Legal

Sub-processors

Effective 2026-09-16 (subject to change on legal review) · Version subprocessors-draft-2026-09-16

DRAFT - pending legal review. Not a binding agreement. The text below is the document prepared for legal review. It does not create, and must not be relied on as, a binding agreement. A reviewed version will supersede this draft under a new version id once review is complete. Breachr OÜ's registry code and registered address are placeholders (shown underlined) while company registration is with our lawyers. They are not the filed values.

This document does two jobs. Sections 1 to 3 are the public sub-processor register for breachr.ai/subprocessors, written for customers and their DPOs. Section 4 onward is the internal coverage note explaining how each tool is handled and where the residual risks sit. Publish sections 1 to 3; keep section 4 onward internal, for you and Lex Law.

1. What a sub-processor is

To run breachr we use a small set of trusted service providers. Some of them process personal data on our behalf. GDPR calls these sub-processors. We list them here, tell you what they do, and tell you where they process data. We keep this list current and give notice of changes as set out in our Data Processing Agreement.

2. Current sub-processors

Sub-processor

Purpose

Data processed

Location

Transfer safeguard

Amazon Web Services (Frankfurt)

Core cloud infrastructure and storage

Account data, scan targets, findings, reports

EU (Frankfurt)

None needed (EU); see note 4.9

Supabase (EU)

Database, authentication and storage

Account data, and scan data held in the database

EU region (on AWS)

SCCs (US parent); see note 4.9

Vercel

Application hosting, edge and serverless functions

Request data, IP addresses, logs (pass-through, not scan storage)

EU region

SCCs (US parent); see note 4.9

OpenRouter

Routing layer for the AI reasoning model

Minimised finding data for analysis

EU endpoint where available; otherwise routed to model provider

SCCs; migrating to EU in-region

Anthropic

AI language model used to analyse findings

Minimised finding data for analysis

United States

Standard Contractual Clauses + Schrems II safeguards

Stripe Europe

Payment processing

Billing and payment data

EU / global

SCCs where applicable

Resend (EU)

Transactional and service email

Name, email, message content

EU

None needed (EU)

Umami Cloud

Cookieless website analytics

Aggregated, non-identifying site metrics

[CONFIRM EU HOSTING]

See note 4.6

PostHog (EU)

Product analytics inside the portal

Product usage and journey data (no scan data, no credentials, no findings)

EU

None needed (EU)

3. Two commitments about your data

We never sell your data, and we never use your scan data for our own purposes beyond delivering the service to you.

The AI reasoning layer involves one transfer outside the EU, and we will not hide it. Where our model provider's infrastructure sits outside the EU, a limited transfer occurs, covered by Standard Contractual Clauses, using only the minimum data needed to analyse a finding. We are migrating this layer to EU in-region routing, after which the transfer falls away.

← Back to home