← Privacy notice

Subprocessor register

UK GDPR Art 28 · Last updated July 2026 · Hypernest Innovations Limited

We use the following subprocessors to operate EnforceIQ Labs. EU/UK hosting is preferred where available. Fleet customers are notified of material changes under the fleet DPA — contact [email protected] to subscribe to change notifications.

Change notification

Material subprocessor additions or replacements are notified to fleet controllers at least 14 days before the change takes effect, unless an urgent security replacement is required. Controllers may object on reasonable data protection grounds during the notice period.

ProviderPurposeDataRegionTier
VercelHosting, CDN, serverless APIIP, request metadata, deployment logsEU preferredCritical
NeonPostgreSQL databaseAll tenant application dataEU (Frankfurt / London)Critical
ClerkAuthentication & org directoryEmail, name, Clerk IDsUS/EU per projectCritical
StripeBilling & subscriptionsCustomer ID, payment metadata (no card PAN in EnforceIQ)EU/US per accountHigh
ResendTransactional email (opt-in reminders)Email, notice references in templatesUS/EU per accountHigh
Amazon Web Services S3Private notice uploadsPhotos, PDFs, object metadataEU (eu-west-2 recommended)Critical
UpstashRate limits, cache, webhook idempotencyOrg IDs, hashed keys (ephemeral)EU optionMedium

Optional providers

ProviderPurposeWhen used
SentryError monitoring (analytics cookie only)Only after you accept analytics cookies
OpenAIAI features (opt-in, PII redacted)Only after you accept analytics cookies
RailwayBackground workers (OCR, PRA)Only after you accept analytics cookies

Data flow summary

User browsers connect to Vercel-hosted EnforceIQ. Authentication flows through Clerk. Application data persists in Neon PostgreSQL with tenant isolation. Notice uploads store in AWS S3 with signed URL access. Billing events flow through Stripe webhooks. Optional email reminders send via Resend when users opt in. Rate limiting and cache use Upstash.

Due diligence

Each subprocessor is assessed for purpose limitation, UK/EU data residency preference, DPA availability, and security certifications where published. Full legal register (DPAs, transfer mechanisms, onboarding checklist) is maintained in the EnforceIQ Labs compliance documentation pack (GDPR-01).