Legal

Sub-Processors

Pericls uses the following third-party service providers (“sub-processors”) to deliver and operate the Regulatory Compliance Intelligence Platform. Each sub-processor is bound by a Data Processing Agreement requiring GDPR-equivalent protections.

Last updated: April 2026
ProviderPurposeData CategoriesLocationPrivacy Policy
StripePayment processingBilling data, email addressUS + EUView →
ResendTransactional email deliveryEmail addresses, notification contentUSView →
PostHogProduct analyticsUser ID, page views, feature usage eventsUSView →
SentryError monitoring & diagnosticsUser ID, error context, device infoUSView →
OpenAILLM inference for regulatory analysisContent submitted for analysisUSView →
AnthropicLLM inference for regulatory analysisContent submitted for analysisUSView →
Google (Gemini)LLM inference for regulatory analysisContent submitted for analysisUS / EUView →
AWS S3Document storageUploaded documentsConfigurable (region-specific)View →
Google OAuthAuthentication (single sign-on)Auth tokens, email address, display nameUSView →

Transfer Safeguards

Where sub-processors are located outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • EU-US Data Privacy Framework certification where applicable
  • Data Processing Agreements with each sub-processor requiring GDPR-equivalent protections

Change Notification

We will update this page and notify affected customers at least 30 days before engaging a new sub-processor or materially changing how an existing sub-processor is used. Customers on Enterprise plans may object to new sub-processors per the terms of their Data Processing Agreement.

To receive notifications of sub-processor changes, contact privacy@pericls.com.