Skip to content
Trust / Sub-processor listVersion 1.4 · Effective 28 Sep 2026
Version 1.4, effective 28 Sep 2026

Sub-processor list

Every third party that processes personal data on our behalf when we provide Pritect Veil, what it does, and where it runs.

White Label Consultancy AS engages the sub-processors below to deliver Pritect Veil. This list is complete. If a sub-processor is not on it, it does not process customer personal data for this product.

Every entry is bound by a written agreement imposing data protection obligations no less protective than those in our own Data Processing Agreement.

One row is on the list although it processes no customer personal data at all: the analytics provider for the public pages of this website, whose entry says as much and whose position clause 1.1 and clause 2.1 set out. It is named here rather than only in the Privacy notice because a reader asking who touches anything is better served by one complete list.

1Current sub-processors

The processing locations below are the regions we have pinned, not the provider's global footprint. Where a provider is headquartered outside the European Economic Area, the processing itself still takes place in the region named.

Sub-processorServicePurposeProcessing location
Supabase (Supabase, Inc.)Database, authentication, object storageThe application database holding cases, entity registries and audit records; account authentication and sessions; private object storage for uploaded source documents and generated bundlesFrankfurt, EU
Fly.io (Fly.io, Inc.)Document processing workersThe containerised service that extracts, detects, redacts, renders, verifies and packages documents. This is the component that processes documentsFrankfurt, EU
Vercel (Vercel Inc.)Web application hostingHosting and delivery of the Pritect Veil web application. Server functions are pinned to Frankfurt. When a reviewer opens an entity on the review screen, a server function decrypts a short excerpt of document text around it and returns it to that reviewer's browserFrankfurt, EU
Mistral AI (Mistral AI SAS)Large language model and optical character recognitionEntity detection over document text, the adversarial residual pass, and OCR of scanned pages. Called only from the processing worker, never from the browserFrance, EU
Stripe (Stripe Payments Europe, Ltd.)Billing and paymentsSubscription management, metered usage billing and payment processing. Receives account and billing contact data only, and never receives document contentIreland, EU
Resend (Resend, Inc.)Transactional email deliveryDelivery of account email: sign-in links, password resets, member invitations and service notices. Receives the recipient's email address and the message we send. Never receives document contentEU West 1, EU
Google (Google Ireland Limited)Website analyticsGoogle Analytics 4 on the public pages of this website, requested only after a visitor accepts the analytics category. Receives pseudonymous usage data about those pages: which of them are read, the referring page, browser and device type, an approximate location derived from the request, and the two random identifiers section 2.3 of the Cookie notice names. Never receives anything from a page behind sign-in, and never document contentGlobal, including the United States, under Standard Contractual Clauses

1.1What each one can see

Supabase, Fly.io and Mistral AI can technically process the content of documents you upload, because processing that content is what they are there for. Vercel serves the application, and its server functions in Frankfurt handle document content in one place only: they decrypt the short excerpts around an entity that a reviewer opens on the review screen and pass them to that reviewer's browser, without storing or logging them. Stripe receives billing data only.

Resend receives the address an account email goes to and the text of that email, which is a sign-in link, a password reset, an invitation or a service notice. Google receives usage data from the public pages of this website and nothing from the signed-in application, so it is the one entry on the list that touches nothing belonging to a case.

Personal data that is dense in identifiers, specifically the text of each mention of a detected entity and the normalised document model, is encrypted on our servers before it is written, using a key held per case. A sub-processor holding that data at rest holds ciphertext.

Not all case data is encrypted under the case key, and what is not, Supabase holds in readable form in Frankfurt. Among it are the display name of each detected entity, which is the fullest spelling of that name, email address or identifier as it appeared in the documents and is shown on the review screen so that a reviewer can tell who is who, and the external reference you give a case, which may identify a person. Clause 7.2 of the Data processing agreement lists every such field, and says that each one survives a purge in a database backup for as long as that backup can be restored, which is seven days. We plan to encrypt the display name under the case key.

1.2Connected customer systems

Systems you connect to the service so it can retrieve your documents, such as Microsoft SharePoint through the storage connection an administrator of your organisation authorises, are not our sub-processors. They process your documents for you, under your own agreement with that provider, before and independently of anything we do. The connection uses delegated access that your organisation consents to, limited to reading, and revocable by you in your provider's own admin portal at any time.

The only artifact of such a connection we store is the delegated refresh credential, encrypted at rest with a key the browser never receives. Documents retrieved through a connection are processed under the Data Processing Agreement exactly as documents you upload by hand.

2International transfers

2.1

All processing of customer personal data takes place within the European Union. We do not transfer customer personal data outside the European Economic Area in the ordinary course of providing the service.

Some sub-processors are incorporated outside the EEA even though the processing runs inside it. Where a corporate structure creates the possibility of access from a third country, that access is governed by the European Commission's Standard Contractual Clauses together with supplementary technical measures, principally the encryption described in clause 1.1. A copy of the safeguards in place is available on request.

One entry's own processing does take place outside the European Economic Area, and the first paragraph still holds because that entry holds no customer personal data. Google Analytics runs on Google's global infrastructure, including the United States. Google Ireland Limited is the party we contract with, and the transfers are governed by the Standard Contractual Clauses that Google's own data processing terms incorporate. What travels is the public website usage data described in clause 2.5 of the Privacy notice, and nothing from the product.

3Changes to this list

3.1

We will give customers at least thirty days' written notice before adding or replacing a sub-processor, so that there is time to object before the change takes effect.

A customer may object on reasonable data protection grounds within that period. If we cannot offer a workable alternative, the customer may terminate the affected subscription without penalty and receive a pro rata refund of prepaid fees.

3.2

To receive notice of changes, subscribe by writing to privacy@pritect.ai with the subject line "Sub-processor notifications".

Every change is also published to a feed at veil.pritect.ai/trust/subprocessors/feed.xml, which any feed reader can watch without telling us anything about you. The feed carries the same entries as section 4 and nothing else.

4Change log

4.1

Every addition to this list, and every replacement of a sub-processor on it, is recorded below with the date we published the change and the date the notice period in clause 3.1 ended. The two changes of 10 September 2026 were made before this service had any customer, so no notice was owed to anyone under clause 3.1; we ran the thirty days regardless and the dates below record it.

DateChangeSub-processorNotice period ended
10 Sep 2026Resend added for transactional email deliveryResend (Resend, Inc.)10 Oct 2026
10 Sep 2026Google added for analytics on the public pages of the websiteGoogle (Google Ireland Limited)10 Oct 2026

Questions about this document

Write to legal@pritect.ai, or to privacy@pritect.ai for anything about personal data. White Label Consultancy AS, Fjordalleen 16, 0250 Oslo, Norway.

White Label Consultancy AS, Fjordalleen 16, 0250 Oslo, NorwayVersion 1.4 · Effective 28 Sep 2026