Sub-processors
Last updated: 5 October 2026
bernard uses these providers to run the service. Each one gets only the data it needs for its purpose.
| Provider | Purpose | Data | Location | Transfer basis |
|---|---|---|---|---|
| Amazon Web Services | Hosting: application, site history, published files and media, forum uploads, backups. Audience email delivery (SES). | All customer data | Ireland (eu-west-1) | UK adequacy regulations (EEA) |
| Supabase | Database, authentication and storage | Account data, contacts, buyers, students, forum members, form submissions | Ireland (West EU) | UK adequacy regulations (EEA) |
| Cloudflare | Content delivery, DNS and security for published sites | Site content, visitor IP addresses | Originals in Ireland; cached copies in Cloudflare data centres worldwide | EU standard contractual clauses with the UK Addendum |
| Postmark | Account and transactional email | Email addresses, message content | United States | UK Extension to the EU-US Data Privacy Framework; EU standard contractual clauses with the UK Addendum |
| Stripe | Subscription payments; payments from customers’ buyers | Names, email addresses, payment details | United States (Stripe, LLC) | UK Extension to the EU-US Data Privacy Framework; UK Addendum as fallback |
| Sign-in with Google; Google Analytics 4 on bernard and on hosted sites (with consent); Search Console data in BigQuery; Cloud Vision image checks; Safe Browsing and PageSpeed URL checks | Sign-in profile, analytics events, search data, images, URLs | BigQuery: London (europe-west2). Others: Google facilities worldwide | Analytics and Cloud Vision: EU standard contractual clauses with the UK Addendum. Sign in with Google, Safe Browsing and PageSpeed: Google acts as an independent controller under its own terms | |
| Deepgram | Transcribing course and library video and audio | Audio recordings | United States (api.deepgram.com) | Being confirmed with Deepgram |
| Meta (Instagram) | Importing a customer’s own Instagram media, when they connect it | Instagram media and account ID | United States (Meta Platforms, Inc.) | Meta acts as an independent controller under the Meta Platform Terms |
| OpenRouter, and the model providers it routes to | bernard-run AI features | Prompts, site content | United States; model providers in their own regions | EU standard contractual clauses with the UK Addendum |
| Anthropic | bernard-run AI editing (Claude) | Prompts, site content | United States; requests may be processed in the US, Europe, Asia and Australia | EU standard contractual clauses with the UK Addendum |
| Anthropic, OpenAI, Google (Gemini) | AI editing with the customer’s own connected AI | Prompts, site content | Set by the customer’s own account with that provider | The customer’s own contract with that provider |
| Sasha (Context is Everything) | Site brain: what bernard knows about a business | Business facts, site content | EU (Germany) | UK adequacy regulations (EEA) |
We give 30 days’ notice before we add or replace a sub-processor that handles our customers’ audience data.
Our own website analytics
Microsoft Clarity runs only on bernardmoves.com, with your consent. Microsoft acts as an independent controller of that data.
Our providers’ credentials
These are our providers’ certifications, not bernard’s. bernard itself holds no certification yet.
Each row comes from the provider’s own page only. We read each page on the date in the last column. A credential not listed in a row was not stated on the page we read. “Could not verify” means we could not read the statement. It does not mean the provider lacks the credential.
| Provider | Trust centre | Main credentials (as stated) | Scope note | Checked |
|---|---|---|---|---|
| Supabase | https://supabase.com/security | SOC 2 Type 2. ISO 27001. HIPAA (needs a BAA). DPA at https://supabase.com/legal/dpa with Standard Contractual Clauses (SCCs) and a UK Addendum. | Reports and certificate are in the dashboard for Team and Enterprise customers. The page says an EU region keeps primary database data in that region. The page does not state a Cyber Essentials, ISO 27017, 27018 or 27701 credential. | 2026-10-05 |
| Amazon Web Services | https://aws.amazon.com/compliance/programs/ | ISO 27001, 27017, 27018, 27701. SOC 1, SOC 2, SOC 3. PCI DSS. CSA STAR. UK Cyber Essentials Plus. UK G-Cloud. UK PASF. DPA: https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf | The page lists programs, not services. It does not name Amazon SES. The SES guide sends readers to the “services in scope” list, and we could not read that list. SES scope: could not verify. The page says customers can choose any AWS Region for their data. The page gives no SOC type and no PCI level. | 2026-10-05 |
| Cloudflare | https://www.cloudflare.com/trust-hub/compliance-resources/ | ISO 27001 (certified since 2019, now ISO 27001:2022). ISO 27018:2019. ISO 27701:2019 (processor and controller). SOC 2 Type II, SOC 3, PCI DSS Level 1 (merchant and service provider): stated in a Cloudflare blog post from 2021, not on the trust hub page we could read. DPA: https://www.cloudflare.com/cloudflare-customer-dpa/ with SCCs, UK Addendum and Data Privacy Framework (DPF). | The ISO scope is “the Cloudflare global cloud platform and subsidiary offices” (ISO page). The compliance resources page lists no certifications. It sends readers to the dashboard for the reports. We did not see a current SOC 2 or PCI statement on a trust hub page. Treat those two as stated in 2021 only. | 2026-10-05 |
