ASCP sub-processors

Last updated: 2026-08-11.

A sub-processor is a third party that processes customer personal data on our behalf. This list is what ASCP actually runs, taken from the infrastructure definition rather than from an intention. Customers under a Data Processing Addendum are notified before a sub-processor is added — see the DPA, §7.


Current sub-processors

That is the complete list. There is no analytics provider, no error-tracking service, no session recording, no customer-support tool with data access, no marketing platform, and no payment processor — because billing is not implemented.

AWS services in use

Listed individually because "AWS" is not a meaningful disclosure on its own:

Not a sub-processor


Where your data is, plainly

Everything is in the United States, in AWS us-east-1. There is no EU, UK or Brazilian deployment today.

This matters if you are subject to GDPR or UK GDPR: using ASCP involves a transfer of personal data to the United States. Our DPA includes the European Commission's Standard Contractual Clauses to cover that transfer, and AWS is certified under the EU–US Data Privacy Framework.

A caveat we would rather state than have you discover. The platform has a data-residency field on a customer record, and it is descriptive, not enforced — setting it to "EU" records a preference and does not move any data. If contractual data residency in a particular region is a requirement for you, tell us before signing: today the honest answer is that we cannot meet it, and changing the region means standing up a new deployment rather than migrating this one.


Changes to this list

We notify customers under a DPA before adding or replacing a sub-processor, with enough notice to object. The mechanism today is email to the account's designated contacts; there is no subscription feed for this page yet.

If you object to a new sub-processor on reasonable data-protection grounds, the DPA sets out what happens — §7.