-processors, for example a Client-chosen hosting region, an analytics tool, or a third-party integration, are named in the relevant Order and authorised there. So this list is not represented as exhaustive for every engagement.
Which sub-processors apply to your engagement. Scoped fixed-price projects and custom handoff builds may involve fewer sub-processors, or none in production, once the Client owns and hosts the solution. Retainer and hosted services, and our productized service, typically use the full stack below, because Vernius runs the solution.
03Our current sub-processors
These are the third parties we currently use to process personal data across the website and hosted engagements.
- Vercel Inc. Website and application hosting, edge delivery, and the AI gateway that routes on-site assistant messages to the model provider. Processes technical data and submitted message content in transit, and contact and brief data at rest where hosted on Vercel. United States. UK GDPR transfer safeguards apply (Standard Contractual Clauses with the UK International Data Transfer Addendum).
- Anthropic PBCAI model inference for the on-site assistant and AI features. A visitor’s message is sent to Anthropic via Vercel’s AI gateway to generate a reply, so Anthropic processes the message content a visitor types into the assistant, and any AI-feature inputs. API inputs are not used to train Anthropic’s models. United States. UK GDPR transfer safeguards apply (Standard Contractual Clauses with the UK International Data Transfer Addendum).
- Neon Inc. Managed PostgreSQL database storing submitted briefs and application data. Processes contact details and enquiry or brief content. Region as configured for the project, with UK GDPR transfer safeguards where hosted outside the UK.
- Resend Transactional email delivery, for example sending a submitted brief to us. Processes sender and recipient email addresses and message content. United States. UK GDPR transfer safeguards apply.
04International transfers
Some of these sub-processors are located outside the UK, primarily in the United States. Where personal data is transferred outside the UK, Vernius relies on an appropriate safeguard under UK GDPR: the International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, as applicable.
We take account of the nature of the data and apply additional measures where appropriate, for example transmission over encrypted connections.
Our fuller position on transfers is set out in the Privacy Policy and the Data Processing Agreement.
05How we choose and vet sub-processors
We keep this list deliberately short and prefer established providers with a track record on security and data protection.
Each sub-processor is engaged under contractual data-protection terms, a data processing agreement or equivalent, that flow down obligations equivalent to those we owe the Client.
Before engaging a provider, and periodically afterwards, we assess, proportionately to the data involved, the provider’s security posture and its published data-protection and transfer terms. This is a reasonable and proportionate assessment. We do not claim to hold or verify certifications, to have exercised audit rights, or to have run our own penetration tests.
06Changes to this list
Our stack may change as the website, a service, or a specific project requires, so this list will be updated from time to time. This page is the authoritative current list and is kept up to date.
Where the Data Processing Agreement requires, Vernius will notify affected Clients in advance of adding or replacing a sub-processor that processes their personal data, and give them a period to object on reasonable data-protection grounds, as set out in the Data Processing Agreement.
If a Client raises a reasonable objection, we will work in good faith to address it. If we cannot, the Client may terminate the affected Services as set out in the Data Processing Agreement.
If you would like to be notified of changes, email us and we will record your preference.
07Questions
Questions about sub-processors, transfers, or a specific engagement are welcome. Email contact@vernius.co.uk.
This site and these services are operated by Vernius Limited, registered in England & Wales under company number 17114305.
Registered office:
1 Albion Place, London W6 0QTSee also our Privacy Policy and the Data Processing Agreement.