Loading...
Legal
This document lists the sub-processors that Pericls Ltd ("Pericls", "we", "us", or "our") engages to process personal data on behalf of our customers in connection with the Pericls regulatory compliance intelligence platform (the "Service").
A "sub-processor" is a third-party entity engaged by Pericls to process personal data on behalf of our customers (who are the data controllers or, in some cases, data processors themselves). Sub-processors assist us in delivering, maintaining, and improving the Service. Each sub-processor is bound by a Data Processing Agreement that imposes obligations no less protective than those in our Data Processing Agreement with you.
Under Article 28(2) and (4) of the GDPR, Pericls:
The following table lists all sub-processors currently authorised to process personal data in connection with the Service.
| Sub-Processor | Entity Country | Processing Location | Purpose | Data Categories Processed | Transfer Mechanism | Privacy Policy / DPA |
|---|---|---|---|---|---|---|
| Hetzner Online GmbH | Germany | Germany (Nuremberg, nbg1; Falkenstein, fsn1) | Application hosting (frontend and backend), PostgreSQL database, Redis cache, S3-compatible object storage for documents, reports, and backups | All Service data including account data, organisation data, uploaded documents, analysis results, authentication data | Not applicable — processing within the EU/EEA (UK–EU adequacy for UK transfers) | Hetzner Privacy Policy / Hetzner DPA |
| Sub-Processor | Entity Country | Processing Location | Purpose | Data Categories Processed | Transfer Mechanism | Privacy Policy / DPA |
|---|---|---|---|---|---|---|
| OpenAI, L.L.C. | United States | United States | LLM-powered regulatory text analysis, compliance gap identification, document analysis, report generation | Content submitted for analysis (document text, regulatory text, assessment responses) | EU Standard Contractual Clauses (SCCs); zero-data-retention API usage | OpenAI Privacy Policy / OpenAI DPA |
| Anthropic PBC | United States | United States | LLM-powered regulatory analysis, compliance assessments, document summarisation | Content submitted for analysis (document text, regulatory text, assessment responses) | EU Standard Contractual Clauses (SCCs); zero-data-retention API usage | Anthropic Privacy Policy / Anthropic DPA |
| Google LLC (Gemini API) | United States | United States | LLM-powered regulatory analysis and document processing | Content submitted for analysis (document text, regulatory text, assessment responses) | EU-US Data Privacy Framework (DPF) + EU Standard Contractual Clauses (SCCs) | Google Cloud Privacy Policy / Google Cloud DPA |
Important: Content submitted to AI/LLM providers is processed solely for the purpose of returning analysis results. None of these providers use customer data to train their foundation models under our API agreements.
| Sub-Processor | Entity Country | Processing Location | Purpose | Data Categories Processed | Transfer Mechanism | Privacy Policy / DPA |
|---|---|---|---|---|---|---|
| Stripe, Inc. | United States | US + EU | Payment processing, subscription management, billing, fraud prevention, invoicing | Customer name, email address, billing address, payment method details, transaction history, Stripe customer ID | EU-US Data Privacy Framework (DPF) + EU Standard Contractual Clauses (SCCs) | Stripe Privacy Policy / Stripe DPA |
| Sub-Processor | Entity Country | Processing Location | Purpose | Data Categories Processed | Transfer Mechanism | Privacy Policy / DPA |
|---|---|---|---|---|---|---|
| Resend, Inc. | United States | United States | Transactional email delivery (account verification, password resets, billing receipts, system notifications) | Recipient email addresses, email subject lines, email body content, delivery metadata | EU Standard Contractual Clauses (SCCs) | Resend Privacy Policy / Resend DPA |
| Sub-Processor | Entity Country | Processing Location | Purpose | Data Categories Processed | Transfer Mechanism | Privacy Policy / DPA |
|---|---|---|---|---|---|---|
| PostHog, Inc. | United States | US (PostHog Cloud) | Product analytics — page views, feature usage tracking, user journey analysis, conversion funnels | User ID, email, name (when identified), page views, feature events, session data, browser/device metadata | EU Standard Contractual Clauses (SCCs) | PostHog Privacy Policy / PostHog DPA |
| Functional Software, Inc. (Sentry) | United States | United States | Application error monitoring, performance tracking, crash reporting | User ID (at time of error), error messages, component stack traces, request metadata, browser/device information | EU Standard Contractual Clauses (SCCs) | Sentry Privacy Policy / Sentry DPA |
| Sub-Processor | Entity Country | Processing Location | Purpose | Data Categories Processed | Transfer Mechanism | Privacy Policy / DPA |
|---|---|---|---|---|---|---|
| Google LLC (OAuth) | United States | United States | Single sign-on authentication, identity verification | OAuth tokens, email address, full name, profile picture URL, Google account identifier | EU-US Data Privacy Framework (DPF) | Google Privacy Policy |
| Sub-Processor | Entity Country | Processing Location | Purpose | Data Categories Processed | Transfer Mechanism | Privacy Policy / DPA |
|---|---|---|---|---|---|---|
| GitHub, Inc. (Microsoft) | United States | United States | Source code hosting, continuous integration and deployment | Source code only — no customer personal data is stored in or accessed through GitHub | EU-US Data Privacy Framework (DPF) + EU Standard Contractual Clauses (SCCs) | GitHub Privacy Statement / GitHub DPA |
All sub-processors processing personal data outside the United Kingdom and the European Economic Area (EEA) have appropriate transfer mechanisms in place:
| Transfer Mechanism | Sub-Processors |
|---|---|
| No transfer — EU/EEA processing | Hetzner (all primary hosting, database, and document storage) |
| EU-US Data Privacy Framework (DPF) | Google (OAuth, Gemini), Stripe |
| EU Standard Contractual Clauses (SCCs) | OpenAI, Anthropic, Resend, PostHog, Sentry, GitHub |
| DPF + SCCs (dual mechanism) | Google (Gemini), Stripe, GitHub |
Where we rely on SCCs, we have conducted Transfer Impact Assessments and, where necessary, implement supplementary measures including encryption in transit and at rest, pseudonymisation, and contractual restrictions on government access.
We will notify you of any changes to this Sub-Processor List, including the addition or replacement of sub-processors, by:
If you reasonably object to a new sub-processor on data protection grounds, you may:
Objections should be sent to: dpo@pericls.com
| Date | Version | Change Description |
|---|---|---|
| 4 April 2026 | 1.0 | Initial publication |
| 5 July 2026 | 1.1 | Infrastructure migrated to Hetzner Online GmbH (Germany, EU) — removed Render, Vercel, and AWS S3; primary hosting and document storage now processed within the EU |
If you have any questions about our sub-processors or this list, please contact:
Data Protection Officer:
Email: dpo@pericls.com
General Enquiries:
Email: legal@pericls.com
Postal Address:
Pericls Ltd
Charterhouse Millburgh Hall, Graffham, Petworth
England, GU28 0QH
This Sub-Processor List is provided in English. If there is any conflict between a translated version and the English version, the English version shall prevail.