| Postmark | https://postmarkapp.com/security | The page states a “Type 2 SSAE 16 SOC 1 accredited facility” (the data centre). Postmark’s EU privacy page states: “Postmark itself has not undergone a SOC audit” and the data centre is SOC 2 Type 2. DPA: https://postmarkapp.com/dpa with DPF (including UK Extension), SCCs and UK Addendum. | The DPA names AC PM LLC as the processor. The ActiveCampaign page says “ActiveCampaign is heavily focused on GDPR, SOC 2, and HIPAA compliance” and does not name Postmark. We found no statement that an ActiveCampaign report covers Postmark. Which entity’s report covers Postmark: could not verify. The EU privacy page says primary data and servers are at a Deft data centre outside Chicago and in AWS, with no plan for EU servers. The EU privacy page has no date. | 2026-10-05 |
| Stripe | https://docs.stripe.com/security | PCI Service Provider Level 1. SOC 1 and SOC 2 Type II, produced each year and given on request. SOC 3 is public. EU-US DPF, UK Extension and Swiss-US DPF. DPA: https://stripe.com/legal/dpa with SCCs and UK Addendum. | The PCI audit covers Stripe’s Card Data Vault and its integration code. The page states no ISO 27001 credential. | 2026-10-05 |
| Google (Google Cloud and Workspace) | https://cloud.google.com/security/compliance/offerings | ISO/IEC 27001:2022. SOC 2 Type II (core Google Cloud and Workspace reports, issued each quarter). SOC 3. PCI DSS. NCSC Cyber Essentials Plus. DPA: https://cloud.google.com/terms/data-processing-addendum | The ISO 27001 and PCI DSS pages name BigQuery and Cloud Vision in their product lists. Cyber Essentials Plus scope is “bound to UK personnel and office locations”. We found no G-Cloud statement on these pages. These pages cover Google Cloud and Workspace. They do not cover Google Analytics, Sign-in with Google, Search Console, Safe Browsing or PageSpeed. For those: could not verify. The DPA transfer mechanism: could not verify. | 2026-10-05 |
| Deepgram | https://developers.deepgram.com/trust-security/data-privacy-compliance | SOC 2 Type 1 and Type 2. PCI compliant (yearly review). HIPAA (Business Associate). | Reports are on request from Deepgram. The page states no ISO credential. It offers an EU endpoint (api.eu.deepgram.com) and an Australian endpoint. Our code uses api.deepgram.com (US). The page links only an AU DPA. A general DPA: could not verify. | 2026-10-05 |
| Meta (Instagram API) | https://developers.facebook.com/terms/dfc_platform_terms/ | No trust centre and no certification stated on the pages we read. The Platform Terms require developers to keep safeguards. | Meta’s Data Processing Terms (https://www.facebook.com/legal/terms/dataprocessing) name the Business Tools Terms and Customer List Custom Audiences Terms. They do not name the Instagram API. We did not confirm that they apply to our use. They include a UK Data Transfer Addendum. | 2026-10-05 |
| OpenRouter | https://trust.openrouter.ai/ | SOC 2 Type 2. No other credential on the page. | The privacy policy says personal data may go to the US or other countries outside the EEA, under SCCs. It says that if a customer has a DPA, that DPA and OpenRouter’s agreements with model providers govern the data. The model providers behind OpenRouter have their own terms. | 2026-10-05 |
| Anthropic | https://trust.anthropic.com | The trust page needs JavaScript. We could not read it. Anthropic’s privacy centre states: “HIPAA-ready configuration (BAA available), ISO 27001:2022 (Information Security Management), ISO/IEC 42001:2023 (AI Management Systems), SOC 2 Type I & Type II”. DPA: https://www.anthropic.com/legal/data-processing-addendum with SCCs and UK Addendum. | The privacy centre article is https://privacy.claude.com/en/articles/10015870-what-certifications-has-anthropic-obtained. The DPA is part of the Commercial Terms and applies to Claude for Work and the Claude API. Our claude_cli engine uses a subscription login. Check which terms apply to that login before we state DPA cover. Trust page content: could not verify. | 2026-10-05 |
| OpenAI | https://trust.openai.com | SOC 2 Type 2. SOC 3. ISO/IEC 27001:2022, 27017:2015, 27018:2019, 27701:2019, 42001:2023. CSA STAR. PCI DSS v4.0.1. GDPR. | The portal says these apply to the API, ChatGPT Enterprise, ChatGPT Edu and ChatGPT Team. It does not name consumer plans. We could not read the DPA page (https://openai.com/policies/data-processing-addendum/ returned an access error). OpenAI DPA: could not verify. | 2026-10-05 |
| Google (Gemini API) | https://ai.google.dev/gemini-api/terms | No certification stated on the Gemini API terms. For paid services the terms say Google processes prompts under its Data Processing Addendum for Products Where Google is a Data Processor (https://business.safety.google/processorterms/). | The terms say data “may be stored transiently or cached in any country in which Google or its agents maintain facilities”. Do not apply the Google Cloud certifications above to the Gemini API without a Google page that names it. | 2026-10-05 |
Third parties you add to your own site
You can choose to put other companies’ tools on a site we host for you: for example a booking calendar, a video player, a newsletter or enquiry form, a chat widget, or your own analytics and advertising tags. You choose these tools, and your agreement with each company covers what it collects from your visitors. They are not bernard’s sub-processors, and bernard does not control the data they collect.