Legal

Sub-processors

The third-party providers that process personal data on our behalf to deliver the Accessio.AI services.

Why this list exists

Under our Data Processing Addendum (Article 28 GDPR), every third party that touches customer data on our behalf must be disclosed. This page is the canonical, customer-facing list.

How we vet processors

Before onboarding, every sub-processor is reviewed for security posture, GDPR compliance, location of data processing, and contractual data-protection obligations no less protective than those in our DPA.

Notification of changes

When we add or replace a sub-processor, customers under an active DPA receive at least 30 days of advance notice by email so they can object on reasonable grounds before the change takes effect.

Sub-processorPurposeRegion
Vercel Inc.Application hosting (dashboard, marketing site, public REST API, MCP server).United States, EU edge
Amazon Web Services / Google CloudPersistent storage of scan results, alt-text suggestions, and audit-log entries.EU primary
Stripe Payments Europe LtdSubscription billing and invoicing.Ireland / EU
Resend / PostmarkTransactional email delivery (account verification, password reset, expiry reminders).United States, EU
SentryError monitoring and performance telemetry.United States, EU
GoogleOAuth identity provider when a customer staff user signs in to the dashboard with Google.United States, EU
MicrosoftOAuth identity provider when a customer staff user signs in to the dashboard with a Microsoft account.United States, EU

Questions or objections?

Customers with an active DPA can raise sub-processor objections at
[email protected].

Sub-processors | AccessioAI | AccessioAI